Expose identity-bound awaited host admission for native Remote input
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- 機能追加
- 明瞭さ
- 説明が足りない
- 活発さ
- 活発
- 技術スタック
- java, typescript
調査の方向性
まず released と public-main のリビジョンを比較し、その後、指定されたセクション付近の docs/hooks/user-prompt-submitted.md と nodejs/src/generated/session-events.ts を読みます。変更を提案する前に、文書化されている hook と認可のエントリポイントを追跡します。サポート対象の契約、順序、失敗時の動作、identity continuity、バージョン固定、ネイティブ Remote テストが文書化され、検証されていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Feature request
Please expose and document a supported host admission contract for native Remote-origin input that combines runtime-attested input identity with an awaited allow/deny/hold decision before the relevant history persistence, model dispatch and effects.
This is a public API-contract request, not a newly reproduced runtime failure or a claim that current hooks provide this guarantee. It is also separate from owner-connection/RPC transport failures.
Public versions and evidence
- Released SDK: v1.0.13, commit
f13e4a2cc7e4e220974d2333142234e162a3252e. - Public main examined:
f45c46fd1812f8bed5b4cbc250f47177c83068f0; comparison from the release. - Submitted-hook documentation at that revision does not provide the required explicit rejection contract.
- Experimental authorization events describe message/effect authority and replay after a turn is read. They are not a documented identity-bound pre-input barrier.
Caller-supplied MessageOptions.source, turn indexes, timestamps, text-derived IDs, mutation-only hooks and unawaited event observers do not establish the requested combination. Throwing from a callback is not a substitute for documented fail-closed semantics.
Minimal contract demonstration
Using the published hook types, dispatch semantics and submitted-hook documentation above, a host cannot express a supported identity-bound rejection that is guaranteed to run before both history/model admission and effects for a native Remote-origin message. Later authorization records necessarily reference an already-read message. No live accounts, private prompts or runtime traces are needed to demonstrate this interface gap.
If a supported API already provides this, please identify its exact version, schema, ordering guarantees and Remote-origin example.
Requested acceptance criteria
- Runtime-attested principal/origin, source session and generation, plus stable original root message/event and causal identities that remain consistent across reconnect. Caller-provided provenance labels must not be treated as authentication.
- An explicitly awaited host decision before the documented persistence/model/effect boundaries, including auxiliary model activity. Please identify whether the guarantee covers remote/cloud persistence, local persistence, or only source-side dispatch. A source callback must not imply that GitHub has not already received the input.
- Explicit denial, malformed responses, timeout, exception, missing owner and disconnect produce typed non-success and prevent the covered downstream actions. No swallowed-exception or unawaited-observer success path.
- Real native Remote positive and negative/spoofed/replayed cases use the same admission path. Reconnect preserves decisions and identities without duplicate model/tool/history effects; distinct equal-text turns remain distinct.
- Publish supported CLI/SDK version pins, ordering tests and an example retaining ordinary allowed custom-tool/permission handling after admission.
Important separation
Awaited custom-tool and permission handlers are useful for controlling effects after input. This request is for the earlier admission boundary; it does not propose weakening existing permission checks. Likewise, fixing a transport problem, selecting a different model or enabling BYOK is not by itself evidence about cloud intake, account visibility or data retention.
- 主要言語
- TypeScript
- スター
- 10.5k
- フォーク
- 1.5k
- 平均マージ
- 1日 11時間
- マージ済み PR(30日)
- 81
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/copilot-sdk のほかの issue
-
Clarify SDK architecture and in-process runtime transport対応中かも @KalebCole が 3 日前に担当しました。 オープンdocumentation
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
github/copilot-sdk#2804 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Python ModelLimits drops max_output_tokens from model metadata対応中かも @HDMowri が 5 日前に担当しました。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
github/copilot-sdk#2798 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
github/copilot-sdk#2793 ·
メンテナーはふだん 1 日以内に返信
-
agentic-workflows
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/copilot-sdk#2782 ·
メンテナーはふだん 1 日以内に返信
-
Rust: subagent lifecycle hooks are logged as unknown対応中かも @hackberry-lab が 7 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
github/copilot-sdk#2781 ·
メンテナーはふだん 1 日以内に返信
github/copilot-sdk の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
openzim/mwoffliner#2933 ·
メンテナーはふだん 1 日以内に返信
-
Use the README category name for website links and submissions対応中かも @dajiaohuang が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
birobirobiro/awesome-shadcn-ui#647 ·
メンテナーはふだん 2 日以内に返信
-
check:passed streams:add
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
Urigo/accounter-fullstack#4604 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信