Feature request: add fine grained permission control
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- authorization, security
Línea de trabajo
Comienza en Settings → Local execution usando el punto de entrada grokbot://app/v1/settings?id=local-execution; el issue no nombra archivos de implementación ni tests. Se considera terminado cuando el interruptor de ámbito global de la máquina se sustituya por permisos por bot y por máquina, los bots nuevos tengan la denegación como comportamiento predeterminado, se muestren vistas previas de los comandos y existan concesiones persistentes con alcance limitado.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
Grok Bot’s local-computer prompt is all-or-nothing across every bot on a machine.
When one bot needs to run a command on my Mac (mac.lan), the card asks (see screenshot):
Allow Grok Bot and all Bots to run commands on your local computer?
Options are Always allow, Allow once, and Never. Copy says this applies to Grok Bot and every Bot, and can be changed in Settings.
That is not the right grain. I cannot grant local execution to one bot and keep it off the others.
Why this matters
I use several Grok Bots with different duties:
- A chief-of-staff bot (mine) that I do want to run commands on my Mac (git,
gh, local clones). - Specialist bots I also created (slack, gitHub, product1, product2, etc.) that should not inherit that grant.
Today, “Always allow” on mac.lan is every bot I own. That breaks separation of duties. “Allow once” is too noisy for a bot I actually trust with the Mac. “Never” blocks the one bot that should have it.
I expect Grok Bots to talk to each other soon, ie my team’s bots should ask my chief-of-staff bot for permission before they act, and I decide through that bot or that bot can decide on my behalf (separate issue). That only works if permissions are per-bot. A machine-wide grant means any bot I (or later, a teammate) created can use the same local access.
Request
-
Per-bot local execution (needed first). Let me allow/deny “run commands on this computer” per bot, per machine. Default deny for new bots. Granting xxx (or any one bot) must not grant slack, eng-abc, or any other bot I created.
-
Visible command, scoped grant. Keep command preview on by default. Prefer grants like “this bot, this machine, this path” over a silent global allow.
-
Bot-to-bot permission requests (next). When bots can message each other across users, let a designated bot be the policy checkpoint: other bots request, that bot (or I through it) allow/deny. Do not treat a teammate bot’s ask as an approved local-computer grant.
Settings → Local execution should show a per-bot matrix, not one switch for all bots.
Out of scope for v1
I am not asking to remove Auto-review or the allow-once prompt. I am asking that a lasting allow be bound to a specific bot (and machine), not the whole fleet.
Workaround today
I can tell the chief-of-staff bot not to hand Mac/git/gh work to other bots, and I can refuse teammate-bot asks until I approve them. That is policy in chat, not enforcement. The product still lets every bot use the Mac if I click Always allow.
- Lenguaje dominante
- TypeScript
- Estrellas
- 8.8k
- Forks
- 819
- Merge medio
- 14 h 37 min
- PR fusionados (30 d)
- 66
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cursor/plugins
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 Medio día Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
Todos los issues de cursor/plugins
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Doist/todoist-cli#576 ·
Los mantenedores suelen responder en 1 día
-
🐛 Bug supabase/cli
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
CopilotKit/aimock#491 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
agilepathway/label-checker#710 · 2 comentarios ·
Los mantenedores suelen responder en 1 día