feat(agent): added implementation authorization gate for branch/PR tools

- Added `is_implementation_authorizer` check requiring OWNER or allowlisted maintainer to authorize implementation work.
- Blocked `gh_push_branch` and `gh_open_pr` for unclassified/enhancement/proposal issues without explicit directive authorization.
- Auto-allowed bug and documentation issues without requiring a directive.
- Propagated `authorizes_impl` flag through events, server, tasks, and worker bindings.
This commit is contained in:
can1357
2026-06-02 08:44:59 +02:00
parent 2ecb5fd9fa
commit f18eb90324
13 changed files with 252 additions and 7 deletions
+2
View File
@@ -86,6 +86,7 @@ class DirectiveInfo:
author: str
thread: tuple[ThreadMessage, ...] = ()
pragmas: tuple[tuple[str, str], ...] = ()
authorizes_impl: bool = False
def _resolve_pragma_overrides(
@@ -685,6 +686,7 @@ async def run_task(
inbound_thread_number=pr_number,
inbound_is_pr=pr_number is not None,
review_mode=review_mode,
impl_authorized=bool(directive is not None and directive.authorizes_impl),
slot_uid=inputs.slot_uid,
abort=AbortController(),
)