TanStack / TanStack/intent

Add worktree-local Intent policy overlays

Open
#228 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
TypeScript
Stars
331
Forks
22
Avg merge
12h 17m
Merged PRs (30d)
51

Description

Problem

Intent policy is currently shared through package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide .intent/hooks.

User outcome

A user can manually create a valid .intent/config.local.json beside the nearest owning package.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.

Example:

{
  "skills": [
    "@acme/private-skill"
  ],
  "exclude": [
    "@acme/unsafe-skill"
  ]
}

In scope

  • Add .intent/config.local.json discovery beside the nearest owning package.json as the sole local policy source. Keep package.json as the sole shared committed source.
  • Provide reusable guarded local resolver and storage behavior that future installer or review work may consume.
  • Require local policy operations to run in a Git worktree. Use only the exact sidecar path in $GIT_COMMON_DIR/info/exclude; do not ignore .intent/, and preserve .intent/hooks.
  • Check that the exact local path is untracked on every local read and write. Reject tracked paths even when info/exclude contains the path.
  • Support a top-level JSON object with optional skills and exclude fields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars.
  • Activate a manually created valid local file automatically. Fail closed when a present local file is tracked, unreadable, malformed, or not exactly ignored.
  • Compile shared and local skill selectors independently. For declared shared policy, grant a candidate when either predicate matches. Preserve existing package, exact-skill, wildcard, npm, and workspace semantics.
  • Preserve migration behavior when shared intent.skills is absent and local skills is omitted or []. A non-empty local skills, including ["*"], ends that migration mode.
  • Apply shared and local exclusions as final additive denials. Local policy must never restore a skill denied by shared policy.
  • Make all policy consumers use the same effective-policy resolver: list, load, stale, support diagnostics, install --map, and hooks.

Acceptance criteria

  • A valid manual .intent/config.local.json beside the nearest owning package.json is discovered and applied automatically in a Git worktree.
  • The local file is accepted only when the exact path is untracked and exactly ignored through $GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes.
  • .intent/hooks remains usable, and the implementation never ignores .intent/ as a whole directory.
  • A tracked, unreadable, malformed, or not-exactly-ignored present local file fails closed with actionable diagnostics.
  • The local object rejects unknown top-level fields, accepts only optional skills and exclude, requires at least one of them, and validates each present array under existing selector or exclusion rules.
  • Shared and local selector sets are compiled independently. For declared shared policy, a candidate is granted when either set matches without changing package, exact-skill, wildcard, npm, or workspace semantics.
  • Shared and local exclusions both deny matching candidates after grant selection. A shared exclusion cannot be bypassed locally.
  • When shared intent.skills is absent, omitted or empty local skills preserves current migration behavior. A non-empty local skills, including ["*"], ends it.
  • list, load, stale, support diagnostics, install --map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics.
  • The work introduces no .intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.

Related work

Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.

#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the existing package.json policy path and the effective-policy consumers named in the issue: list, load, stale, support diagnostics, install --map, and hooks. Implement and verify the guarded .intent/config.local.json resolver so Git tracking and exact-ignore checks, validation, selector compilation, exclusions, migration behavior, and shared-policy precedence match the acceptance criteria.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
authorization, cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.