Expose identity-bound awaited host admission for native Remote input
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Attiva
- Stack tecnologico
- java, typescript
- Ambito
- api, authentication, backend-api-design, security
Direzione di ricerca
Inizia confrontando le revisioni released e public-main, quindi leggi docs/hooks/user-prompt-submitted.md e nodejs/src/generated/session-events.ts nelle sezioni indicate. Traccia i punti di ingresso documentati degli hook e dell’autorizzazione prima di proporre modifiche. Il lavoro è completo quando il contratto supportato, l’ordinamento, il comportamento in caso di errore, la continuità dell’identità, i pin delle versioni e i test Remote nativi sono documentati e verificati.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Feature request
Please expose and document a supported host admission contract for native Remote-origin input that combines runtime-attested input identity with an awaited allow/deny/hold decision before the relevant history persistence, model dispatch and effects.
This is a public API-contract request, not a newly reproduced runtime failure or a claim that current hooks provide this guarantee. It is also separate from owner-connection/RPC transport failures.
Public versions and evidence
- Released SDK: v1.0.13, commit
f13e4a2cc7e4e220974d2333142234e162a3252e. - Public main examined:
f45c46fd1812f8bed5b4cbc250f47177c83068f0; comparison from the release. - Submitted-hook documentation at that revision does not provide the required explicit rejection contract.
- Experimental authorization events describe message/effect authority and replay after a turn is read. They are not a documented identity-bound pre-input barrier.
Caller-supplied MessageOptions.source, turn indexes, timestamps, text-derived IDs, mutation-only hooks and unawaited event observers do not establish the requested combination. Throwing from a callback is not a substitute for documented fail-closed semantics.
Minimal contract demonstration
Using the published hook types, dispatch semantics and submitted-hook documentation above, a host cannot express a supported identity-bound rejection that is guaranteed to run before both history/model admission and effects for a native Remote-origin message. Later authorization records necessarily reference an already-read message. No live accounts, private prompts or runtime traces are needed to demonstrate this interface gap.
If a supported API already provides this, please identify its exact version, schema, ordering guarantees and Remote-origin example.
Requested acceptance criteria
- Runtime-attested principal/origin, source session and generation, plus stable original root message/event and causal identities that remain consistent across reconnect. Caller-provided provenance labels must not be treated as authentication.
- An explicitly awaited host decision before the documented persistence/model/effect boundaries, including auxiliary model activity. Please identify whether the guarantee covers remote/cloud persistence, local persistence, or only source-side dispatch. A source callback must not imply that GitHub has not already received the input.
- Explicit denial, malformed responses, timeout, exception, missing owner and disconnect produce typed non-success and prevent the covered downstream actions. No swallowed-exception or unawaited-observer success path.
- Real native Remote positive and negative/spoofed/replayed cases use the same admission path. Reconnect preserves decisions and identities without duplicate model/tool/history effects; distinct equal-text turns remain distinct.
- Publish supported CLI/SDK version pins, ordering tests and an example retaining ordinary allowed custom-tool/permission handling after admission.
Important separation
Awaited custom-tool and permission handlers are useful for controlling effects after input. This request is for the earlier admission boundary; it does not propose weakening existing permission checks. Likewise, fixing a transport problem, selecting a different model or enabling BYOK is not by itself evidence about cloud intake, account visibility or data retention.
- Lingua principale
- TypeScript
- Stelle
- 10.5k
- Fork
- 1.5k
- Merge medio
- 1g 6h
- PR unite (30g)
- 106
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/copilot-sdk
-
documentation
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
github/copilot-sdk#2804 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
github/copilot-sdk#2798 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
github/copilot-sdk#2793 ·
I maintainer di solito rispondono entro 1 giorno
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/copilot-sdk#2782 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
github/copilot-sdk#2781 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di github/copilot-sdk
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
betagouv/mon-entreprise#4699 ·
I maintainer di solito rispondono entro 3 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
jaegertracing/jaeger-ui#4547 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
ai-driven-qa
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
linagora/twake-calendar-frontend#1467 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
need4deed-org/sdk#267 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
auth0/universal-login#414 ·
I maintainer di solito rispondono entro 1 giorno