Skip to content

feat(managed-agent): show the pending tool call's input on Hosted approval Actions #13160

Description

@yiliang114

What would you like to be added?

A pending Hosted permission Action should carry a bounded preview of the exact tool input it asks about, on both the public and WebShell Actions routes, so whoever answers it can see what will run.

Where main is today

  • The Harness already stores the input. Before asking, HostedWorkspaceToolTurn publishes the call's exact input as a durable managed-tool-input resource and records it as the wait's invocationRef (packages/cli/src/serve/hosted-workspace-tool-turn.ts, the approval loop that calls resources.publish('managed-tool-input', …)).
  • The Action record does not reference it. The action.changed payload and its managed-action-options resource are closed shapes that Java validates key by key: requestId, kind, source, inputRevision, optionsRef, state, decisionRef, and v, requestId, turnId, functionCallId, toolName, policyRevision, inputRevision, createdAt, expiresAt, options (ManagedActionStore). Java therefore cannot read the input, and the public and WebShell Action views carry only toolName and functionCallId.
  • The transcript deliberately omits arguments. HarnessEventProjector.safeToolData copies only toolCallId, callId, title, status and name into tool-call Items. That is a reasonable default for the transcript and is not what this issue proposes to change.
  • The WebShell card is ready. feat(web-shell): show and answer Hosted tool approvals in the Managed panel #13107 shows a pending approval's arguments when a transcript tool row carries them and otherwise says they are unavailable. Against a real Hosted deployment it always takes the second branch today, so a person approves write_file, edit or, once enabled, a Shell command without seeing its input.

Proposed slice

  1. Harness. Add the input reference to the Action, either as a new key in the action.changed payload or as a field of a v: 2 options resource, so Java can resolve it. Keep v: 1 readable.
  2. Java. Resolve the managed-tool-input resource for a requested Action and expose a bounded preview on PublicAction and WebShellPermissionAction: the JSON input truncated to a fixed byte limit (for example 8 KiB) with a truncated flag and the full byte length. A resource that is missing or fails validation yields no preview and never fails the Action read. The new fields are added to the OpenAPI contract and the generated WebShell types.
  3. WebShell. When the transcript has no arguments for the call, show the Action's preview in the approval card, marked as truncated when it is.

Out of scope

Acceptance

  • A Hosted write_file or edit approval read through either surface carries a preview equal to the start of the exact input the tool would receive, with truncated set correctly at the byte limit.
  • A large input stays within the bound; a missing or invalid input resource yields an Action without a preview rather than an error.
  • The WebShell card shows the preview when the transcript has no arguments, and the transcript's own projection is unchanged.
  • Contract tests cover the new fields on both surfaces; the generated WebShell types are regenerated, not hand-edited.

Why is this needed?

Approval is part of the first Hosted slice's release boundary in #12380, and an approval made without seeing the input is not a meaningful control. It also gates public Hosted Shell (#12952): a Shell call must not be approved blind. The #12380 delivery snapshot lists "publish tool-call Items, project bounded/redacted arguments … to the durable transcript/card" under remaining D6 work with no implementation PR. This issue proposes the narrower card path, which needs neither a transcript policy change nor the output-projection line.

Additional context

中文说明

希望增加什么?

待处理的 Hosted 权限 Action 应在公开与 WebShell 的 Actions 路由上携带它所询问的确切工具输入的有界预览,让作答的人能看到将要执行的内容。

main 当前状态

  • Harness 已经保存了输入。 发起询问前,HostedWorkspaceToolTurn 把这次调用的确切输入发布为持久的 managed-tool-input 资源,并记录为等待的 invocationRef(packages/cli/src/serve/hosted-workspace-tool-turn.ts 中调用 resources.publish('managed-tool-input', …) 的审批循环)。
  • Action 记录没有引用它。 action.changed 载荷与其 managed-action-options 资源都是封闭结构,Java 逐个键校验:requestId、kind、source、inputRevision、optionsRef、state、decisionRef,以及 v、requestId、turnId、functionCallId、toolName、policyRevision、inputRevision、createdAt、expiresAt、options(ManagedActionStore)。因此 Java 读不到输入,公开与 WebShell 的 Action 视图只有 toolName 和 functionCallId。
  • 转录刻意不含参数。 HarnessEventProjector.safeToolData 只把 toolCallId、callId、title、status、name 复制进工具调用 Item。这对转录是合理的默认值,本 issue 不打算改变它。
  • WebShell 卡片已就绪。 feat(web-shell): show and answer Hosted tool approvals in the Managed panel #13107 在转录的工具行带参数时显示参数,否则提示参数不可见。在真实 Hosted 部署中它目前总是走第二个分支,所以用户在看不到输入的情况下批准 write_file、edit,以及开启后的 Shell 命令。

提议的切片

  1. Harness。 把输入引用加到 Action 上:作为 action.changed 载荷的新键,或作为 v: 2 options 资源的字段,让 Java 能解析它。保持 v: 1 可读。
  2. Java。 为待处理的 Action 解析 managed-tool-input 资源,在 PublicAction 与 WebShellPermissionAction 上暴露有界预览:按固定字节上限(例如 8 KiB)截断的 JSON 输入,附 truncated 标志与完整字节长度。资源缺失或校验失败时不提供预览,且绝不让 Action 读取失败。新字段加入 OpenAPI 契约与生成的 WebShell 类型。
  3. WebShell。 当转录中没有该调用的参数时,在审批卡片中显示 Action 的预览,截断时予以标注。

不在范围内

验收

  • 通过任一入口读取 Hosted write_file 或 edit 审批时,预览等于工具将收到的确切输入的开头,在字节上限处正确设置 truncated。
  • 大输入保持在上限内;输入资源缺失或无效时,返回不带预览的 Action,而不是报错。
  • 转录没有参数时,WebShell 卡片显示预览;转录自身的投影不变。
  • 契约测试覆盖两个入口的新字段;WebShell 生成类型通过生成器重新生成,而非手改。

为什么需要?

审批属于 #12380 首个 Hosted 切片的发布边界,看不到输入的审批不是有效的控制。它也是公开 Hosted Shell(#12952)的前提:Shell 调用不能被盲批。#12380 交付快照把"发布工具调用 Item、把有界/脱敏的参数投影到持久转录/卡片"列为没有实现 PR 的剩余 D6 工作。本 issue 提出更窄的卡片路径,既不需要改变转录策略,也不依赖输出投影那条线。

补充信息

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions