Skip to content

Let blocked and allowed domains apply to a rule set - #416

Draft
drudge wants to merge 1 commit into
mainfrom
claude/per-device-blocking-0lzpfb
Draft

drudge wants to merge 1 commit into
mainfrom
claude/per-device-blocking-0lzpfb

Conversation

@drudge

@drudge drudge commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Before: custom blocked and allowed domains always apply to every device. A rule set's own domains can only be typed into the rule set dialog on the Rule Sets tab.

After: the Blocked and Allowed tabs have an Applies to picker, offering Everyone or any rule set. Picking a rule set shows that rule set's own domains, with a line saying they apply only to its devices and win over everyone's. Add Domain, Import, Export, Clear All and each row's remove button all follow the picker. The Add Blocked Domain and Add Allowed Domain dialogs carry the same picker, defaulting to the one on the page, and a domain added to a rule set lands in that view. The picker only shows when there are rule sets, so nothing changes for anyone without one. The MCP allow_domain, block_domain and remove_domain_rule tools gain an optional rule_set argument.

Part of #240 (PR 4c). The Bypass Clients move into a built-in rule set comes next as its own PR, because it needs the rule set dialog to take addresses and networks first.

How: policyService takes a rule set on every change and works on a domainLists pair (everyone's or the rule set's), so the lists stay exclusive inside each scope and the audit log records rule_set. An unknown rule set is refused with a 422. blockingView reads rule_set from the request, and a new GET /ui/blocking/domains re-renders the page content when the picker changes. Export names the file after the rule set, such as warehouse-blocked-domains.txt.

Screenshots

Before shots are from main. The rule set views and dialogs are new, so they have after shots only.

Before After
Blocked tab, everyone before after
Blocked tab, everyone, dark before after
Allowed tab, everyone before after
Allowed tab, everyone, dark before after
Add Blocked Domain before after
Add Blocked Domain, dark before after
Blocked tab, Warehouse rule set after
Blocked tab, Warehouse rule set, dark after
Add Blocked Domain, from Warehouse after
Add Blocked Domain, from Warehouse, dark after
Clear All, Warehouse after
Clear All, Warehouse, dark after
Phone
Before After
Blocked tab, everyone before after
Blocked tab, everyone, dark before after
Allowed tab, everyone before after
Allowed tab, everyone, dark before after
Add Blocked Domain before after
Add Blocked Domain, dark before after
Blocked tab, Warehouse rule set after
Blocked tab, Warehouse rule set, dark after
Add Blocked Domain, from Warehouse after
Add Blocked Domain, from Warehouse, dark after
Clear All, Warehouse after
Clear All, Warehouse, dark after

Testing

go tool mage verify passes. TestDomainTabsApplyToARuleSet covers the picker, scoped add/remove/export, and an unknown rule set; the policy service and MCP tests cover the new argument.

An Applies to picker on the Domains and Allowed tabs, and on the Add Blocked
Domain and Add Allowed Domain dialogs, chooses between everyone's lists and
one rule set's own. Adding, removing, importing, exporting and clearing all
follow it. policyService takes the rule set, so the MCP allow_domain,
block_domain and remove_domain_rule tools gain an optional rule_set too.

Part of #240.
drudge added a commit that referenced this pull request Oct 9, 2026
@drudge
drudge marked this pull request as draft October 9, 2026 10:58

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant