Synced from monorepo
Changes: - Non-blocking coding-data sharing upsell banner - Consolidate remediation in Doctor - Auto mode defers fail-closed gate asks to the classifier - Coalesce marketplace list fetches - Allow removing a marketplace source by name - Contain hung git marketplace sources (timeouts, non-blocking refresh, unbrick modal) - Label failed workspace RPCs with error_kind - Drop redundant explicit tonic/prost deps from xai-grok-shell - Report real exit codes for completed background shells - Narrow the date-rollover reminder to date-bearing templates - Wire toolOverrides through the session and agent - Security: Bash(git:*) allowlist matches whole command chain by prefix - Split prompt-trigger telemetry and record classifier provenance - Raise connectors-manager timeout to 60s - Auto classifier honors recorded approvals for repeat actions - Apply doctor fixes in the TUI - Auto-mode classifier timeouts prompt instead of silently denying - Scope subagent completion drains to the owning session - Add the toolOverrides wire types - Set client_identifier=grok-agent-sdk - Accept both spellings of the workspace-teleport kill switch - Persist one-shot occurrence journal - Stop turns that poll the exact same tool call 16x in a row - Copy compaction checkpoint files when forking sessions - Auto-focus permission prompt from scrollback - Esc cancels the running turn in non-vim and minimal modes - List Ctrl+Z undo and redo in keyboard shortcuts - Out-of-process macOS mic capture - Show active auth mode on session-info - Install the npm binary under $GROK_HOME - Remove hover/click dead zones between dashboard items - Route startup warnings to doctor - Document [feedback.user] author identity config - Extend bang command timeout - Close combine-queued edit-hold race - Integrate relocation recovery - Expose privacy notice rollout flag - Break harness discovery ref cycle so connections can idle-evict - Shift/Alt+Enter inserts newline when editing a queued prompt - Gate project Claude permissions on folder trust - Echo response.create.event_id on response.created - Toast when session creation fails from disk full - Add shared test process lifecycle - Enable dynamic workflows by default - Add relocation transaction state machine - Add shared test sandbox - Surface auth failures on model-switch compact - Persist durable scheduler expiry - Confirm before removing extensions-modal items - Re-run compact and prompt after login when compact hit expired auth - Recap sends hosted tools under backend search
This commit is contained in:
parent
3af4d5d398
commit
a5727c5960
482 changed files with 37627 additions and 13402 deletions
|
|
@ -204,13 +204,19 @@ fn toml_to_json(v: &toml::Value) -> Value {
|
|||
/// merges rules from requirements.toml, managed-settings.json,
|
||||
/// managed_config.toml, config.toml, and `.claude/settings.json`.
|
||||
///
|
||||
/// `project_trusted` gates project-tier permission sources (same contract as
|
||||
/// env/hooks/plugins). Hub/cloud callers outside the local folder-trust model
|
||||
/// should pass `true`.
|
||||
///
|
||||
/// Returns a JSON object with `sources`, `loaded` (rule count), and
|
||||
/// `skipped` (unrecognized rules). Returns `Value::Null` if no
|
||||
/// permission sources are configured.
|
||||
pub async fn load_permissions(root_cwd: &Path) -> Value {
|
||||
pub async fn load_permissions(root_cwd: &Path, project_trusted: bool) -> Value {
|
||||
use crate::permission::resolution;
|
||||
|
||||
let Some(resolved) = resolution::resolve_permissions_with_provenance(root_cwd).await else {
|
||||
let Some(resolved) =
|
||||
resolution::resolve_permissions_with_provenance(root_cwd, project_trusted).await
|
||||
else {
|
||||
return Value::Null;
|
||||
};
|
||||
|
||||
|
|
@ -536,7 +542,7 @@ mod tests {
|
|||
#[tokio::test]
|
||||
async fn load_permissions_returns_valid_json() {
|
||||
let tmp = tempfile::tempdir().unwrap();
|
||||
let result = load_permissions(tmp.path()).await;
|
||||
let result = load_permissions(tmp.path(), true).await;
|
||||
// Result is either Null (no sources) or an object with
|
||||
// sources, loaded, and skipped fields. Both branches assert
|
||||
// a definite pass criterion.
|
||||
|
|
@ -563,7 +569,7 @@ mod tests {
|
|||
)
|
||||
.unwrap();
|
||||
|
||||
let result = load_permissions(tmp.path()).await;
|
||||
let result = load_permissions(tmp.path(), true).await;
|
||||
assert!(result.is_object(), "should return an object, got {result}");
|
||||
assert!(result["sources"].is_array(), "sources should be an array");
|
||||
assert!(result["loaded"].is_number(), "loaded should be a number");
|
||||
|
|
|
|||
Loading…
Reference in a new issue