mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
protocol: report session permission profiles (#18282)
## Why Clients that observe `SessionConfigured` need the same canonical permission view that app-server thread responses provide. Reporting the profile in protocol events lets clients keep their local state synchronized without reinterpreting legacy sandbox fields. ## What changed This adds `permission_profile` to `SessionConfigured` and propagates it through core, exec JSON output, MCP server messages, and TUI history/widget handling. ## Verification - `cargo test -p codex-tui permissions -- --nocapture` - `cargo test -p codex-core --test all permissions_messages -- --nocapture` --- [//]: # (BEGIN SAPLING FOOTER) Stack created with [Sapling](https://sapling-scm.com). Best reviewed with [ReviewStack](https://reviewstack.dev/openai/codex/pull/18282). * #18288 * #18287 * #18286 * #18285 * #18284 * #18283 * __->__ #18282
This commit is contained in:
committed by
GitHub
Unverified
parent
2b2de3f38b
commit
082fc4f632
@@ -1470,6 +1470,33 @@ async fn record_initial_history_reconstructs_forked_transcript() {
|
||||
assert_eq!(expected, history.raw_items());
|
||||
}
|
||||
|
||||
#[tokio::test(flavor = "multi_thread", worker_threads = 2)]
|
||||
async fn session_configured_omits_permission_profile_for_external_sandbox() -> anyhow::Result<()> {
|
||||
let server = start_mock_server().await;
|
||||
let sandbox_policy = SandboxPolicy::ExternalSandbox {
|
||||
network_access: codex_protocol::protocol::NetworkAccess::Restricted,
|
||||
};
|
||||
let expected_sandbox_policy = sandbox_policy.clone();
|
||||
let mut builder = test_codex().with_config(move |config| {
|
||||
config.permissions.sandbox_policy = codex_config::Constrained::allow_any(sandbox_policy);
|
||||
config.permissions.file_system_sandbox_policy = FileSystemSandboxPolicy::external_sandbox();
|
||||
config.permissions.network_sandbox_policy = NetworkSandboxPolicy::Restricted;
|
||||
});
|
||||
|
||||
let test = builder.build(&server).await?;
|
||||
|
||||
assert_eq!(
|
||||
test.session_configured.sandbox_policy,
|
||||
expected_sandbox_policy
|
||||
);
|
||||
assert_eq!(
|
||||
test.session_configured.permission_profile, None,
|
||||
"ExternalSandbox is enforced outside the PermissionProfile model, so SessionConfigured must \
|
||||
not expose a lossy root-write profile"
|
||||
);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[tokio::test(flavor = "multi_thread", worker_threads = 2)]
|
||||
async fn fork_startup_context_then_first_turn_diff_snapshot() -> anyhow::Result<()> {
|
||||
let server = start_mock_server().await;
|
||||
|
||||
Reference in New Issue
Block a user