mirror of
https://github.com/openswarm-ai/openswarm.git
synced 2026-09-22 01:24:52 +02:00
* [eric] ci: gitleaks-ignore the known historical secrets so our branch stops failing on leaks it didnt add * [eric] workflows: restore scheduled-tasks on the workflow line (revert removal, keep windows fixes + 1.1.69) * [eric] workflows: re-apply uncommitted scheduling wip (schedule pill, calendar view, slice) * [eric] ops: gitignore dev-team local state files * [eric] ops: backlog item for download-tracking visibility * [eric] ci: allowlist the cdp-routes redaction-test token in gitleaks * [aidan] feat/scheduled-tasks: keep step labels in sync on edit and show chevron on every step * [aidan] fix: schedule time in chat * [aidan] ux/workflows: add workflow step removal (#91) * [aidan] feat/scheduled-tasks: remember workflow tool permissions across runs * [aidan] feat/task-scheduling: add hourly and minute (15-min minimum) schedule intervals (#93) * [aidan] feat/scheduled-tasks: calendar, rename, and edit workflows (#94) * [aidan] bug: fix schedule button * [aidan] fix/agent-errors: surface provider rate limits * [aidan] ux/cards: click-to-rename for chat and workflow titles Single-click a card's title to enter edit mode inline. Commit on Enter/blur, cancel on Escape. Rename persists via PATCH for workflows and sessions. * [aidan] feat/workflows: seed build prompt for zero-step workflows When a new workflow has no steps, seed the agent with a prompt asking the user to describe what the workflow should do, rather than starting blank. * [aidan] feat/workflows: add-to-schedule popover for unscheduled workflows Clicking the "+" on an unscheduled workflow row opens a popover with two options: - Keep this schedule: enables the workflow's existing cadence and moves it to Scheduled - Change schedule: opens the scheduling editor to pick a different time * [aidan] ux/workflows: wire add-to-schedule popover and simplify New button - Made the "+" icon on unscheduled workflow rows clickable, opening a popover to keep or change the schedule - Removed AddIcon from toolbar "New" button (now reads "New" instead of "+ New") * [aidan] fix/scheduled-tasks: open schedule calendar when Schedule pill clicked Fixed the Schedule pill click being swallowed by the toolbar's dismiss handler. Exempted the toolbar pills via data-toolbar-pills so their click handlers fire. * [aidan] ux/workflows: open New workflow in agent build chat instead of empty card When creating a new workflow from the hub, open it in edit_agent view (with the agent builder chat) instead of a preview card. The workflow is created on the backend first so the embedded session has a real ID. * [aidan] feat/workflow-edit: add draft testing save flow * [aidan] ux/chat: remove continue chat button * [aidan] ux/workflows: polish workflow card interactions * [aidan] fix/workflow-scheduling: save unscheduled workflows as drafts * aidan ui: schedule naming changes * [aidan] ui: tool calling desc/naming * [aidan] ui: calendar sidebar naming * [aidan] ui: fix stop viewing closing chat * [aidan] feat/workflows: auto-name workflows and polish the build flow (#95) * [aidan] feat/workflow-auto-naming: auto-generate workflow titles from steps Generate a title + description from a workflow's steps (one aux call, reused for step labels) whenever it is still auto_named, so a workflow built in the Edit Agent names itself on commit instead of staying "New workflow". A manual rename sets auto_named=False and is never overwritten. Stream the aux call (non-streaming drops content on some 9router lanes) and fall back to