feat(agent): added implementation authorization gate for branch/PR tools

- Added `is_implementation_authorizer` check requiring OWNER or allowlisted maintainer to authorize implementation work.
- Blocked `gh_push_branch` and `gh_open_pr` for unclassified/enhancement/proposal issues without explicit directive authorization.
- Auto-allowed bug and documentation issues without requiring a directive.
- Propagated `authorizes_impl` flag through events, server, tasks, and worker bindings.
This commit is contained in:
can1357
2026-06-02 08:44:59 +02:00
parent 2ecb5fd9fa
commit f18eb90324
13 changed files with 252 additions and 7 deletions
+1
View File
@@ -379,6 +379,7 @@ def create_app(settings: Settings | None = None) -> FastAPI:
"body": decision.directive_body,
"author": decision.directive_author,
"pragmas": [list(item) for item in decision.directive_pragmas],
"authorizes_impl": decision.directive_authorizes_impl,
}
if not decision.should_queue: