mirror of
https://github.com/davidkaya/aryx.git
synced 2026-08-08 04:38:45 +02:00
fix: auto-approve URL permission requests
- map GitHub Copilot SDK PermissionRequestUrl to web_fetch so runtime tool auto-approval matches URL fetch permissions - include hook tool names in approval tool-name extraction - include requested URLs in approval detail when manual review is still required - add sidecar tests covering URL and hook permission handling Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -403,16 +403,29 @@ public sealed class CopilotWorkflowRunner : ITurnWorkflowRunner
|
||||
string? normalizedToolName = string.IsNullOrWhiteSpace(toolName)
|
||||
? null
|
||||
: toolName.Trim();
|
||||
string? requestedUrl = request is PermissionRequestUrl urlRequest && !string.IsNullOrWhiteSpace(urlRequest.Url)
|
||||
? urlRequest.Url.Trim()
|
||||
: null;
|
||||
string title = normalizedToolName is null
|
||||
? $"Approve {permissionKind}"
|
||||
: $"Approve {normalizedToolName}";
|
||||
string detail = normalizedToolName is null
|
||||
? sessionId is null
|
||||
? $"{agentName} requested {permissionKind} permission."
|
||||
: $"{agentName} requested {permissionKind} permission for Copilot session {sessionId}."
|
||||
: sessionId is null
|
||||
? $"{agentName} requested {permissionKind} permission for tool \"{normalizedToolName}\"."
|
||||
: $"{agentName} requested {permissionKind} permission for tool \"{normalizedToolName}\" in Copilot session {sessionId}.";
|
||||
? $"{agentName} requested {permissionKind} permission"
|
||||
: $"{agentName} requested {permissionKind} permission for tool \"{normalizedToolName}\"";
|
||||
|
||||
if (requestedUrl is not null)
|
||||
{
|
||||
detail = $"{detail} to access \"{requestedUrl}\"";
|
||||
}
|
||||
|
||||
if (sessionId is not null)
|
||||
{
|
||||
detail = normalizedToolName is null
|
||||
? $"{detail} for Copilot session {sessionId}"
|
||||
: $"{detail} in Copilot session {sessionId}";
|
||||
}
|
||||
|
||||
detail = $"{detail}.";
|
||||
|
||||
return new ApprovalRequestedEventDto
|
||||
{
|
||||
@@ -482,6 +495,8 @@ public sealed class CopilotWorkflowRunner : ITurnWorkflowRunner
|
||||
{
|
||||
PermissionRequestMcp mcp when !string.IsNullOrWhiteSpace(mcp.ToolName) => mcp.ToolName.Trim(),
|
||||
PermissionRequestCustomTool customTool when !string.IsNullOrWhiteSpace(customTool.ToolName) => customTool.ToolName.Trim(),
|
||||
PermissionRequestHook hook when !string.IsNullOrWhiteSpace(hook.ToolName) => hook.ToolName.Trim(),
|
||||
PermissionRequestUrl => "web_fetch",
|
||||
_ => null,
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user