a step-derived title when the model is unavailable. * [aidan] feat/workflows: hide unsaved new workflows until first save A brand-new "+ New" workflow is created with unsaved=true and kept out of the hub's scheduled/unscheduled lists while the user is still building it in the Edit Agent. The first commit (Save) clears the flag and the workflow appears. Every other create path stays visible immediately. * [aidan] ux/workflows: remove redundant save workflow button The Edit Agent already has Discard/Save controls in its strip, so the header "Save Workflow" button was a duplicate save path. Remove it and its pulse/edit-session-id wiring; the model/time subtitle stays. * [aidan] ux/workflows: animate title on auto-rename Wrap the workflow card title in the same Typewriter the chat card uses, so when the auto-generated name replaces the placeholder after Save it retypes letter-by-letter. Gated on a real (non-placeholder) title so it never animates on mount or for already-named workflows. * [aidan] ux/workflows: animate sidebar title on auto-rename Wrap the calendar hub's sidebar row title in the same Typewriter the workflow card uses, so a title that auto-renames retypes letter-by-letter in the sidebar too. Extract the placeholder/isRealTitle guard into the shared workflowVisuals so the card and sidebar stay in sync. * [aidan] fix/workflows: connect watch tether, keep watched chat open, wire draft run/history * [aidan] ui: grey out chat pill when not selected * [aidan] ui: fix running agent display * [aidan] feat/history-popover: add chat history and scheduled tasks run log tabs (#96) * [aidan] ux/schedule: toast when calendar view already open on expand * [aidan] ui: fix popover descs * [aidan] feat/workflow-runs: add pause, resume, and stop controls for live runs * [aidan] feat/schedule-calendar: add calendar occurrences endpoint and concrete timezones * [aidan] feat/workflows: require at least one step to save a workflow * [aidan] ux/edit-agent: hide Discard for an unsaved new workflow * [aidan] ux/edit-agent: move fix-prefix card below the step list * [aidan] feat/workflows: toast when an unattended scheduled run starts * [aidan] fix/dashboard-tethers: anchor workflow-sidecar tethers to measured card rects * [aidan] feat/workflows: validate steps before scheduling and keep chat tool memory * [aidan] feat/mcp-suggestions: dismissable integration banner with per-session cooldown * [aidan] feat/workflows: add scheduled-run "running now" toast with click-to-view (#97) * [aidan] ux/workflows: surface paused state on card, sidebar, and calendar; tidy run history * [aidan] feat/mcp-suggestions: suggest both Google and Microsoft when provider is ambiguous * [aidan] fix/agent-tokens: friendly out-of-tokens card across all agent surfaces * [aidan] feat/workflow-model: persist edit-agent model on save with switch notice and fresh drafts * [aidan] fix/workflow-chat: force stop on watched run mirrors workflow card stop * [aidan] fix/workflow-cards: keep watched run tethered on finish to avoid duplicate chat * [aidan] feat/schedule-calendar: mark current time with a now line in week view * [aidan] refactor/private-names: rename error and schedule classifiers from _ to p_ * [aidan] feat/scheduled-tasks: agent workflow scheduling and in-chat convert (#98) * [aidan] feat/workflow-suggest: nudge user to convert repeatable chat to workflow Add SuggestConvertToWorkflow MCP tool that agents call at the end of a task when they've completed something worth repeating (daily report, weekly check, recurring data pull). Frontend detects the tool call