feat(approvals): govern once and run scopes - #408
Conversation
waterbro-8
left a comment
There was a problem hiding this comment.
Review — Request changes
Exact head de85478fab60. MERGEABLE vs main after the #313 rebase, but required verify is red.
Blocking: packages/shared/src/approval-scope.ts is exported from the shared barrel, but dist/approval-scope.js is not on SHARED_RUNTIME_FILES in apps/desktop/packaging/runtime-layout.cjs.
Ubuntu Node 24 fails:
shared runtime inventory must be updated explicitly when source modules change
packages/shared/dist/index.js imports unpackaged dist/approval-scope.js
Same class of miss as #405 (approval-preview.js). Add dist/approval-scope.js to the allowlist (and any other new shared dist files this PR introduces), then re-run verify.
Layout-parity / unpacked-smoke reds look like fallout from that unpackaged module, not a separate product issue.
Not product验收. Not mergeable until packaging + Node 24 are green.
waterbro-8
left a comment
There was a problem hiding this comment.
Review — Approve (code, not 产品验收)
Exact head fb37f8f81f29. MERGEABLE. CI 11/11 green.
The previous blocker is fixed: dist/approval-scope.js is on SHARED_RUNTIME_FILES next to approval-preview.js. Verify (ubuntu/mac, unpacked smoke, layout parity) is green.
Scope remains engine-declared approval-scope-offer.v1 with SHA-256 binding; not product验收. Not auto-merge.
Closes #401
Implements engine-declared, source-bound approval scopes.
approval-scope-offer.v1at the engine and persisted-turn boundariesrunVerification:
npm run buildnode --test apps/server/dist/test/approval.test.js apps/server/dist/test/approvals-center.test.jsnpm run test:renderer -- approvals-state.test.tsx approval-queue.test.tsxnpm run typecheck:renderernpm run typecheck:ui