github / github/app

Tool whitelist for interactive mode (permissions)

Ouverte
#1,148 0 commentaires 4 réactions 0 personnes assignées Voir sur GitHub
Requests and ideas
Langage dominant
Aucune donnée de langage
Étoiles
2.1k
Forks
153
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Feature summary

Tool whitelist for interactive mode on a global level (not only per session or repo)

### What problem are you trying to solve?

Currently Interactive mode requires manual approval for every tool call, including safe read-only operations (grep, cat, find, git log, git status, etc.). The only alternative is /allow-all which also approves destructive operations.

This feature request was also opened in the copilot-cli repo: https://github.com/github/copilot-cli/issues/1973

### Proposed solution

A user-scoped / global `permissions-config.json` instead of on a per-repo basis (https://github.com/github/copilot-cli/issues/1973#issuecomment-4335076889), could both be a solution for the copilot CLI and for the Copilot App too. Nice to have: from the settings menu you could edit these easily.

Workaround for github CLI at this time is a command line alias that includes the right allow flags (https://github.com/github/copilot-cli/issues/1973#issuecomment-4040243845). Modifuing the command line arguments in the copilot app is not supported so this is even a bigger problem here.

### Workflow impact

This would reduce the amount of times copilot asks for manual approval drastically, while still following principle of least privilege (that's why I don't use /allow-all-tools or auto mode)

### Installation context

_No response_

### Additional context

_No response_

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start by tracing interactive-mode approval behavior and the existing /allow-all path in the Copilot App. Then inspect how user settings and per-repository permissions are represented. Done means a user-scoped permissions configuration can allow selected safe tools globally while preserving approval for unlisted or destructive operations.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Domaine
authorization, desktop
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.