and glows the "Convert to workflow" button 3 times to draw the eye. When user clicks it, the suggested cadence (e.g. "every weekday at 9am") is stored in the draft and seeded into the scheduling agent's first prompt, so the agent can act on the suggestion rather than asking the user again. Tool is never auto-called — agents decide when a task is genuinely repeatable (not debugging, creative work, one-off lookup). Tool description emphasizes sparse, high-confidence use only (once per session max). Files changed: - backend/apps/agents/schedule_mcp_server.py: add SuggestConvertToWorkflow tool - frontend/src/shared/mcpToolMeta.ts: add label for new tool - frontend/src/app/pages/Dashboard/cards/AgentCard.tsx: detect suggestion in session messages, show+glow "Convert to workflow" button, pass cadence to draft - frontend/src/shared/state/workflowsSlice.ts: add suggested_cadence field to Workflow interface - frontend/src/app/pages/Workflows/SchedulingView.tsx: seed scheduling agent prompt with suggested cadence hint * [aidan] feat/agent-scheduling: route recurring asks through native workflows, deny claude cron skill * [aidan] feat/workflow-convert: in-chat convert popup and auto-open scheduled workflow card * [aidan] ux/calendar-page: schedule calendar restyle + popover fixes (#99) * [aidan] fix/dashboard-delete: remove workflows calendar panel on delete key * [aidan] ux/workflows-calendar: restyle hub, fix today highlight, add toolbar toggle * [aidan] ux/schedule-popover: compact density, fix sticky header bleed, add header spacing * [aidan] ux/schedule-calendar: hollow ring dot for past fires in month view * [aidan] ux/schedule-calendar: clickable +N more opens day's full run list * [aidan] feat/run-log-filters: add success and skipped pills to scheduled task history * [aidan] fix/convert-button: stop drag capture so convert-to-workflow click fires * [aidan] ux/calendar-card: match border color and radius to chat and workflow cards * [aidan] fix/minimap: render missed-runs card on the minimap * [aidan] ux/run-sparkline: simplify tooltip to plain run tally * [aidan] ux/run-history: collapse expanded run view to one clickable line * [aidan] ux/calendar-card: match corner radius to browser cards * [aidan] feat/workflows: launch-time scheduling UX and workflow-card polish (#101) * [aidan] feat/schedule-list: lazy-load list view via scroll sentinel * [aidan] feat/missed-runs: launch toast with per-workflow counts and pan-to-card * [aidan] fix/dashboard-tethers: keep watching line anchored on canvas zoom * [aidan] feat/scheduled-tasks: review missed runs at launch instead of auto-firing on_missed * [aidan] refactor/workflow-cards: use radius and status design tokens, polish card chrome * [aidan] ux/agent-card: keep convert-to-workflow visible during runs with mid-turn toast * [aidan] ux/mcp-bubble: drop redundant verb label when a workflow label is shown * [aidan] chore/backend: remove stale explanatory comments * [aidan] fix/workflows-hub: load workflows on hub mount so calendar fills at launch * [aidan] feat/workflows: generate title, description, step labels at convert time * [aidan] fix/tidy-layout: include workflows hub in tidy and fit-to-view * [aidan] feat/schedule-list: window long list via measured-height virtualizer * [aidan] ux/workflows-hub: remove time-saved badge from calendar header * [aidan] fix/types: add missing semantic-type labels and drop stray fade arg * [aidan] feat/schedule: pin monthly day-of-month and honor repeat-every intervals * [aidan] feat/schedule: inherit source-session tool surface for scheduled runs * [aidan] ux/calendar: restack hour-cell events as bars with overflow affordance * [aidan] feat/calendar: open the run card when clicking a scheduled occurrence * [aidan] ux/missed-runs: add per-group select-all toggle and rename skip action * [aidan] feat: new scheduled task design ported * [aidan] ui: sidebar reorder, repeat controls on schedule card * [aidan] ui: sidebar, scheduling time * [aidan] feat/schedule: pin monthly last-day-of-month * [aidan] feat/steps: per-step enable toggle * [aidan] feat/workflows: per-workflow color swatch * [aidan] feat/trash: soft-delete workflows with restore and purge * [aidan] feat/run-monitor: live run monitor card on the canvas * [aidan] feat/run-context: attach a run as removable chat context * [aidan] feat/compose: new-workflow landing page and auto-commit build flow * [aidan] ui/workflows: dark mode and design-system cohesion * [aidan] ui/calendar: overflow popover, condensed week view, scroll fix * [aidan] feat/home: ongoing runs, missed review, and accurate Coming-up counts * [aidan] fix/run-status: sync ongoing runs and heal stuck/interrupted runs * [aidan] ux/schedule: last-day-of-month UI, Run-at time typing, interval input * [aidan] ux/workflows: default window size and toolbar icon * [aidan] fix/schedule: measure ran_late from start and anchor recurrences to created_at * [aidan] feat/calendar: render fire times from backend, drop JS recurrence reimpl * [aidan] chore/dashboard: drop dead configure/missed-run cards, refetch on reconnect * [aidan] chore/agent-card: remove unreachable convert-to-workflow action * [aidan] fix/workflows: don't bump updated_at on a no-op draft commit so viewing a workflow doesn't reorder the sidebar * [aidan] feat/schedule: warn when scheduling a workflow that has no steps * [aidan] fix/selection-tool: never select the workflows app, and exit the tool on Escape without dropping selections * [aidan] ux/compose: diversify new-workflow starter prompts across personas * [aidan] ux/run-monitor: spawn the run card a bit farther right of the workflows app * [aidan] fix/schedule: harden run recovery and storage writes against crashes * [aidan] ux/compose: restyle new-workflow starters as a clean pill cluster with rich prompts * [aidan] fix/workflows: optimistically apply edits so the schedule banner updates instantly * [aidan] ui/workflows: three-tone surface depth so the window lifts off the canvas in both themes * [aidan] ui/workflows: close buttons turn red on hover, matching the chat card * [aidan] test/schedule: cover executor pipeline, storage durability, and recurrence gaps * [aidan] fix: remove package-lock json * [aidan] fix/workflows-compose: keep compose view until edit agent replies * [aidan] feat/workflows: auto-generate workflow + step titles with typewriter animation * [eric] deps: restore frontend/package-lock.json (PR #105 deletion broke npm ci) --------- Co-authored-by: Eric <ciregenz@berkeley.edu> Co-authored-by: cire <134991075+ciregenz@users.noreply.github.com>
213 lines
11 KiB
Python
213 lines
11 KiB
Python
"""Defense-in-depth permission gate, lifted verbatim out of the agent loop so it's
|
|
independently testable. Flips a permissive tool policy to 'ask' when a write would land
|
|
on a sensitive path (SSH keys, shell rc files, keychains, system dirs), when a Bash
|
|
command writes to a catastrophic path, or when Bash looks like OS-level scheduling
|
|
(crontab/launchctl/schtasks). The trusted-paths allowlist is reloaded on every call so a
|
|
trust decision taken during one approval applies to any later prompt in the same turn."""
