feat(agent): added implementation authorization gate for branch/PR tools
- Added `is_implementation_authorizer` check requiring OWNER or allowlisted maintainer to authorize implementation work. - Blocked `gh_push_branch` and `gh_open_pr` for unclassified/enhancement/proposal issues without explicit directive authorization. - Auto-allowed bug and documentation issues without requiring a directive. - Propagated `authorizes_impl` flag through events, server, tasks, and worker bindings.
This commit is contained in:
@@ -54,7 +54,12 @@ def _directive_from_payload(payload: Mapping[str, Any]) -> DirectiveInfo | None:
|
||||
k, v = entry
|
||||
if isinstance(k, str) and isinstance(v, str):
|
||||
pragmas.append((k, v))
|
||||
return DirectiveInfo(body=body, author=author, pragmas=tuple(pragmas))
|
||||
return DirectiveInfo(
|
||||
body=body,
|
||||
author=author,
|
||||
pragmas=tuple(pragmas),
|
||||
authorizes_impl=bool(raw.get("authorizes_impl")),
|
||||
)
|
||||
|
||||
|
||||
async def _fetch_thread(
|
||||
|
||||
Reference in New Issue
Block a user