Refuse any change through a verb to a module with a trusted mergeable file
A mergeable file takes any key, not only those its content names, so an empty runtime configuration a provider reads took a url of the caller's through the settings verb (hq issue 340 review).
This commit is contained in:
@@ -30,6 +30,10 @@ import (
|
||||
// managed settings and tool servers every Claude Code session on a node obeys in one, and through a verb an
|
||||
// agent could have given every person's session a hook of its own.
|
||||
//
|
||||
// 4. **A module's whole layer, when it has a mergeable file not marked `"trusted": false`** (novox/hq issue 340,
|
||||
// TrustedMergeable). A mergeable file takes any key a layer sets, not only those its content names, so no list
|
||||
// of keys covers it: an empty runtime configuration a provider reads would take a `url` of the caller's.
|
||||
//
|
||||
// Derived from the manifest, never listed by hand, so a provider or a trusted file added tomorrow is covered.
|
||||
|
||||
// TrustedField is the key a file resource carries to say whether the settings it asks for are trusted: true, or
|
||||
@@ -92,6 +96,28 @@ func UnsaidTrust(m Manifest) []string {
|
||||
return out
|
||||
}
|
||||
|
||||
// TrustedMergeable is every mergeable file of a module not marked `"trusted": false`, by id (novox/hq issue 340).
|
||||
// A mergeable file takes any key a layer sets, not only those its content names: an empty runtime configuration a
|
||||
// provider reads takes a `url` of a caller's as surely as a declared one. So a module holding one has its whole
|
||||
// layer set at the controller's terminal; a verb may read it and change nothing.
|
||||
func TrustedMergeable(m Manifest) []string {
|
||||
var out []string
|
||||
for _, r := range m.Resources {
|
||||
if fmt.Sprint(r["type"]) != "file" {
|
||||
continue
|
||||
}
|
||||
if how, _ := r["merge"].(string); how == "" {
|
||||
continue
|
||||
}
|
||||
if trusted, said := r[TrustedField].(bool); said && !trusted {
|
||||
continue
|
||||
}
|
||||
out = append(out, fmt.Sprint(r["id"]))
|
||||
}
|
||||
sort.Strings(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// asksFor is every setting a file resource asks for: each `${setting:…}` in its content and, for a mergeable file,
|
||||
// every key at the top of the content it merges into (novox/hq issue 340). Those are the keys the file declares it
|
||||
// takes: a layer's value for one of them lands in it as surely as a placeholder would be filled. A key the content
|
||||
|
||||
Reference in New Issue
Block a user