Skip to content

feat(permissions): add host-owned auto review and scoped grants - #954

Open
hui455 wants to merge 7 commits into
vastsa:mainfrom
hui455:feat/permission-auto-review-recovery
Open

hui455 wants to merge 7 commits into
vastsa:mainfrom
hui455:feat/permission-auto-review-recovery

Conversation

@hui455

@hui455 hui455 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

为 PI-Desktop 增加可选的模型自动审核和按调用主体、实际操作限定的会话授权。默认仍由用户审批;Auto 模式仍按原有语义跳过审批。审核模型只能批准当前操作,不能创建会话授权或覆盖 Host 的硬性拒绝。不确定、无效响应或模型不可用时转人工。

设置左侧新增独立的“权限”入口,集中管理权限模式、审批人、审核模型、思考等级和自定义策略。审核模型可搜索;未固定模型时思考等级显示 off,固定模型后仅显示 off 和该模型支持的等级。自定义策略默认留空,输入非空内容后自动保存并替换内置策略,清空后自动恢复内置策略。标题和输入框之间留有 8px 间距。

Scope and compatibility

  • Rust Host 保留最终权限裁决和一次性执行许可;Renderer 不直接授权执行。会话授权可查看、逐条撤销及全部清除,且不能跨路径、命令、工具或调用主体复用。
  • 审核请求不提供工具。固定模型不可用时不会静默切换供应商;策略变更使旧审核批准失效。Host 权限和硬性拒绝不能被自定义策略移除。
  • 协议升级到 v12,数据库迁移到 schema v20。现有设置默认人工审核,内存授权不会跨重启恢复。自定义策略只保存在本机,不参与配置同步。
  • 插件风险和 Plan 豁免以已安装 manifest 为准;缺少 Host 可见声明的动态工具按保守风险处理。
  • 本 PR 不提供操作系统 Shell 沙箱、插件进程隔离或原生 Pi 工具桥接;这些仍由 [Feature] 权限升级路线图:Auto review、作用域授权与 Pi 兼容 #952 跟踪。

相关规格:docs/spec/03-runtime/23-permission-auto-review.md、docs/adr/0306-host-owned-automatic-permission-review.md、权限 UX / RPC / 存储 / 安全 / E2E 文档及权限指南。

Validation

基于 origin/main 27fad580c6e1 的候选,在隔离 Windows 桌面、真实 Rust Host 和本地 HTTP 模型 fixture 下验证;没有调用付费供应商。

  • pnpm check:pr-base、pnpm build:js、Desktop typecheck、pnpm lint、pnpm docs:check、架构检查通过。
  • cargo test -p host-core --locked permission_review:13 项通过。
  • node scripts/e2e-permission-review.mjs:15 个 Host 到模型的场景通过,包括策略替换、清空恢复默认、迟到批准拒绝、转人工、授权隔离及取消。
  • node scripts/e2e-permission-ui.mjs:中英文权限卡及策略输入交互通过,包括自动保存、连续输入、全空格清空、超长拦截和失败重试。
  • PI_PERMISSION_DESKTOP_SETTINGS_ONLY=1:中英文真实桌面设置页均通过模型搜索、实际思考等级、默认 off、策略自动保存、重进及清空恢复默认。
  • pnpm test:e2e:permissions-desktop:自动批准、转人工、停止和停止后恢复四个完整桌面场景通过。

英文设置页本轮首次在搜索框聚焦等待处超时,立即重跑通过;该偶发测试超时仍需留意。全量 JS / Rust 测试本轮未重跑;原草稿记录了在对应主线也可复现的 Windows 路径、Shell 和源级契约测试失败。远端 CI 结果以本次推送后的实际运行结果为准。真实付费模型及 macOS/Linux 原生桌面未验证。

Visual evidence

权限卡片为隔离组件夹具截图;设置页为真实 Windows 桌面截图,使用本地测试模型。原草稿没有可用的修改前截图,因此下列图片只展示本次候选状态。

  • 权限卡片:权限卡片
  • 独立权限入口、默认 off 和空白策略:权限设置默认状态
  • 搜索审核模型:审核模型菜单
  • 模型实际支持的思考等级:审核思考等级
  • 自动保存的自定义策略:自定义策略

Refs #952。该 Issue 仍跟踪后续安全隔离工作,本阶段不关闭它。

Separate the approval reviewer from permission mode while keeping the
host authoritative over scoped grants and one-use execution permits.
Default to human review and preserve native Pi session boundaries.

Cover approval, takeover, cancellation and recovery across the runtime
and desktop, with migration and security contracts documented.
Carry the contributor draft and prevalidated main integration into the task branch while preserving the original PR commit for final ancestry.
Keep permission review production code below the architecture limit while retaining the existing test coverage and behavior.
Place permission and review controls in the left settings navigation. Keep the custom policy field minimal and auto-saving, and show off plus only the selected model's available thinking levels.
Include current main fixes in the draft candidate and retain both permission-review and SVG-attachment specification links.
Keep public screenshots of the isolated permission card and settings paths with the draft PR so maintainers can inspect the visible controls.
@hui455
hui455 marked this pull request as ready for review September 23, 2026 18:22

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant