feat: persist permission auto-accept on server (#2158)

Move per-session permission auto-accept policy ownership from the UI to the
OpenChamber server so enabled sessions continue running when clients disconnect
or the server restarts.

- persist explicit per-session policies in OpenChamber settings
- inherit the nearest explicit policy across subagent session hierarchies
- allow child sessions to opt out of an inherited parent policy
- immediately accept matching global and directory-scoped pending requests
- process future requests without requiring a connected UI client
- reconcile pending permissions after startup and event-stream reconnects
- deduplicate concurrent requests and retry transient reply failures
- synchronize policy updates across connected clients
- migrate existing browser-persisted policies to server storage
- suppress auto-accepted permission cards before they enter UI state
- show deduplicated permission toasts for inactive sessions
- preserve foreground-only permission handling in VS Code
- integrate directory-aware notification routing from main
- add coverage for persistence, inheritance, retries, reconciliation, pending
  requests, client hydration, and inactive-session toasts
This commit is contained in:
Bohdan Triapitsyn
2026-07-12 15:03:16 +03:00
committed by GitHub
parent 3d90eddcaf
commit d738d41574
18 changed files with 795 additions and 387 deletions
@@ -0,0 +1,66 @@
import { beforeEach, describe, expect, mock, test } from 'bun:test';
let fetchImpl: (input: string, init?: RequestInit) => Promise<Response>;
mock.module('@/lib/runtime-fetch', () => ({
runtimeFetch: (input: string, init?: RequestInit) => fetchImpl(input, init),
}));
mock.module('@/sync/sync-refs', () => ({ getAllSyncSessions: () => [] }));
mock.module('@/sync/session-ui-store', () => ({
useSessionUIStore: { getState: () => ({ getDirectoryForSession: () => '/project' }) },
}));
mock.module('@/lib/opencode/client', () => ({
opencodeClient: { getDirectory: () => '/fallback' },
}));
const { usePermissionStore } = await import('./permissionStore');
const json = (value: unknown, status = 200) => new Response(JSON.stringify(value), { status });
describe('permission store server policy', () => {
beforeEach(() => {
usePermissionStore.getState().reset();
fetchImpl = async () => json({ sessions: {} });
});
test('hydrates the authoritative server snapshot', async () => {
fetchImpl = async () => json({ sessions: { root: true } });
await usePermissionStore.getState().hydrate();
expect(usePermissionStore.getState().autoAccept).toEqual({ root: true });
});
test('preserves previous state when hydration fails', async () => {
usePermissionStore.setState({ autoAccept: { root: true }, loaded: true });
fetchImpl = async () => json({}, 503);
await expect(usePermissionStore.getState().hydrate()).rejects.toThrow();
expect(usePermissionStore.getState().autoAccept).toEqual({ root: true });
});
test('updates local state only after server persistence succeeds', async () => {
fetchImpl = async () => json({}, 500);
await expect(usePermissionStore.getState().setSessionAutoAccept('root', true)).rejects.toThrow();
expect(usePermissionStore.getState().autoAccept).toEqual({});
});
test('sends the session directory for immediate pending reconciliation', async () => {
let body: unknown;
fetchImpl = async (_input, init) => {
body = JSON.parse(String(init?.body));
return json({ sessions: { root: true } });
};
await usePermissionStore.getState().setSessionAutoAccept('root', true);
expect(body).toEqual({ enabled: true, directory: '/project' });
});
test('migrates a legacy local policy when the server has no policy yet', async () => {
usePermissionStore.setState({ autoAccept: { root: true } });
const requests: string[] = [];
fetchImpl = async (input) => {
requests.push(input);
return input.includes('/sessions/')
? json({ sessions: { root: true } })
: json({ sessions: {} });
};
await usePermissionStore.getState().hydrate();
expect(requests).toEqual(['/api/permission-auto-accept', '/api/permission-auto-accept/sessions/root']);
expect(usePermissionStore.getState().autoAccept).toEqual({ root: true });
});
});