|
|
|
|
import fnmatch
|
|
import os
|
|
import re
|
|
from typing import Dict, Optional, Tuple
|
|
|
|
from typeguard import typechecked
|
|
|
|
from backend.apps.tools_lib.tools_lib import load_trusted_sensitive_paths
|
|
|
|
# Each entry: pattern -> (short label, plain-English risk). The label/risk is what the
|
|
# approval card shows, so it has to read clearly to a non-developer who has never heard
|
|
# of `~/.ssh/authorized_keys`.
|
|
P_SENSITIVE_PATH_INFO: Dict[str, Tuple[str, str]] = {
|
|
"*/.ssh": ("SSH folder (~/.ssh)", "Controls who can log in to your computer remotely."),
|
|
"*/.ssh/*": ("SSH folder (~/.ssh)", "Controls who can log in to your computer remotely."),
|
|
"*/.aws/*": ("AWS credentials (~/.aws)", "Cloud account access keys; can spend money and read your data."),
|
|
"*/.config/gcloud/*": ("Google Cloud credentials", "Cloud account access; can spend money and read your data."),
|
|
"*/.kube/*": ("Kubernetes config (~/.kube)", "Admin access to your Kubernetes clusters."),
|
|
"*/.gnupg/*": ("GPG encryption keys", "Your private encryption keys; lets attackers decrypt your data or sign as you."),
|
|
"*/.docker/config*": ("Docker credentials", "Login tokens for container registries."),
|
|
"*/.zshrc": ("Shell startup file (.zshrc)", "Runs automatically every time you open a terminal."),
|
|
"*/.bashrc": ("Shell startup file (.bashrc)", "Runs automatically every time you open a terminal."),
|
|
"*/.bash_profile": ("Shell startup file (.bash_profile)", "Runs automatically every time you log in."),
|
|
"*/.profile": ("Shell startup file (.profile)", "Runs automatically every time you log in."),
|
|
"*/.zprofile": ("Shell startup file (.zprofile)", "Runs automatically every time you log in."),
|
|
"*/.zshenv": ("Shell environment file (.zshenv)", "Runs automatically for every shell, including non-interactive ones."),
|
|
"*/.gitconfig": ("Global Git config", "Affects every Git command you run; can hijack commits."),
|
|
"*/.npmrc": ("npm auth file (~/.npmrc)", "Lets you publish npm packages; a token here can publish malicious packages as you."),
|
|
"*/.pypirc": ("PyPI auth file (~/.pypirc)", "Lets you publish Python packages; a token here can publish malicious packages as you."),
|
|
"*/.netrc": ("Stored login info (~/.netrc)", "Saved passwords for various services."),
|
|
"*/Library/Keychains/*": ("macOS Keychain", "Where macOS stores all your saved passwords."),
|
|
"/etc/*": ("System config (/etc)", "Affects the whole computer, not just your account."),
|
|
"/private/etc/*": ("System config (/etc)", "Affects the whole computer, not just your account."),
|
|
"/System/*": ("macOS system folder", "Affects the whole computer; should almost never be modified."),
|
|
"/usr/local/etc/*": ("System config (/usr/local/etc)", "Affects the whole computer, not just your account."),
|
|
}
|
|
P_SENSITIVE_PATH_PATTERNS: Tuple[str, ...] = tuple(P_SENSITIVE_PATH_INFO.keys())
|
|
|
|
P_PATH_GATED_TOOLS: Tuple[str, ...] = ("Write", "Edit", "NotebookEdit")
|
|
|
|
# OS-level scheduling across macOS/Linux/Windows. The agent must not install cron entries,
|
|
# launchd plists, Windows scheduled tasks, or PowerShell ScheduledTask cmdlets behind the
|
|
# user's back. Word-bounded so stray strings in echo etc. don't trip it.
|
|
P_OS_SCHED_RE = re.compile(
|
|
r"\b("
|
|
r"crontab|launchctl|launchd|schtasks|systemd-run|"
|
|
r"systemctl\s+--user.*timer|at\s+\d|at\s+now|at\s+-f|"
|
|
r"Register-ScheduledTask|New-ScheduledTask|Set-ScheduledTask|"
|
|
r"Register-ScheduledJob|New-ScheduledJob"
|
|
r")\b",
|
|
re.IGNORECASE,
|
|
)
|
|
|
|
# Catastrophic-path Bash gate. Bash is intentionally NOT in P_PATH_GATED_TOOLS (gating
|
|
# every `echo ... > /tmp/foo` would interrupt routine work), but a single redirected write
|
|
# to one of these can grant persistent attacker access or break the OS unrecoverably. The
|
|
# trust list is shared with Write/Edit so one "Always allow" covers both surfaces.
|
|
P_BASH_CATASTROPHIC_INFO: Dict[str, Tuple[str, str]] = {
|
|
"*/.ssh/*": ("SSH folder (~/.ssh)", "Controls who can log in to your computer remotely."),
|
|
"/etc/sudoers": ("Sudo permissions (/etc/sudoers)", "Controls which commands can run with admin privileges."),
|
|
"/etc/sudoers.d/*": ("Sudo permissions (/etc/sudoers.d)", "Controls which commands can run with admin privileges."),
|
|
"/etc/passwd": ("System user list (/etc/passwd)", "Defines every user account on this computer."),
|
|
"/etc/shadow": ("System password file (/etc/shadow)", "Stores password hashes for every user account."),
|
|
"*/Library/Keychains/*": ("macOS Keychain", "Where macOS stores all your saved passwords."),
|
|
"/System/*": ("macOS system folder", "Affects the whole computer; should almost never be modified."),
|
|
}
|
|
P_BASH_CATASTROPHIC_PATTERNS: Tuple[str, ...] = tuple(P_BASH_CATASTROPHIC_INFO.keys())
