feat(chat): default scoped project conversations to workspace writes - #5555
Open
huangruiteng wants to merge 3 commits into
Open
huangruiteng wants to merge 3 commits into
huangruiteng wants to merge 3 commits into
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ordinary project Chat currently refuses requested file edits because both the Codex sandbox and conversational prompt are read-only. Default host-declared project workspaces and Codex project App bindings now support
workspace_write, with an explicit read-only option. The existing typed context owner derives the actual host sandbox on start and exact-thread resume, without Task/Goal mode or manager authority.Settings, persisted App readback and
/status//helpagree with the effective grant.--project-workspace-grant workspace_readrestricts both local Chat and App binding creation/resume. Changing an App grant creates a new binding/Session and requires new Agent target authorization; old Sessions cannot gain permission or move audiences. Other executors and steward/attached-host permissions remain independently scoped. Material Lifecycle still requires its own explicit activation and project adapter.Stacked on #5546 at
e05382373f21e4660fdc8377af109264fa9ecc9f; the PR base isolates this increment and does not repeat its unmerged foundations. The base includes the current main99839aeb8fed5fae38a5d319391cd050672a6508.Validation on this head:
The existing IO census was regenerated for three shifted line references, without adding direct IO classifications. Shared project context/binding remains the permission owner; no provider-local Session authority, new runner or scheduler. Runtime/product/permission changes require maintainer review and are not self-merged.