fix(notifications): suppress permission notifs when session auto-accepts

Server now mirrors client-side Permission Auto-Accept via
POST /api/notifications/auto-accept and short-circuits permission.asked
dispatch (walking the session parent chain). Prior 500ms debounce raced
the client auto-response and leaked notifications.

Also hint under Summarize Last Message that templates must contain
{last_message} for the setting to take effect.
This commit is contained in:
Bohdan Triapitsyn
2026-04-22 19:22:50 +03:00
parent 1ad64cc69e
commit a2730b793e
7 changed files with 91 additions and 0 deletions
@@ -46,6 +46,7 @@ export const registerNotificationRoutes = (app, dependencies) => {
markSessionUnviewed,
markUserMessageSent,
setPushInitialized,
setAutoAcceptSession,
} = dependencies;
const ensureSessionWatcher = async () => {
@@ -294,4 +295,20 @@ export const registerNotificationRoutes = (app, dependencies) => {
messageSent: true,
});
});
// Mirror client-side Permission Auto-Accept state to the server so it can
// suppress permission notifications at the source (the 500ms debounce race
// otherwise leaks notifications for auto-accepted permissions).
app.post('/api/notifications/auto-accept', (req, res) => {
const body = req.body && typeof req.body === 'object' ? req.body : {};
const sessionId = typeof body.sessionId === 'string' ? body.sessionId.trim() : '';
const enabled = body.enabled === true;
if (!sessionId) {
return res.status(400).json({ error: 'sessionId required' });
}
if (typeof setAutoAcceptSession === 'function') {
setAutoAcceptSession(sessionId, enabled);
}
return res.json({ success: true, sessionId, enabled });
});
};