Skip to content

fix(approval): auto-approve commands when alwaysAllowExecute=true without allowlist - #3

Merged
hacker-b2k merged 1 commit into
mainfrom
fix/brrr-auto-approve-commands
Jun 24, 2026
Merged

fix(approval): auto-approve commands when alwaysAllowExecute=true without allowlist#3
hacker-b2k merged 1 commit into
mainfrom
fix/brrr-auto-approve-commands

Conversation

@hacker-b2k

Copy link
Copy Markdown
Owner

Problem

BRRR mode (all 7 auto-approval toggles ON) was still asking for permission on commands. The UI showed all toggles enabled but the engine still prompted the user.

Root Cause

getCommandDecision() returned "ask_user" when �llowedCommands array was empty, even with �lwaysAllowExecute=true. The auto-approval engine required explicit entries in �llowedCommands to approve commands.

Fix

In src/core/auto-approval/index.ts: when �lwaysAllowExecute=true and �llowedCommands is empty, treat as wildcard ["*"]. All commands auto-approve (except those matching deniedCommands) — aligning engine behavior with the BRRR UI expectation.

Verification

  • All 39 auto-approval tests pass
  • TypeScript compilation passes
  • Lint passes

…hout allowlist

BRRR mode (all 7 toggles ON) was still asking for permission on commands
because getCommandDecision() returned 'ask_user' when allowedCommands
array was empty, even with alwaysAllowExecute=true.

The fix treats empty allowedCommands as wildcard ['*'] when
alwaysAllowExecute=true, so all commands auto-approve (except those
matching deniedCommands). This aligns the engine behavior with the
BRRR UI expectation that 'allow all' means ALL.
@hacker-b2k
hacker-b2k merged commit 91afe61 into main Jun 24, 2026
@hacker-b2k
hacker-b2k deleted the fix/brrr-auto-approve-commands branch June 24, 2026 05:56
hacker-b2k pushed a commit that referenced this pull request Jul 31, 2026
…tory, dry_run, batch replace, enhanced rename

Issue #1: search_replace error now shows closest matching text with line number
Issue #2: read_spec mode='headings' returns only heading lines with line numbers
Issue #3: read_spec mode='history' returns revision list; revision=N reads specific version
Issue #4: renameWorkspace enhanced heading patterns (suffix, contains, case-insensitive)
Issue Zoo-Code-Org#5: write_spec dry_run=true previews changes without applying
Issue Zoo-Code-Org#6: write_spec replacements=[] for atomic batch search_replace operations

Files: specMerge.ts, ReadSpecTool.ts, WriteSpecTool.ts, SpecService.ts, read_spec.ts, write_spec.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant