You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(managed-agent): show the pending tool call's input on Hosted approval Actions #13160
A pending Hosted permission Action should carry a bounded preview of the exact tool input it asks about, on both the public and WebShell Actions routes, so whoever answers it can see what will run.
Where main is today
The Harness already stores the input. Before asking, HostedWorkspaceToolTurn publishes the call's exact input as a durable managed-tool-input resource and records it as the wait's invocationRef (packages/cli/src/serve/hosted-workspace-tool-turn.ts, the approval loop that calls resources.publish('managed-tool-input', …)).
The Action record does not reference it. The action.changed payload and its managed-action-options resource are closed shapes that Java validates key by key: requestId, kind, source, inputRevision, optionsRef, state, decisionRef, and v, requestId, turnId, functionCallId, toolName, policyRevision, inputRevision, createdAt, expiresAt, options (ManagedActionStore). Java therefore cannot read the input, and the public and WebShell Action views carry only toolName and functionCallId.
The transcript deliberately omits arguments.HarnessEventProjector.safeToolData copies only toolCallId, callId, title, status and name into tool-call Items. That is a reasonable default for the transcript and is not what this issue proposes to change.
The WebShell card is ready.feat(web-shell): show and answer Hosted tool approvals in the Managed panel #13107 shows a pending approval's arguments when a transcript tool row carries them and otherwise says they are unavailable. Against a real Hosted deployment it always takes the second branch today, so a person approves write_file, edit or, once enabled, a Shell command without seeing its input.
Proposed slice
Harness. Add the input reference to the Action, either as a new key in the action.changed payload or as a field of a v: 2 options resource, so Java can resolve it. Keep v: 1 readable.
Java. Resolve the managed-tool-input resource for a requested Action and expose a bounded preview on PublicAction and WebShellPermissionAction: the JSON input truncated to a fixed byte limit (for example 8 KiB) with a truncated flag and the full byte length. A resource that is missing or fails validation yields no preview and never fails the Action read. The new fields are added to the OpenAPI contract and the generated WebShell types.
WebShell. When the transcript has no arguments for the call, show the Action's preview in the approval card, marked as truncated when it is.
Out of scope
Projecting arguments into the transcript or Items.
Secret redaction beyond the byte bound. If a redaction policy is required before this ships, it should be decided here first.
A Hosted write_file or edit approval read through either surface carries a preview equal to the start of the exact input the tool would receive, with truncated set correctly at the byte limit.
A large input stays within the bound; a missing or invalid input resource yields an Action without a preview rather than an error.
The WebShell card shows the preview when the transcript has no arguments, and the transcript's own projection is unchanged.
Contract tests cover the new fields on both surfaces; the generated WebShell types are regenerated, not hand-edited.
Why is this needed?
Approval is part of the first Hosted slice's release boundary in #12380, and an approval made without seeing the input is not a meaningful control. It also gates public Hosted Shell (#12952): a Shell call must not be approved blind. The #12380 delivery snapshot lists "publish tool-call Items, project bounded/redacted arguments … to the durable transcript/card" under remaining D6 work with no implementation PR. This issue proposes the narrower card path, which needs neither a transcript policy change nor the output-projection line.
I'd like to implement this (Harness, Java and WebShell parts) once the D6 owner agrees with the shape, in particular the byte bound and whether redaction must come first.
What would you like to be added?
A pending Hosted permission Action should carry a bounded preview of the exact tool input it asks about, on both the public and WebShell Actions routes, so whoever answers it can see what will run.
Where
mainis todayHostedWorkspaceToolTurnpublishes the call's exact input as a durablemanaged-tool-inputresource and records it as the wait'sinvocationRef(packages/cli/src/serve/hosted-workspace-tool-turn.ts, the approval loop that callsresources.publish('managed-tool-input', …)).action.changedpayload and itsmanaged-action-optionsresource are closed shapes that Java validates key by key:requestId,kind,source,inputRevision,optionsRef,state,decisionRef, andv,requestId,turnId,functionCallId,toolName,policyRevision,inputRevision,createdAt,expiresAt,options(ManagedActionStore). Java therefore cannot read the input, and the public and WebShell Action views carry onlytoolNameandfunctionCallId.HarnessEventProjector.safeToolDatacopies onlytoolCallId,callId,title,statusandnameinto tool-call Items. That is a reasonable default for the transcript and is not what this issue proposes to change.write_file,editor, once enabled, a Shell command without seeing its input.Proposed slice
action.changedpayload or as a field of av: 2options resource, so Java can resolve it. Keepv: 1readable.managed-tool-inputresource for a requested Action and expose a bounded preview onPublicActionandWebShellPermissionAction: the JSON input truncated to a fixed byte limit (for example 8 KiB) with atruncatedflag and the full byte length. A resource that is missing or fails validation yields no preview and never fails the Action read. The new fields are added to the OpenAPI contract and the generated WebShell types.Out of scope
await_action, and question or vote Actions. These are the other remaining D6 items in the proposal(serve): Define Managed Agent dual-path architecture and staged delivery #12380 snapshot.Acceptance
write_fileoreditapproval read through either surface carries a preview equal to the start of the exact input the tool would receive, withtruncatedset correctly at the byte limit.Why is this needed?
Approval is part of the first Hosted slice's release boundary in #12380, and an approval made without seeing the input is not a meaningful control. It also gates public Hosted Shell (#12952): a Shell call must not be approved blind. The #12380 delivery snapshot lists "publish tool-call Items, project bounded/redacted arguments … to the durable transcript/card" under remaining D6 work with no implementation PR. This issue proposes the narrower card path, which needs neither a transcript policy change nor the output-projection line.
Additional context
中文说明
希望增加什么?
待处理的 Hosted 权限 Action 应在公开与 WebShell 的 Actions 路由上携带它所询问的确切工具输入的有界预览,让作答的人能看到将要执行的内容。
main当前状态HostedWorkspaceToolTurn把这次调用的确切输入发布为持久的managed-tool-input资源,并记录为等待的invocationRef(packages/cli/src/serve/hosted-workspace-tool-turn.ts中调用resources.publish('managed-tool-input', …)的审批循环)。action.changed载荷与其managed-action-options资源都是封闭结构,Java 逐个键校验:requestId、kind、source、inputRevision、optionsRef、state、decisionRef,以及v、requestId、turnId、functionCallId、toolName、policyRevision、inputRevision、createdAt、expiresAt、options(ManagedActionStore)。因此 Java 读不到输入,公开与 WebShell 的 Action 视图只有toolName和functionCallId。HarnessEventProjector.safeToolData只把toolCallId、callId、title、status、name复制进工具调用 Item。这对转录是合理的默认值,本 issue 不打算改变它。write_file、edit,以及开启后的 Shell 命令。提议的切片
action.changed载荷的新键,或作为v: 2options 资源的字段,让 Java 能解析它。保持v: 1可读。managed-tool-input资源,在PublicAction与WebShellPermissionAction上暴露有界预览:按固定字节上限(例如 8 KiB)截断的 JSON 输入,附truncated标志与完整字节长度。资源缺失或校验失败时不提供预览,且绝不让 Action 读取失败。新字段加入 OpenAPI 契约与生成的 WebShell 类型。不在范围内
await_action处的重启恢复、提问与投票类 Action。这些是 proposal(serve): Define Managed Agent dual-path architecture and staged delivery #12380 快照中其余的 D6 项。验收
write_file或edit审批时,预览等于工具将收到的确切输入的开头,在字节上限处正确设置truncated。为什么需要?
审批属于 #12380 首个 Hosted 切片的发布边界,看不到输入的审批不是有效的控制。它也是公开 Hosted Shell(#12952)的前提:Shell 调用不能被盲批。#12380 交付快照把"发布工具调用 Item、把有界/脱敏的参数投影到持久转录/卡片"列为没有实现 PR 的剩余 D6 工作。本 issue 提出更窄的卡片路径,既不需要改变转录策略,也不依赖输出投影那条线。
补充信息