🤖 fix: VS Code webview model list ignores admin policy
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript, vscode
Research direction
Start in vscode/src/orpcAllowlist.ts and inspect how the webview allowlist handles policy.get and policy.onChanged. Compare these read-only calls with the PolicyProvider usage described in #4711, then request the required security review. Done means the model selector reflects admin model/provider policies without weakening unrelated allowlist restrictions.
Written by the indexing model from the issue text.
Description
Problem
The model list in the VS Code webview ignores admin policy (model/provider allowlists).
- After #4711 the webview mounts
PolicyProvider, but the bridge's oRPC allowlist (vscode/src/orpcAllowlist.ts) rejectspolicy.getandpolicy.onChanged. The provider therefore falls back to "no policy", and the model selector offers models the admin has disallowed. - The backend still enforces policy: a send with a disallowed model fails with
policy_denied, which the composer shows as an error notice. So this is a UI mismatch, not a bypass.
Proposed fix
Add the read-only policy.get and policy.onChanged to the webview allowlist so the selector matches what the backend enforces. Expanding the allowlist changes what the webview can call, so this needs a security review.
Refs #4711
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $14.11
- Dominant language
- TypeScript
- Stars
- 2k
- Forks
- 139
- Avg merge
- 6h 35m
- Merged PRs (30d)
- 819
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from coder/xum
-
approved
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
🤖 Delegated-turn delivery and peer-limit follow-ups from #5311 and #5327Possibly taken @ThomasK33 claimed this today. Open
Maintainers usually reply within 1 day
-
🤖 Compaction follow-up dispatch: remaining follow-ups from #5313Possibly taken @ThomasK33 claimed this today. Open
Maintainers usually reply within 1 day
-
🤖 Concurrency primitive and fileLock hazards found by the formal models (#5309, #5319 follow-ups)Possibly taken @ThomasK33 claimed this today. Open
Maintainers usually reply within 1 day
-
🤖 History persistence follow-ups from the formal-verification fixes (#5312, #5316, #5318)Possibly taken @ThomasK33 claimed this today. Open
Maintainers usually reply within 1 day
Similar issues
-
area/frontend good first issue kind/cooldown
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
voidzero-dev/oxc-angular-compiler#511 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
langchain-ai/deepagentsjs#898 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
anomalyco/models.dev#8509 · 2 comments ·
Maintainers usually reply within 1 day
-
bug documentation P2 UI/UX
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day