Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Decide whether a coordinator may lift a headless worker's refusal (the trust boundary #68 defers)

Open
#142 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Active
Tech stack
typescript

Research direction

Start with the refusal key resolution at index.ts:3203, liftRefusals at index.ts:3262, and the dialog-approval and headless checks at index.ts:4302 and index.ts:4333. Decide and document the trust-boundary policy, then add tests covering coordinator authorization, critical refusals, and attribution of both identities in decisions.jsonl. Done means the chosen constraints hold and the agent-on-behalf-of-user behavior is documented.

Written by the indexing model from the issue text.

Description

enhancement ready-for-human

Split from #68 by your decision there: the mechanical half (narrowing the refusal key) is agent work on that issue, and this is the trust boundary it deliberately does not touch.

The gap. A headless worker cannot lift a refusal. liftRefusals (index.ts:3262) runs at exactly one call site, inside the dialog-approval handler (index.ts:4333), and that handler is only reachable when ctx.hasUI — index.ts:4302 collapses every headless hit into a block before any lift path. A refusal a coordinator considers wrong therefore stays for the whole session.

Why it is a design call and not a fix. Building the channel means answering who may lift a refusal taken on another agent's command, whether an agent may approve on a user's behalf, and whether a critical refusal is ever liftable. Those are the same questions the persistent-grant surface answers for a human, asked about a machine, and the answer decides how much of the prod-secrets posture moves.

Options as presented.

  1. A registered tool a coordinator may call, with headless coordinators rejected by construction, critical refusals permanently unliftable, and the hop recorded in decisions.jsonl with both identities. Cost: an agent-to-agent approval path exists at all.
  2. Lift only with a human-issued token in the environment, so an unattended session still cannot lift. Cost: it is a human approval with extra steps in the common case.
  3. Leave it unliftable, documented with the reason. Cost: a wedged headless worker is restart-only.

Acceptance, whichever is chosen: the chosen constraints hold under test (a headless coordinator is rejected or accepted as specified; a critical refusal cannot be lifted by any path); every lift is attributable in the log with the lifting identity and the original refuser; the docs state what an agent may do on another agent's behalf.

Related: #68 (key narrowing), and the refusal store's key resolution at index.ts:3203.

Dominant language
TypeScript
Stars
0
Forks
1
Avg merge
2h 10m
Merged PRs (30d)
64

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from STRML/omp-classifier

All issues in STRML/omp-classifier

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.