Skip to content

Ask before every command that can edit a folder - #759

Open
NathanTarbert wants to merge 3 commits into
CopilotKit:mainfrom
NathanTarbert:fix/always-here-read-only-commands
Open

NathanTarbert wants to merge 3 commits into
CopilotKit:mainfrom
NathanTarbert:fix/always-here-read-only-commands

Conversation

@NathanTarbert

@NathanTarbert NathanTarbert commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

What this changes

On the desktop app, a Bot can run commands in a folder someone has shared with it. Each command shows a prompt first, and that prompt can offer "Always allow in this folder" so the person stops being asked.

Some commands can only read the folder. Others can also change or delete files in it. After this change, "Always allow in this folder" only covers the read-only kind. A command that can change files always shows the prompt, and that prompt doesn't offer "Always allow".

Folders already set to "Always allow" keep working the same way for read-only commands.

The decision is made in command_approval in desktop/src-tauri/src/host_access.rs, which now gets told whether the command can change files. The dialog in desktop/src-tauri/src/desktop_host_access.rs passes that through. Its wording now says "Always allow" covers read-only commands, and that commands which can edit files still ask every time.

Where it runs

On the desktop app only. No new state, nothing serialised, nothing fanned out, and no new listener, port or schedule. Nothing on the server changes, so the second replica behaves as it did before.

Boundary and audit

  • Every acting call still goes through the gateway: the server path is unchanged, and the desktop asks in more cases, never fewer.
  • No new refusals or failures. A command the person denies at the prompt is recorded the way it already is.
  • Nothing new trusted from the client.

Changelog

  • A line in CHANGELOG.md under Unreleased.

Proof

A new test, a_command_that_can_edit_the_folder_asks_even_where_always_allowed, covers an editing command under each setting. The existing approval test is updated for the extra argument.

  • cargo fmt --check passes.
  • cargo clippy --all-targets -- -D warnings is clean.
  • cargo test --locked --lib --bins: 538 passed and 149 passed, 0 failed.

"Always allow in this folder" now covers a Bot's read-only commands. A
command that can edit files in an approved folder shows the desktop
prompt every time, the prompt says so, and it no longer offers to stop
asking for that command. Read-only commands in a folder already set to
always allow behave as before.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant