fix(approval): carry allow_permanent to TUI + desktop approval prompts

When a tirith content-security warning is present the approval backend
forces allow_permanent=False and silently downgrades an "always" choice to
session scope (the persistence loop in check_all_command_guards only honors
"always" → permanent when no tirith finding exists). But the gateway notify
payload that drives the TUI and the Electron desktop app never carried that
flag, so both surfaces always rendered "Always allow" — offering a permanent
allow the backend would quietly refuse to persist.

Plumb allow_permanent end-to-end:
- tools/approval.py: include `allow_permanent: not has_tirith` in the gateway
  approval_data the notify callback emits as `approval.request`.
- ui-tui: thread `allowPermanent` through the event handler, gateway types,
  and ApprovalReq; ApprovalPrompt drops the "always" option (and renumbers the
  quick-pick keys) when it's false.
- apps/desktop: thread `allow_permanent` through the gateway payload type, the
  per-session approval store, and the inline ApprovalBar, which now hides the
  "Always allow…" dropdown item when permanent allow is disallowed — reusing
  the existing DropdownMenu / confirm-Dialog UI.

The desktop/TUI render path for approvals already landed in #38578 (the root
cause of approvals not surfacing in the GUI); this completes the salvage of
#37856 by carrying allow_permanent across both surfaces. #37856's original
thread-local _block() approach is dropped: desktop/TUI approvals resolve via
approval.respond → resolve_gateway_approval (the per-session queue), not the
_block()/request_id correlation, so a worker-thread callback waiting on _block
would never be released by the real UI.

Tests: gateway notify payload carries allow_permanent (True without tirith,
False with a tirith warning); ui-tui approvalAction reduced option set +
event-handler allowPermanent propagation; desktop store round-trip + the
ApprovalBar showing/hiding "Always allow".

Supersedes #37856
Closes #37812

Co-authored-by: LeonSGP43 <cine.dreamer.one@gmail.com>
This commit is contained in:
Brooklyn Nicholson
2026-06-11 18:23:59 -05:00
co-authored by LeonSGP43
parent d221e369b8
commit 81436e143e
14 changed files with 214 additions and 28 deletions
+24 -13
View File
@@ -7,10 +7,16 @@ import type { ApprovalReq, ClarifyReq, ConfirmReq } from '../types.js'
import { TextInput } from './textInput.js'
const OPTS = ['once', 'session', 'always', 'deny'] as const
const APPROVAL_OPTS = ['once', 'session', 'always', 'deny'] as const
// When the backend disallows a permanent allow (tirith content-security
// warning present) the "always" option is dropped — picking it would only
// be silently downgraded to session scope, so don't offer it.
const APPROVAL_OPTS_NO_ALWAYS = ['once', 'session', 'deny'] as const
const LABELS = { always: 'Always allow', deny: 'Deny', once: 'Allow once', session: 'Allow this session' } as const
const CMD_PREVIEW_LINES = 10
type ApprovalChoice = 'always' | 'deny' | 'once' | 'session'
type ApprovalKey = {
downArrow?: boolean
escape?: boolean
@@ -18,10 +24,7 @@ type ApprovalKey = {
upArrow?: boolean
}
type ApprovalAction =
| { kind: 'choose'; choice: (typeof OPTS)[number] }
| { kind: 'move'; delta: -1 | 1 }
| { kind: 'noop' }
type ApprovalAction = { kind: 'choose'; choice: ApprovalChoice } | { kind: 'move'; delta: -1 | 1 } | { kind: 'noop' }
/**
* Pure key-dispatch for the approval prompt — exported so the regression
@@ -34,26 +37,31 @@ type ApprovalAction =
* for approvals). Numbers 1..OPTS.length pick the labelled choice. Enter
* confirms the current selection. ↑/↓ moves the selection within bounds.
*/
export function approvalAction(ch: string, key: ApprovalKey, sel: number): ApprovalAction {
export function approvalAction(
ch: string,
key: ApprovalKey,
sel: number,
opts: readonly ApprovalChoice[] = APPROVAL_OPTS
): ApprovalAction {
if (key.escape) {
return { kind: 'choose', choice: 'deny' }
}
const n = parseInt(ch, 10)
if (n >= 1 && n <= OPTS.length) {
return { kind: 'choose', choice: OPTS[n - 1]! }
if (n >= 1 && n <= opts.length) {
return { kind: 'choose', choice: opts[n - 1]! }
}
if (key.return) {
return { kind: 'choose', choice: OPTS[sel]! }
return { kind: 'choose', choice: opts[sel]! }
}
if (key.upArrow && sel > 0) {
return { kind: 'move', delta: -1 }
}
if (key.downArrow && sel < OPTS.length - 1) {
if (key.downArrow && sel < opts.length - 1) {
return { kind: 'move', delta: 1 }
}
@@ -62,9 +70,10 @@ export function approvalAction(ch: string, key: ApprovalKey, sel: number): Appro
export function ApprovalPrompt({ onChoice, req, t }: ApprovalPromptProps) {
const [sel, setSel] = useState(0)
const opts = req.allowPermanent === false ? APPROVAL_OPTS_NO_ALWAYS : APPROVAL_OPTS
useInput((ch, key) => {
const action = approvalAction(ch, key, sel)
const action = approvalAction(ch, key, sel, opts)
if (action.kind === 'choose') {
onChoice(action.choice)
@@ -99,7 +108,7 @@ export function ApprovalPrompt({ onChoice, req, t }: ApprovalPromptProps) {
<Text />
{OPTS.map((o, i) => (
{opts.map((o, i) => (
<Text key={o}>
<Text bold={sel === i} color={sel === i ? t.color.warn : t.color.muted} inverse={sel === i}>
{sel === i ? '▸ ' : ' '}
@@ -108,7 +117,9 @@ export function ApprovalPrompt({ onChoice, req, t }: ApprovalPromptProps) {
</Text>
))}
<Text color={t.color.muted}>/ select · Enter confirm · 1-4 quick pick · Esc/Ctrl+C deny</Text>
<Text color={t.color.muted}>
/ select · Enter confirm · 1-{opts.length} quick pick · Esc/Ctrl+C deny
</Text>
</Box>
)
}