fix(approval): auto-approve commands when alwaysAllowExecute=true without allowlist - #3
Merged
Merged
Conversation
…hout allowlist BRRR mode (all 7 toggles ON) was still asking for permission on commands because getCommandDecision() returned 'ask_user' when allowedCommands array was empty, even with alwaysAllowExecute=true. The fix treats empty allowedCommands as wildcard ['*'] when alwaysAllowExecute=true, so all commands auto-approve (except those matching deniedCommands). This aligns the engine behavior with the BRRR UI expectation that 'allow all' means ALL.
hacker-b2k
pushed a commit
that referenced
this pull request
Jul 31, 2026
…tory, dry_run, batch replace, enhanced rename Issue #1: search_replace error now shows closest matching text with line number Issue #2: read_spec mode='headings' returns only heading lines with line numbers Issue #3: read_spec mode='history' returns revision list; revision=N reads specific version Issue #4: renameWorkspace enhanced heading patterns (suffix, contains, case-insensitive) Issue Zoo-Code-Org#5: write_spec dry_run=true previews changes without applying Issue Zoo-Code-Org#6: write_spec replacements=[] for atomic batch search_replace operations Files: specMerge.ts, ReadSpecTool.ts, WriteSpecTool.ts, SpecService.ts, read_spec.ts, write_spec.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
BRRR mode (all 7 auto-approval toggles ON) was still asking for permission on commands. The UI showed all toggles enabled but the engine still prompted the user.
Root Cause
getCommandDecision() returned "ask_user" when �llowedCommands array was empty, even with �lwaysAllowExecute=true. The auto-approval engine required explicit entries in �llowedCommands to approve commands.
Fix
In src/core/auto-approval/index.ts: when �lwaysAllowExecute=true and �llowedCommands is empty, treat as wildcard ["*"]. All commands auto-approve (except those matching deniedCommands) — aligning engine behavior with the BRRR UI expectation.
Verification