Skip to content

feat(ai): F008 permission bridge, allowlist, mobile confirm card, and audit log - #9

Merged
nimat-dev merged 1 commit into
mainfrom
feat/F008
Oct 8, 2026
Merged

nimat-dev merged 1 commit into
mainfrom
feat/F008

Conversation

@nimat-dev

Copy link
Copy Markdown
Owner

Summary

Implements F008 — Permission bridge + confirm UI + allowlist + audit log:

  • Wire Protocol (packages/protocol):
    • RiskHint enum: "low" | "medium" | "high".
    • Pure classifyRisk(toolName, input): detects safe read-only operations ("low"), file writes/modifications ("medium"), and destructive patterns ("high" — rm, sudo, dd, git reset --hard, chained && rm, $()).
    • Pure isReadonlyCommand(toolName, input): allowlist evaluator.
    • perm.request and perm.response envelopes, Zod schemas, and serializers.
  • Pure Core Interfaces (packages/agent/src/core):
    • IPermissionBridge, PermissionRequest, PermissionDecision in src/core/permission.ts (0 Node builtins or I/O imports).
    • IAuditLogger, AuditEntry in src/core/audit.ts (0 Node builtins or I/O imports).
  • Concrete Adapters (packages/agent/src/adapters):
    • PermissionBridge: auto-allows safe read-only operations without interrupting the user, prompts mobile client for writes/destructive actions, session allowlist with "remember for session", 60s timeout to default deny, idempotent double-tap resolution, denyAllPending() on disconnect/abort/revocation.
    • FileAuditLogger: atomic append-only JSONL file logger with mode 0600; written before releasing execution of dangerous commands; rejects tool if audit writing fails.
    • ClaudeStreamParser & LocalClaudeDriver: intercepts stdio control_request (can_use_tool) from Claude Code, queries PermissionBridge, and sends control_response (allow or deny) back over stdin.
    • AgentDaemon: routes perm.request to connected mobile client, handles perm.response, denys pending on disconnect or device revocation.
  • Mobile Client & UI (packages/mobile):
    • onPermissionRequest() and respondPermission() in AgentClient.
    • PermissionCard.tsx: React Native component displaying tool name, command box, cwd, color-coded risk badge (Green/Amber/Red), remember checkbox, and Allow/Deny buttons.
  • Maestro E2E & Verification:
    • Flow: .maestro/permission_flow.yaml.
    • Evidence: .harness/evidence/F008/ (arch-summary.txt, test-summary.txt, e2e-trace.txt).
    • Full suite passing: 99/99 tests, 0 dependency violations (61 modules cruised).

@nimat-dev nimat-dev left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maker-Checker Evaluation: F008 (Permission bridge + confirm UI + allowlist + audit log)

  1. Acceptance Criteria Verification:

    • Intercepts stdio permission prompts from Claude Code and surfaces perm.request across Tailnet transport: PASS.
    • Pure classifyRisk detects read-only (low), writes (medium), and destructive commands (high): PASS.
    • Pure isReadonlyCommand allowlist auto-approves safe read-only operations without human friction: PASS.
    • Append-only file audit log with mode 0600 written BEFORE executing approved operations: PASS.
    • Edge cases tested: timeout to default deny, double-tap idempotency, disconnect abort & pending rejection, device revocation immediate denial, chained/obfuscated command detection: PASS.
    • Mobile PermissionCard component with color-coded risk badge, session checkbox, Allow/Deny actions: PASS.
  2. Architecture & Boundaries:

    • Zero Node builtins or I/O in packages/protocol and packages/agent/src/core.
    • Dependency-cruiser: 61 modules cruised, 0 violations. Clean architecture verified.
  3. Test Battery & CI:

    • 99/99 tests passing monorepo-wide.
    • GitHub Actions CI checks all green.

Ready for squash merge.

@nimat-dev
nimat-dev merged commit 091c4ad into main Oct 8, 2026
2 checks passed
@nimat-dev
nimat-dev deleted the feat/F008 branch October 8, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant