Skip to content

feat(approvals): govern once and run scopes - #408

Merged
PeterGuy326 merged 3 commits into
mainfrom
feat/approval-governed-run-scope
Sep 20, 2026
Merged

PeterGuy326 merged 3 commits into
mainfrom
feat/approval-governed-run-scope

Conversation

@Bindy-lbb

Copy link
Copy Markdown
Collaborator

Closes #401

Implements engine-declared, source-bound approval scopes.

  • validates approval-scope-offer.v1 at the engine and persisted-turn boundaries
  • verifies the SHA-256 binding against approval, source run, action, and expiry before allowing run
  • persists and replays the selected scope idempotently
  • exposes only server-verified choices in both approval UI entry points and shows the effective audit boundary
  • adds protocol, service, expiry/replay, renderer, and documentation coverage

Verification:

  • npm run build
  • node --test apps/server/dist/test/approval.test.js apps/server/dist/test/approvals-center.test.js
  • npm run test:renderer -- approvals-state.test.tsx approval-queue.test.tsx
  • npm run typecheck:renderer
  • npm run typecheck:ui

@waterbro-8 waterbro-8 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review — Request changes

Exact head de85478fab60. MERGEABLE vs main after the #313 rebase, but required verify is red.

Blocking: packages/shared/src/approval-scope.ts is exported from the shared barrel, but dist/approval-scope.js is not on SHARED_RUNTIME_FILES in apps/desktop/packaging/runtime-layout.cjs.

Ubuntu Node 24 fails:

shared runtime inventory must be updated explicitly when source modules change
packages/shared/dist/index.js imports unpackaged dist/approval-scope.js

Same class of miss as #405 (approval-preview.js). Add dist/approval-scope.js to the allowlist (and any other new shared dist files this PR introduces), then re-run verify.

Layout-parity / unpacked-smoke reds look like fallout from that unpackaged module, not a separate product issue.

Not product验收. Not mergeable until packaging + Node 24 are green.

@waterbro-8 waterbro-8 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review — Approve (code, not 产品验收)

Exact head fb37f8f81f29. MERGEABLE. CI 11/11 green.

The previous blocker is fixed: dist/approval-scope.js is on SHARED_RUNTIME_FILES next to approval-preview.js. Verify (ubuntu/mac, unpacked smoke, layout parity) is green.

Scope remains engine-declared approval-scope-offer.v1 with SHA-256 binding; not product验收. Not auto-merge.

@PeterGuy326
PeterGuy326 merged commit e823269 into main Sep 20, 2026
11 checks passed
@PeterGuy326
PeterGuy326 deleted the feat/approval-governed-run-scope branch September 20, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(approvals): support governed once-versus-run approval scope

3 participants