mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-09-02 17:49:20 +00:00
fix(approval): make "always" auto-approve work for credentialed HTTP requests (#1257)
The HTTP tool returned `ApprovalRequirement::Always` for requests with credentials, but `Always` is hardcoded to ignore the session auto-approve set. This meant users who clicked "always" were re-prompted on every subsequent HTTP call — the UI offered "always" but the backend ignored it. Two fixes: 1. HTTP credentialed requests now return `UnlessAutoApproved` instead of `Always`, so the session auto-approve set is respected. 2. `StatusUpdate::ApprovalNeeded` now carries `allow_always: bool`. All channel UIs (Telegram, Slack, Signal, REPL, Web) conditionally hide the "always" option when a tool truly requires per-invocation approval (`ApprovalRequirement::Always`, e.g. destructive shell commands). Also boxes `PendingApproval` in `AgenticLoopResult::NeedApproval` to fix a pre-existing clippy `large_enum_variant` warning. Regression tests included (test_credentialed_requests_respect_auto_approve, test_allow_always_matches_approval_requirement) but CI heuristic cannot detect them in cross-fork PR diffs. [skip-regression-check] Co-authored-by: Tyler <[email protected]>
This commit is contained in:
@@ -2043,6 +2043,7 @@ impl WasmChannel {
|
||||
tool_name,
|
||||
description,
|
||||
parameters,
|
||||
allow_always,
|
||||
..
|
||||
} => {
|
||||
// WASM channels (Telegram, Slack, etc.) cannot render
|
||||
@@ -2081,6 +2082,11 @@ impl WasmChannel {
|
||||
})
|
||||
.unwrap_or_default();
|
||||
|
||||
let reply_hint = if *allow_always {
|
||||
"Reply \"yes\" to approve, \"no\" to deny, or \"always\" to auto-approve."
|
||||
} else {
|
||||
"Reply \"yes\" to approve or \"no\" to deny."
|
||||
};
|
||||
let prompt = format!(
|
||||
"Approval needed: {tool_name}\n\
|
||||
{description}\n\
|
||||
@@ -2088,7 +2094,7 @@ impl WasmChannel {
|
||||
Parameters:\n\
|
||||
{params_preview}\n\
|
||||
\n\
|
||||
Reply \"yes\" to approve, \"no\" to deny, or \"always\" to auto-approve."
|
||||
{reply_hint}"
|
||||
);
|
||||
|
||||
let metadata_json = serde_json::to_string(metadata).unwrap_or_default();
|
||||
@@ -2981,15 +2987,23 @@ fn status_to_wit(
|
||||
request_id,
|
||||
tool_name,
|
||||
description,
|
||||
allow_always,
|
||||
..
|
||||
} => wit_channel::StatusUpdate {
|
||||
status: wit_channel::StatusType::ApprovalNeeded,
|
||||
message: format!(
|
||||
"Approval needed for tool '{}'. {}\nRequest ID: {}\nReply with: yes (or /approve), no (or /deny), or always (or /always).",
|
||||
tool_name, description, request_id
|
||||
),
|
||||
metadata_json,
|
||||
},
|
||||
} => {
|
||||
let reply_hint = if *allow_always {
|
||||
"yes (or /approve), no (or /deny), or always (or /always)"
|
||||
} else {
|
||||
"yes (or /approve) or no (or /deny)"
|
||||
};
|
||||
wit_channel::StatusUpdate {
|
||||
status: wit_channel::StatusType::ApprovalNeeded,
|
||||
message: format!(
|
||||
"Approval needed for tool '{}'. {}\nRequest ID: {}\nReply with: {}.",
|
||||
tool_name, description, request_id, reply_hint
|
||||
),
|
||||
metadata_json,
|
||||
}
|
||||
}
|
||||
StatusUpdate::JobStarted {
|
||||
job_id,
|
||||
title,
|
||||
@@ -3670,6 +3684,7 @@ mod tests {
|
||||
tool_name: "http_request".into(),
|
||||
description: "Fetch weather".into(),
|
||||
parameters: serde_json::json!({"url": "https://wttr.in"}),
|
||||
allow_always: true,
|
||||
},
|
||||
&metadata,
|
||||
)
|
||||
@@ -4131,6 +4146,7 @@ mod tests {
|
||||
tool_name: "http_request".to_string(),
|
||||
description: "Fetch weather data".to_string(),
|
||||
parameters: serde_json::json!({"url": "https://api.weather.test"}),
|
||||
allow_always: true,
|
||||
},
|
||||
&metadata,
|
||||
)
|
||||
@@ -4156,6 +4172,7 @@ mod tests {
|
||||
tool_name: "http_request".to_string(),
|
||||
description: "Fetch weather data".to_string(),
|
||||
parameters: serde_json::json!({"url": "https://api.weather.test"}),
|
||||
allow_always: true,
|
||||
},
|
||||
&metadata,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user