aws / aws/amazon-q-developer-cli

[Feature Request] Customizing bash command permissions.

Offen
#2,401 0 Kommentare 4 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Rust
Sterne
2k
Forks
439
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

In Q CLI, you are given two tool trust options: trust on a per-command basis, and trust on every command basis. However, for the execute_bash tool, it is very hard for developers to provide full trust to this tool, since there are a wide variety of bash commands. However, the user may want to give trust to some bash commands (for example, mkdir and cd for file navigation and directory creation). Giving the user customization options over which bash commands are acceptable will help increase developer trust with using Q CLI tools, especially in agent script usage where they trust certain parts of the script to run autonomously using bash commands, but don't trust every command.

If needed, I can help take a look at adding this functionality. I had done a small pr for Q CLI a month ago, and am eager to learn more about the codebase as well.

Thank you!

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Das Issue nennt Q CLI, das Tool execute_bash sowie die bestehenden Trust-Optionen pro Befehl und für jeden Befehl, aber keine Dateien oder Tests. Beginne damit, execute_bash und diese Pfade zur Verarbeitung von Trust zu lokalisieren; die Arbeit ist abgeschlossen, wenn eine definierte Konfiguration und eine testbare Regel ausgewählte Bash-Befehle ohne Vertrauen in jeden Befehl erlauben.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
bash, rust
Bereich
cli, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.