Repository navigation
Ask before every command that can edit a folder - #759
Open
NathanTarbert wants to merge 3 commits into
Open
NathanTarbert wants to merge 3 commits into
NathanTarbert wants to merge 3 commits into
Conversation
"Always allow in this folder" now covers a Bot's read-only commands. A command that can edit files in an approved folder shows the desktop prompt every time, the prompt says so, and it no longer offers to stop asking for that command. Read-only commands in a folder already set to always allow behave as before.
NathanTarbert
requested review from
MikeRyanDev,
davidmckayv,
guidovizoso,
mxmzb and
tylerslaton
as code owners
October 8, 2026 15:11
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
On the desktop app, a Bot can run commands in a folder someone has shared with it. Each command shows a prompt first, and that prompt can offer "Always allow in this folder" so the person stops being asked.
Some commands can only read the folder. Others can also change or delete files in it. After this change, "Always allow in this folder" only covers the read-only kind. A command that can change files always shows the prompt, and that prompt doesn't offer "Always allow".
Folders already set to "Always allow" keep working the same way for read-only commands.
The decision is made in
command_approvalindesktop/src-tauri/src/host_access.rs, which now gets told whether the command can change files. The dialog indesktop/src-tauri/src/desktop_host_access.rspasses that through. Its wording now says "Always allow" covers read-only commands, and that commands which can edit files still ask every time.Where it runs
On the desktop app only. No new state, nothing serialised, nothing fanned out, and no new listener, port or schedule. Nothing on the server changes, so the second replica behaves as it did before.
Boundary and audit
Changelog
CHANGELOG.mdunderUnreleased.Proof
A new test,
a_command_that_can_edit_the_folder_asks_even_where_always_allowed, covers an editing command under each setting. The existing approval test is updated for the extra argument.cargo fmt --checkpasses.cargo clippy --all-targets -- -D warningsis clean.cargo test --locked --lib --bins: 538 passed and 149 passed, 0 failed.