Decide whether a coordinator may lift a headless worker's refusal (the trust boundary #68 defers)
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Necesita aclaración
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- authorization, security
Línea de trabajo
Start with the refusal key resolution at index.ts:3203, liftRefusals at index.ts:3262, and the dialog-approval and headless checks at index.ts:4302 and index.ts:4333. Decide and document the trust-boundary policy, then add tests covering coordinator authorization, critical refusals, and attribution of both identities in decisions.jsonl. Done means the chosen constraints hold and the agent-on-behalf-of-user behavior is documented.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Split from #68 by your decision there: the mechanical half (narrowing the refusal key) is agent work on that issue, and this is the trust boundary it deliberately does not touch.
The gap. A headless worker cannot lift a refusal. liftRefusals (index.ts:3262) runs at exactly one call site, inside the dialog-approval handler (index.ts:4333), and that handler is only reachable when ctx.hasUI — index.ts:4302 collapses every headless hit into a block before any lift path. A refusal a coordinator considers wrong therefore stays for the whole session.
Why it is a design call and not a fix. Building the channel means answering who may lift a refusal taken on another agent's command, whether an agent may approve on a user's behalf, and whether a critical refusal is ever liftable. Those are the same questions the persistent-grant surface answers for a human, asked about a machine, and the answer decides how much of the prod-secrets posture moves.
Options as presented.
- A registered tool a coordinator may call, with headless coordinators rejected by construction, critical refusals permanently unliftable, and the hop recorded in
decisions.jsonlwith both identities. Cost: an agent-to-agent approval path exists at all. - Lift only with a human-issued token in the environment, so an unattended session still cannot lift. Cost: it is a human approval with extra steps in the common case.
- Leave it unliftable, documented with the reason. Cost: a wedged headless worker is restart-only.
Acceptance, whichever is chosen: the chosen constraints hold under test (a headless coordinator is rejected or accepted as specified; a critical refusal cannot be lifted by any path); every lift is attributable in the log with the lifting identity and the original refuser; the docs state what an agent may do on another agent's behalf.
Related: #68 (key narrowing), and the refusal store's key resolution at index.ts:3203.
- Lenguaje dominante
- TypeScript
- Estrellas
- 0
- Forks
- 1
- Merge medio
- 2 h 10 min
- PR fusionados (30 d)
- 64
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de STRML/omp-classifier
-
enhancement ready-for-human
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
STRML/omp-classifier#116 · 7 comentarios ·
Los mantenedores suelen responder en 1 día
-
enhancement ready-for-human
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
STRML/omp-classifier#13 · 6 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de STRML/omp-classifier
Issues similares
-
refactor
Dificultad 2/5 Medio día Aptitud para principiantes 84/100
Los mantenedores suelen responder en 5 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
OHDSI/Data2Evidence#3450 ·
Los mantenedores suelen responder en 2 días
-
e2e-failure ready-to-code
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
redhat-developer/rhdh-plugin-export-overlays#4011 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
automation missing-model model-sync provider:ofox
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
anomalyco/models.dev#8421 ·
Los mantenedores suelen responder en 1 día
-
SlackAdapter and TelegramAdapter are not assignable to Adapter under exactOptionalPropertyTypesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día