github / github/copilot-cli

"ask" permissionDecision does not suppress the native trust prompt, causing two confirmations per gated tool call

未关闭
#3,042 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
area:permissions area:plugins
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

### Describe the bug

When a PreToolUse hook returns permissionDecision: "ask", the CLI shows the hook's custom permission dialog and then the native trust prompt for the same tool call. Selecting Yes on the hook's dialog should authorize the call, but instead it just advances to a second prompt, so every gated command requires two confirmations.

Selecting No on the hook's dialog correctly cancels the call with no native prompt. The double-prompt only manifests on the approval path.

### Affected version

1.0.40-0

### Steps to reproduce the behavior

1. Create a folder (e.g. repro-plugin/) with these files:.claude-plugin/plugin.json { "name":
"ask-double-prompt-repro", "version": "0.1.0" }

hooks/hooks.json {
"hooks": {
"PreToolUse": [{
"hooks": [{
"type": "command",
"command": "bash \"${CLAUDE_PLUGIN_ROOT}/hooks/scripts/gate.sh\"",
"powershell": "pwsh -NoProfile -ExecutionPolicy Bypass -File
\"${CLAUDE_PLUGIN_ROOT}/hooks/scripts/gate.ps1\"",
"timeout": 10
}]
}]
}
}

hooks/scripts/gate.ps1 $payload = [Console]::In.ReadToEnd()
$obj = $payload | ConvertFrom-Json
$cmd = [string]$obj.tool_input.command
if ($obj.tool_name -eq "powershell" -and $cmd -match "\bgit\s+push\b") {
Write-Output
'{"hookSpecificOutput":{"hookEventName":"PreToolUse","permissionDecision":"ask","permissionDecisionReason":"REPRO:
confirm push"}}'
}
exit 0
2. Start Copilot with the plugin loaded: copilot --plugin-dir
3. In the session, prompt: Run exactly this bash command and only this command, do not modify it: git push origin master
4. Select Yes on the first dialog that appears.

Result: Two sequential dialogs appear for the same tool call:

1. Hook permission request, shows permissionDecisionReason "REPRO: confirm push", with options Yes / No
2. Native trust prompt, with options Yes / Yes-and-don't-ask-again / No

### Expected behavior

A single confirmation per gated tool call. The hook's ask dialog should replace the native trust prompt, not precede
it. Selecting Yes on the hook's dialog should authorize the call and run it immediately.

### Additional context

_No response_

贡献指南

打开贡献指南

调研方向

Reproduce the issue with the plugin.json, hooks/hooks.json, and hooks/scripts/gate.ps1 setup described in the report, then run the copilot CLI command with the plugin loaded. Start at the PreToolUse handling for permissionDecision "ask" and trace how the hook approval reaches native trust prompting. Done means selecting Yes in the hook dialog runs the tool without a second native prompt.

由索引模型根据 Issue 内容生成。

评估

技术栈
powershell, shell
领域
authorization, cli
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
冷清
描述清晰度
描述清楚
新手友好度
55/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。