|
|
|
|
# Pulls quoted strings AND bare path-like tokens out of a Bash command. Intentionally loose:
|
|
# a false positive just means an extra approval prompt, never a missed gate.
|
|
P_BASH_PATH_TOKEN_RE = re.compile(
|
|
r"""(?P<quoted>"[^"]+"|'[^']+')|(?P<bare>[~/.][\w./~\-]*)"""
|
|
)
|
|
|
|
# Write operators we care about; presence alone isn't enough, a sensitive target in the
|
|
# same command is also required. Covers shell redirection and tools with a destination flag.
|
|
P_BASH_WRITE_OP_RE = re.compile(
|
|
r"(?:>>?|\btee\b|\bsed\s+-i\b|\bcp\b|\bmv\b|\bdd\b[^|]*\bof=|\binstall\b|\bchmod\b|\bchown\b|\brm\b|\btouch\b|\bmkdir\b|\bln\b)",
|
|
re.IGNORECASE,
|
|
)
|
|
|
|
|
|
@typechecked
|
|
def match_sensitive_pattern(file_path: str) -> Optional[str]:
|
|
"""The matched sensitive pattern, or None if the path isn't sensitive OR the user has
|
|
trusted that pattern. The trusted list reloads per call so a same-turn trust decision
|
|
takes effect immediately (no in-process cache to invalidate)."""
|
|
if not file_path or not isinstance(file_path, str):
|
|
return None
|
|
try:
|
|
norm = os.path.normpath(os.path.expanduser(file_path))
|
|
except Exception:
|
|
return None
|
|
# Forward-slash the path so patterns match on Windows too; os.path.normpath emits
|
|
# backslashes there and fnmatch treats '/' as literal. Without this the gate would
|
|
# silently no-op on Windows and a prompt-injected Write to ~/.ssh/... would pass.
|
|
if os.sep != '/':
|
|
norm = norm.replace(os.sep, '/')
|
|
trusted = set(load_trusted_sensitive_paths())
|
|
for pat in P_SENSITIVE_PATH_PATTERNS:
|
|
if pat in trusted:
|
|
continue
|
|
if fnmatch.fnmatch(norm, pat):
|
|
return pat
|
|
return None
|
|
|
|
|
|
@typechecked
|
|
def looks_like_os_scheduling(tool_input: object) -> bool:
|
|
if not isinstance(tool_input, dict):
|
|
return False
|
|
cmd = str(tool_input.get("command") or "")
|
|
if not cmd:
|
|
return False
|
|
return bool(P_OS_SCHED_RE.search(cmd))
|
|
|
|
|
|
@typechecked
|
|
def match_bash_catastrophic_pattern(command: str) -> Optional[str]:
|
|
"""The matched catastrophic-path pattern for a Bash command, or None if it isn't writing
|
|
to one (or the user has trusted it). Same trust-list as match_sensitive_pattern."""
