Skip to content

feat(tui): add scoped permission controls - #37

Closed
ZhiXiao-Lin wants to merge 1 commit into
recovery/execution-workflowsfrom
recovery/permission-control-stacked
Closed

ZhiXiao-Lin wants to merge 1 commit into
recovery/execution-workflowsfrom
recovery/permission-control-stacked

Conversation

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor

Dependency

This is intentionally stacked on #32. Merge #32 first; this PR then contributes only the permission-control layer and preserves the Plan Review, Send-now, and immutable queued-mode behavior already reviewed there.

Summary

  • replace the broad approval toggle with four scoped choices: allow once, remember the exact capability for this TUI session, add the exact capability to the project, or deny with feedback for the agent
  • persist bounded project grants in .a3s/permissions.acl through a3s-acl, with strict parsing, canonical arguments, atomic replacement, symbolic-link rejection, a 256-rule limit, and a 256 KiB file/output limit
  • add /permissions, a searchable session/project grant inspector with canonical details and two-step revocation; revocation affects future checks without cancelling a running tool
  • share grants across session rebuilds while keeping Plan strictly read-only and Auto fully non-interactive behind hard policy and workspace denials
  • update keyboard/mouse routing, approval rendering, help, README, changelog, and regression coverage

Validation

Validated against published crates.io dependencies, including a3s-code-core 5.3.5:

  • cargo fmt --all --check
  • cargo check --all-targets --offline
  • cargo clippy --all-targets --offline -- -D warnings
  • cargo test --all-targets --locked --offline (main TUI: 1,488 passed, 4 ignored; every integration target passed)
  • standalone optimized release build of the recovered permission implementation

Recovery scope

This is a focused extraction from independently preserved interrupted-agent snapshots. It excludes prompt history, relay, delegated tasks, DeepResearch, transcript export, and other recovery slices so they remain independently reviewable.

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor Author

Independent follow-up validation of b4d5ce7 completed in a detached published-dependency mirror. The source branch remained clean and unchanged.

Validation:

  • cargo fmt --all -- --check
  • git diff --check
  • cargo clippy --all-targets --locked --offline -- -D warnings
  • cargo test --all-targets --locked --offline
    • library target: 33 passed, 1 ignored
    • main TUI target: 1,488 passed, 4 ignored
    • every non-network integration target passed
    • real LLM, real OS, real Box/MicroVM, and soak tests remained ignored by their repository annotations

Security-path review also confirmed that remembered grants are evaluated only after base hard denials and workspace guardrails, Plan mode remains read-only even with a matching grant, project ACL parsing is bounded and strict, symbolic-link targets are rejected, project writes are atomic, and a failed revocation restores the in-memory grant.

PR remains MERGEABLE / CLEAN and intentionally stacked on #32.

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor Author

Integrated through #40 at merge commit c252583e413f70a4cb265012d776f9d050b94de5. The consolidated v0.9.7 branch contains this PR's latest head b4d5ce7a39c999965a84ba1755c85fd034448f62 and passed Linux, macOS, and Windows CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant