Add worktree-local Intent policy overlays
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 42/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- typescript
- 领域
- authorization, cli, security
调研方向
首先追踪现有的 package.json policy 路径,以及 issue 中列出的 effective-policy 消费者:list、load、stale、支持诊断、install --map 和 hooks。实现并验证受保护的 .intent/config.local.json resolver,使 Git 跟踪和精确忽略检查、验证、选择器编译、排除项、迁移行为以及共享 policy 优先级符合验收标准。
由索引模型根据 Issue 内容生成。
描述
Problem
Intent policy is currently shared through package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide .intent/hooks.
User outcome
A user can manually create a valid .intent/config.local.json beside the nearest owning package.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.
Example:
{
"skills": [
"@acme/private-skill"
],
"exclude": [
"@acme/unsafe-skill"
]
}
In scope
- Add
.intent/config.local.jsondiscovery beside the nearest owningpackage.jsonas the sole local policy source. Keeppackage.jsonas the sole shared committed source. - Provide reusable guarded local resolver and storage behavior that future installer or review work may consume.
- Require local policy operations to run in a Git worktree. Use only the exact sidecar path in
$GIT_COMMON_DIR/info/exclude; do not ignore.intent/, and preserve.intent/hooks. - Check that the exact local path is untracked on every local read and write. Reject tracked paths even when
info/excludecontains the path. - Support a top-level JSON object with optional
skillsandexcludefields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars. - Activate a manually created valid local file automatically. Fail closed when a present local file is tracked, unreadable, malformed, or not exactly ignored.
- Compile shared and local skill selectors independently. For declared shared policy, grant a candidate when either predicate matches. Preserve existing package, exact-skill, wildcard, npm, and workspace semantics.
- Preserve migration behavior when shared
intent.skillsis absent and localskillsis omitted or[]. A non-empty localskills, including["*"], ends that migration mode. - Apply shared and local exclusions as final additive denials. Local policy must never restore a skill denied by shared policy.
- Make all policy consumers use the same effective-policy resolver: list, load, stale, support diagnostics, install
--map, and hooks.
Acceptance criteria
- A valid manual
.intent/config.local.jsonbeside the nearest owningpackage.jsonis discovered and applied automatically in a Git worktree. - The local file is accepted only when the exact path is untracked and exactly ignored through
$GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes. .intent/hooksremains usable, and the implementation never ignores.intent/as a whole directory.- A tracked, unreadable, malformed, or not-exactly-ignored present local file fails closed with actionable diagnostics.
- The local object rejects unknown top-level fields, accepts only optional
skillsandexclude, requires at least one of them, and validates each present array under existing selector or exclusion rules. - Shared and local selector sets are compiled independently. For declared shared policy, a candidate is granted when either set matches without changing package, exact-skill, wildcard, npm, or workspace semantics.
- Shared and local exclusions both deny matching candidates after grant selection. A shared exclusion cannot be bypassed locally.
- When shared
intent.skillsis absent, omitted or empty localskillspreserves current migration behavior. A non-empty localskills, including["*"], ends it. list,load,stale, support diagnostics, install--map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics.- The work introduces no
.intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.
Related work
Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.
#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.
- 主要语言
- TypeScript
- 星标
- 331
- 派生
- 22
- 平均合并
- 12 小时 17 分钟
- 30 天内合并 PR
- 51
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
TanStack/intent 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 5/5 一周以上 新手友好度 45/100
-
难度 4/5 3-5 天 新手友好度 48/100
-
难度 5/5 一周以上 新手友好度 35/100
-
难度 5/5 一周以上 新手友好度 45/100
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
receptron/mulmoterminal#2264 ·
-
documentation
难度 2/5 1-3 小时 新手友好度 78/100
components-web-app/docs#96 ·
-
enhancement
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 68/100
simonsobs/tileviewer#114 ·
-
难度 2/5 1-3 小时 新手友好度 75/100