Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

🤖 fix: VS Code webview model list ignores admin policy

Closed Beginner friendly
#4,739 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript, vscode

Research direction

Start in vscode/src/orpcAllowlist.ts and inspect how the webview allowlist handles policy.get and policy.onChanged. Compare these read-only calls with the PolicyProvider usage described in #4711, then request the required security review. Done means the model selector reflects admin model/provider policies without weakening unrelated allowlist restrictions.

Written by the indexing model from the issue text.

Description

Problem

The model list in the VS Code webview ignores admin policy (model/provider allowlists).

  • After #4711 the webview mounts PolicyProvider, but the bridge's oRPC allowlist (vscode/src/orpcAllowlist.ts) rejects policy.get and policy.onChanged. The provider therefore falls back to "no policy", and the model selector offers models the admin has disallowed.
  • The backend still enforces policy: a send with a disallowed model fails with policy_denied, which the composer shows as an error notice. So this is a UI mismatch, not a bypass.

Proposed fix

Add the read-only policy.get and policy.onChanged to the webview allowlist so the selector matches what the backend enforces. Expanding the allowlist changes what the webview can call, so this needs a security review.

Refs #4711


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $14.11

Dominant language
TypeScript
Stars
2k
Forks
139
Avg merge
6h 35m
Merged PRs (30d)
819

Getting set up

  • Ships a Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from coder/xum

All issues in coder/xum

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.