feat(agent): added implementation authorization gate for branch/PR tools

- Added `is_implementation_authorizer` check requiring OWNER or allowlisted maintainer to authorize implementation work.
- Blocked `gh_push_branch` and `gh_open_pr` for unclassified/enhancement/proposal issues without explicit directive authorization.
- Auto-allowed bug and documentation issues without requiring a directive.
- Propagated `authorizes_impl` flag through events, server, tasks, and worker bindings.
This commit is contained in:
can1357
2026-06-02 08:44:59 +02:00
parent 2ecb5fd9fa
commit f18eb90324
13 changed files with 252 additions and 7 deletions
+6 -1
View File
@@ -54,7 +54,12 @@ def _directive_from_payload(payload: Mapping[str, Any]) -> DirectiveInfo | None:
k, v = entry
if isinstance(k, str) and isinstance(v, str):
pragmas.append((k, v))
return DirectiveInfo(body=body, author=author, pragmas=tuple(pragmas))
return DirectiveInfo(
body=body,
author=author,
pragmas=tuple(pragmas),
authorizes_impl=bool(raw.get("authorizes_impl")),
)
async def _fetch_thread(