Repository navigation
feat(tui): add scoped permission controls - #37
ZhiXiao-Lin wants to merge 1 commit into
Conversation
|
Independent follow-up validation of Validation:
Security-path review also confirmed that remembered grants are evaluated only after base hard denials and workspace guardrails, Plan mode remains read-only even with a matching grant, project ACL parsing is bounded and strict, symbolic-link targets are rejected, project writes are atomic, and a failed revocation restores the in-memory grant. PR remains |
|
Integrated through #40 at merge commit |
Dependency
This is intentionally stacked on #32. Merge #32 first; this PR then contributes only the permission-control layer and preserves the Plan Review, Send-now, and immutable queued-mode behavior already reviewed there.
Summary
.a3s/permissions.aclthrougha3s-acl, with strict parsing, canonical arguments, atomic replacement, symbolic-link rejection, a 256-rule limit, and a 256 KiB file/output limit/permissions, a searchable session/project grant inspector with canonical details and two-step revocation; revocation affects future checks without cancelling a running toolValidation
Validated against published crates.io dependencies, including
a3s-code-core 5.3.5:cargo fmt --all --checkcargo check --all-targets --offlinecargo clippy --all-targets --offline -- -D warningscargo test --all-targets --locked --offline(main TUI: 1,488 passed, 4 ignored; every integration target passed)Recovery scope
This is a focused extraction from independently preserved interrupted-agent snapshots. It excludes prompt history, relay, delegated tasks, DeepResearch, transcript export, and other recovery slices so they remain independently reviewable.