fix(code): avoid redundant Auto approval prompts - #4993
Merged
Mason Daugherty (mdrxy) merged 3 commits intoJul 23, 2026
Conversation
This was referenced Jul 23, 2026
…ndant-auto-approvals # Conflicts: # libs/code/deepagents_code/_cli_context.py # libs/code/deepagents_code/tui/textual_adapter.py
Mason Daugherty (mdrxy)
deleted the
mdrxy/code/avoid-redundant-auto-approvals
branch
July 23, 2026 13:37
Mason Daugherty (mdrxy)
pushed a commit
that referenced
this pull request
Jul 24, 2026
> [!CAUTION] > Merging this PR will automatically publish to **PyPI** and create a **GitHub release**. For the full release process, see [`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md). --- _Release notes preview: keep this section in sync with the package `CHANGELOG.md`. The published GitHub release body is extracted from the merged `CHANGELOG.md` by `release.yml`, not from this PR description._ --- ## [0.1.46](deepagents-code==0.1.45...deepagents-code==0.1.46) (2026-07-24) ### Highlights - Auto mode is now generally available. [#4957](#4957) - Added configurable Auto goal-criteria acceptance. [#4940](#4940) - Improved Auto behavior by authorizing actions from active goal/rubric directives, avoiding redundant approval prompts, showing the enable notice only on first global enable, deduplicating classifier-unavailable transcript spam, logging underlying classifier failures, and reporting classifier timeout budgets. [#5017](#5017) [#4993](#4993) [#5012](#5012) [#5013](#5013) [#5011](#5011) [#5025](#5025) - Added Hooks v2 capability snapshots and session transcripts, and hardened Hooks v2 command execution. [#4916](#4916) [#4918](#4918) [#4917](#4917) - Raised the agent recursion limit to 2000 and made it configurable. [#4994](#4994) ### Improvements and fixes - Let the rubric grader inspect working-directory files, show rubric grader defaults, and improved `/rubric` help and empty-state messaging. [#4835](#4835) [#4966](#4966) [#5015](#5015) - Unified goal activation signaling. [#4980](#4980) - Made Version, Model, and CWD copyable in the Debug Console. [#4975](#4975) - Improved `config get` output when a key is missing. [#4976](#4976) - Aborted YOLO launch on `Ctrl+C`/`Ctrl+D` and made the YOLO warning friendlier for new users. [#4953](#4953) [#4950](#4950) - Updated LangSmith handling: secret redaction is disabled by default, `/trace` now flags empty env overrides that shadow the LangSmith key, and the default US endpoint is no longer treated as a custom target. [#4970](#4970) [#4996](#4996) [#5022](#5022) - Injected OpenAI `prompt_cache_key` for any OpenAI-provider endpoint. [#4995](#4995) - Improved tool and schema presentation: finished calls stay on the live tool-group line, first-party tool schemas now include field descriptions, and `web_search`/`fetch_url` tool descriptions were trimmed. [#4927](#4927) [#5019](#5019) [#5016](#5016) - Omitted `plugins/` and `conversation_history/` from the `/agent` picker. [#4991](#4991) - Made selector modal backdrop dimming consistent. [#4990](#4990) - Restored the `"Server log preserved at:"` notice on exit. [#4999](#4999) - Used the SDK pin as the effective editable version. [#4949](#4949) _End release notes preview._ --- > [!NOTE] > A **New Contributors** section is appended to the GitHub release notes automatically at publish time (see [Release Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline), step 2). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Marcelo5444
pushed a commit
to Marcelo5444/deepagents
that referenced
this pull request
Jul 30, 2026
Supersedes langchain-ai#4946 Supersedes langchain-ai#4947 Auto mode no longer interrupts users when an action is already covered by their explicit `ask_user` selection or when the agent is performing the built-in conversation-compaction operation. --- Previously, Auto mode could ask users to approve an action immediately after they selected it in an `ask_user` prompt. It could also pause autonomous work to approve `compact_conversation`, even though compaction is an internal maintenance operation without an externally consequential effect. The two cases now follow separate trust rules: - Server-created, same-turn receipts allow the authorization classifier to consider only the user's selected answer for the exact subsequent action. The receipt is bound to the LangGraph execution thread, the active