|
|
if not command or not isinstance(command, str):
|
|
return None
|
|
if not P_BASH_WRITE_OP_RE.search(command):
|
|
return None
|
|
trusted = set(load_trusted_sensitive_paths())
|
|
for raw_match in P_BASH_PATH_TOKEN_RE.finditer(command):
|
|
tok = (raw_match.group("quoted") or raw_match.group("bare") or "")
|
|
if tok and tok[0] in ("'", '"'):
|
|
tok = tok[1:-1]
|
|
if not tok:
|
|
continue
|
|
try:
|
|
norm = os.path.normpath(os.path.expanduser(tok))
|
|
except Exception:
|
|
continue
|
|
if os.sep != '/':
|
|
norm = norm.replace(os.sep, '/')
|
|
for pat in P_BASH_CATASTROPHIC_PATTERNS:
|
|
if pat in trusted:
|
|
continue
|
|
if fnmatch.fnmatch(norm, pat):
|
|
return pat
|
|
return None
|
|
|
|
|
|
@typechecked
|
|
def extract_target_path(tool_name: str, tool_input: object) -> str:
|
|
if not isinstance(tool_input, dict):
|
|
return ""
|
|
if tool_name == "NotebookEdit":
|
|
return str(tool_input.get("notebook_path") or "")
|
|
return str(tool_input.get("file_path") or "")
|
|
|
|
|
|
# Native-scheduler MCP tools that commit or mutate a recurring schedule. Always-on
|
|
# MCP servers fall through to the always_allow default, so these would otherwise fire
|
|
# silently; force them through ApprovalBar. The Cron* tools are Claude's own internal
|
|
# scheduler, denied outright in favour of the visible/auditable native one.
|
|
p_SCHEDULE_GATED = {
|
|
"mcp__openswarm-schedule__ScheduleWorkflow",
|
|
"mcp__openswarm-schedule__UpdateScheduledWorkflow",
|
|
"mcp__openswarm-schedule__DeleteScheduledWorkflow",
|
|
"mcp__openswarm-schedule__PauseAllWorkflows",
|
|
}
|
|
p_CLAUDE_INTERNAL_SCHEDULER_TOOLS = ("CronCreate", "CronList", "CronDelete")
|
|
|
|
|
|
@typechecked
|
|
def maybe_override_policy(policy: str, tool_name: str, tool_input: object) -> Tuple[str, Optional[str]]:
|
|
"""Returns (effective_policy, matched_sensitive_pattern). Flips a permissive policy to
|
|
'ask' when the target is a sensitive/catastrophic path or the Bash command looks like OS
|
|
scheduling, even if the user set the tool to always_allow, so a prompt-injected agent
|
|
writing to ~/.ssh/authorized_keys still gets surfaced. Once the user trusts a pattern,
|
|
future writes to it pass through silently."""
|
|
if tool_name == "Bash" and looks_like_os_scheduling(tool_input):
|
|
return "ask", None
|
|
if tool_name in p_CLAUDE_INTERNAL_SCHEDULER_TOOLS:
|
|
return "deny", None
|
|
# Committing or mutating a native recurring schedule is the in-app twin of the
|
|
# crontab gate above: real, user-visible, hard-to-undo, so it goes through
|
|
# ApprovalBar every time regardless of the always_allow default.
|
|
if tool_name in p_SCHEDULE_GATED:
|
|
return "ask", None
|
|
if tool_name == "Bash" and isinstance(tool_input, dict):
|
|
bash_match = match_bash_catastrophic_pattern(str(tool_input.get("command") or ""))
|
|
if bash_match:
|
|
return "ask", bash_match
|
|
if policy != "always_allow" or tool_name not in P_PATH_GATED_TOOLS:
|
|
return policy, None
|
|
matched = match_sensitive_pattern(extract_target_path(tool_name, tool_input))
|
|
if matched:
|
|
return "ask", matched
|
|
return policy, None
|
|
|
|
|
|
@typechecked
|
|
def describe_sensitive_pattern(pattern: str) -> Optional[Tuple[str, str]]:
|
|
"""The (short label, plain-English risk) shown on the approval card for a matched
|
|
pattern, from either table; None if the pattern is unknown."""
|
|
if pattern in P_SENSITIVE_PATH_INFO:
|
|
return P_SENSITIVE_PATH_INFO[pattern]
|
|
if pattern in P_BASH_CATASTROPHIC_INFO:
|
|
return P_BASH_CATASTROPHIC_INFO[pattern]
|
|
return None
|