P2 BLOCKING exit green: approval interception chain end-to-end
- tc-tools: Effect declarations -> §15 GatedCategory mapping, deny-by-default external reach, taint invariant property-tested (tainted external effects are NEVER auto-allowed) - tc-safety: pending approvals with exact payload+preview, CAS decide with audit + single-use grant in one tx, checkpoint suspend/load, exclusive resume claim, expiry sweep, decided-unresumed work queue (migration 0004 adds the outbox the gated email.send tool writes) - tc-runtime: resumable LoopState checkpointed to agent_runs; gated tool -> approval row -> approval_required/run_suspended events -> suspend; resume consumes the grant BEFORE executing (spent grant = no execution), rejection feeds a structured refusal in-band; durable resume sweeper; continuous journal seq across suspension (tested). ContentPart::Text became a struct variant — internally-tagged newtype primitives don't serialize - tc-api: GET/decide approvals endpoints (409 double-decide, tenant isolation), decision triggers in-process resume; full chain proven over HTTP incl. gateway resumeFrom continuation - frontend: approval_required/run_suspended events, suspended reply state, inline ApprovalCard (§10: summary, category, exact payload preview, approve/reject -> decide + stream re-attach), /approvals queue page, nav - E2E (14 journeys, workers:1 to serialize the shared backend): gated email blocks with disabled composer -> approve -> continuation + ✓ step + reload replay; reject -> ✗ step, nothing executed; queue page decides pending 106 Rust + 61 frontend tests + 14 Playwright journeys green. Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
co-authored by
Claude Fable 5
parent
9f9f507c15
commit
de38449b41
@@ -30,6 +30,18 @@ pub enum RunEventBody {
|
||||
status: String,
|
||||
output: Value,
|
||||
},
|
||||
/// A gated action awaits human review (§15): carries the exact preview
|
||||
/// of what will execute, surfaced as the approval card (§10).
|
||||
ApprovalRequired {
|
||||
approval_id: Uuid,
|
||||
category: String,
|
||||
action_type: String,
|
||||
preview: Value,
|
||||
},
|
||||
/// The run is blocked until the pending approval is decided.
|
||||
RunSuspended {
|
||||
approval_id: Uuid,
|
||||
},
|
||||
RunCompleted {
|
||||
message_id: String,
|
||||
},
|
||||
@@ -46,6 +58,8 @@ impl RunEventBody {
|
||||
RunEventBody::TextDelta { .. } => "text_delta",
|
||||
RunEventBody::StepStarted { .. } => "step_started",
|
||||
RunEventBody::StepFinished { .. } => "step_finished",
|
||||
RunEventBody::ApprovalRequired { .. } => "approval_required",
|
||||
RunEventBody::RunSuspended { .. } => "run_suspended",
|
||||
RunEventBody::RunCompleted { .. } => "run_completed",
|
||||
RunEventBody::Error { .. } => "error",
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user