turn, and the originating `ask_user` tool call, and is validated against the full checkpoint history so it survives conversation compaction. Only the latest `ask_user` exchange in the turn is admitted; model-authored questions, unselected choices, and prior answers are excluded. Invalid, stale, ambiguous, or overly broad consent continues through the normal approval path. - The trusted built-in `compact_conversation` operation is deterministically allowed without classifier or human review. The exemption is guarded by exact tool-object identity, not by name, so a caller-supplied tool with the same name cannot exploit it. At most one trusted compaction call is allowed per action batch; duplicates are denied without classifier review, and that denial is preserved across all fallback paths. <details> <summary>Test plan</summary> Targeted Auto-mode, ask_user, agent-wiring, and Textual-adapter tests: ``` uv run --group test pytest tests/unit_tests/test_ask_user_middleware.py \ tests/unit_tests/test_auto_mode.py \ tests/unit_tests/tui/test_textual_adapter.py::TestExecuteTaskTextualTurnMarkers \ tests/unit_tests/test_agent.py::test_cli_context_schema_fields_mirror_typed_dict \ tests/unit_tests/test_agent.py::TestCreateCliAgentInterpreterWiring \ --disable-socket --allow-unix-socket --benchmark-disable -q ``` Result: 135 passed. Full package unit tests: ``` make test ``` Result: 10617 passed, 4 skipped, 6 pre-existing failures in `TestLangsmithSecretRedaction` (env-dependent, fail on clean `origin/main`). Lint, format, type check, and commands catalog: ``` make lint ``` Result: All checks passed. A real LangGraph interrupt/resume test (`test_real_agent_resume_forwards_ask_user_receipt_to_classifier`) verifies the full path: `ask_user` interrupt → checkpoint resume → receipt minting with real `execution_info.thread_id` → classifier sees `same_turn_user_answers` → action executes without a second HITL prompt. A compiled-graph identity test (`test_compiled_agent_preserves_canonical_compaction_tool_identity`) verifies the canonical `CLICompactionMiddleware` tool object survives `create_deep_agent`'s middleware merge into the compiled `ToolNode`, and that `AutoModeHITLMiddleware._trusted_compaction_tool` references that same object. The 6 `TestLangsmithSecretRedaction` failures are pre-existing and env-dependent (real LangSmith credentials in the local environment); they fail identically on clean `origin/main` and are unrelated to this change. </details>
Marcelo5444
pushed a commit
to Marcelo5444/deepagents
that referenced
this pull request
Jul 30, 2026
> [!CAUTION] > Merging this PR will automatically publish to **PyPI** and create a **GitHub release**. For the full release process, see [`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md). --- _Release notes preview: keep this section in sync with the package `CHANGELOG.md`. The published GitHub release body is extracted from the merged `CHANGELOG.md` by `release.yml`, not from this PR description._ --- ## [0.1.46](langchain-ai/deepagents@deepagents-code==0.1.45...deepagents-code==0.1.46) (2026-07-24) ### Highlights - Auto mode is now generally available. [langchain-ai#4957](langchain-ai#4957) - Added configurable Auto goal-criteria acceptance. [langchain-ai#4940](langchain-ai#4940) - Improved Auto behavior by authorizing actions from active goal/rubric directives, avoiding redundant approval prompts, showing the enable notice only on first global enable, deduplicating classifier-unavailable transcript spam, logging underlying classifier failures, and reporting classifier timeout budgets. [langchain-ai#5017](langchain-ai#5017) [langchain-ai#4993](langchain-ai#4993) [langchain-ai#5012](langchain-ai#5012) [langchain-ai#5013](langchain-ai#5013) [langchain-ai#5011](langchain-ai#5011) [langchain-ai#5025](langchain-ai#5025) - Added Hooks v2 capability snapshots and session transcripts, and hardened Hooks v2 command execution. [langchain-ai#4916](langchain-ai#4916) [langchain-ai#4918](langchain-ai#4918) [langchain-ai#4917](langchain-ai#4917) - Raised the agent recursion limit to 2000 and made it configurable. [langchain-ai#4994](langchain-ai#4994) ### Improvements and fixes - Let the rubric grader inspect working-directory files, show rubric grader defaults, and improved `/rubric` help and empty-state messaging. [langchain-ai#4835](langchain-ai#4835) [langchain-ai#4966](langchain-ai#4966) [langchain-ai#5015](langchain-ai#5015) - Unified goal activation signaling. [langchain-ai#4980](langchain-ai#4980) - Made Version, Model, and CWD copyable in the Debug Console. [langchain-ai#4975](langchain-ai#4975) - Improved `config get` output when a key is missing. [langchain-ai#4976](langchain-ai#4976) - Aborted YOLO launch on `Ctrl+C`/`Ctrl+D` and made the YOLO warning friendlier for new users. [langchain-ai#4953](langchain-ai#4953) [langchain-ai#4950](langchain-ai#4950) - Updated LangSmith handling: secret redaction is disabled by default, `/trace` now flags empty env overrides that shadow the LangSmith key, and the default US endpoint is no longer treated as a custom target. [langchain-ai#4970](langchain-ai#4970) [langchain-ai#4996](langchain-ai#4996) [langchain-ai#5022](langchain-ai#5022) - Injected OpenAI `prompt_cache_key` for any OpenAI-provider endpoint. [langchain-ai#4995](langchain-ai#4995) - Improved tool and schema presentation: finished calls stay on the live tool-group line, first-party tool schemas now include field descriptions, and `web_search`/`fetch_url` tool descriptions were trimmed. [langchain-ai#4927](langchain-ai#4927) [langchain-ai#5019](langchain-ai#5019) [langchain-ai#5016](langchain-ai#5016) - Omitted `plugins/` and `conversation_history/` from the `/agent` picker. [langchain-ai#4991](langchain-ai#4991) - Made selector modal backdrop dimming consistent. [langchain-ai#4990](langchain-ai#4990) - Restored the `"Server log preserved at:"` notice on exit. [langchain-ai#4999](langchain-ai#4999) - Used the SDK pin as the effective editable version. [langchain-ai#4949](langchain-ai#4949) _End release notes preview._ --- > [!NOTE] > A **New Contributors** section is appended to the GitHub release notes automatically at publish time (see [Release Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline), step 2). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #4946
Supersedes #4947
Auto mode no longer interrupts users when an action is already covered by their explicit
ask_userselection or when the agent is performing the built-in conversation-compaction operation.Previously, Auto mode could ask users to approve an action immediately after they selected it in an
ask_userprompt. It could also pause autonomous work to approvecompact_conversation, even though compaction is an internal maintenance operation without an externally consequential effect.The two cases now follow separate trust rules:
ask_usertool call, and is validated against the full checkpoint history so it survives conversation compaction. Only the latestask_userexchange in the turn is admitted; model-authored questions, unselected choices, and prior answers are excluded. Invalid, stale, ambiguous, or overly broad consent continues through the normal approval path.compact_conversationoperation is deterministically allowed without classifier or human review. The exemption is guarded by exact tool-object identity, not by name, so a caller-supplied tool with the same name cannot exploit it. At most one trusted compaction call is allowed per action batch; duplicates are denied without classifier review, and that denial is preserved across all fallback paths.Test plan
Targeted Auto-mode, ask_user, agent-wiring, and Textual-adapter tests:
Result: 135 passed.
Full package unit tests:
Result: 10617 passed, 4 skipped, 6 pre-existing failures in
TestLangsmithSecretRedaction(env-dependent, fail on cleanorigin/main).Lint, format, type check, and commands catalog:
Result: All checks passed.
A real LangGraph interrupt/resume test (
test_real_agent_resume_forwards_ask_user_receipt_to_classifier) verifies the full path:ask_userinterrupt → checkpoint resume → receipt minting with realexecution_info.thread_id→ classifier seessame_turn_user_answers→ action executes without a second HITL prompt.A compiled-graph identity test (
test_compiled_agent_preserves_canonical_compaction_tool_identity) verifies the canonicalCLICompactionMiddlewaretool object survivescreate_deep_agent's middleware merge into the compiledToolNode, and thatAutoModeHITLMiddleware._trusted_compaction_toolreferences that same object.The 6
TestLangsmithSecretRedactionfailures are pre-existing and env-dependent (real LangSmith credentials in the local environment); they fail identically on cleanorigin/mainand are unrelated to this change.