"ask" permissionDecision does not suppress the native trust prompt, causing two confirmations per gated tool call
- 主要語言
- Shell
- 星號
- 11.2k
- 分支
- 1.9k
- 平均合併
- 14 小時 16 分鐘
- 30 天內合併 PR
- 6
描述
### Describe the bug
When a PreToolUse hook returns permissionDecision: "ask", the CLI shows the hook's custom permission dialog and then the native trust prompt for the same tool call. Selecting Yes on the hook's dialog should authorize the call, but instead it just advances to a second prompt, so every gated command requires two confirmations.
Selecting No on the hook's dialog correctly cancels the call with no native prompt. The double-prompt only manifests on the approval path.
### Affected version
1.0.40-0
### Steps to reproduce the behavior
1. Create a folder (e.g. repro-plugin/) with these files:.claude-plugin/plugin.json { "name":
"ask-double-prompt-repro", "version": "0.1.0" }
hooks/hooks.json {
"hooks": {
"PreToolUse": [{
"hooks": [{
"type": "command",
"command": "bash \"${CLAUDE_PLUGIN_ROOT}/hooks/scripts/gate.sh\"",
"powershell": "pwsh -NoProfile -ExecutionPolicy Bypass -File
\"${CLAUDE_PLUGIN_ROOT}/hooks/scripts/gate.ps1\"",
"timeout": 10
}]
}]
}
}
hooks/scripts/gate.ps1 $payload = [Console]::In.ReadToEnd()
$obj = $payload | ConvertFrom-Json
$cmd = [string]$obj.tool_input.command
if ($obj.tool_name -eq "powershell" -and $cmd -match "\bgit\s+push\b") {
Write-Output
'{"hookSpecificOutput":{"hookEventName":"PreToolUse","permissionDecision":"ask","permissionDecisionReason":"REPRO:
confirm push"}}'
}
exit 0
2. Start Copilot with the plugin loaded: copilot --plugin-dir
3. In the session, prompt: Run exactly this bash command and only this command, do not modify it: git push origin master
4. Select Yes on the first dialog that appears.
Result: Two sequential dialogs appear for the same tool call:
1. Hook permission request, shows permissionDecisionReason "REPRO: confirm push", with options Yes / No
2. Native trust prompt, with options Yes / Yes-and-don't-ask-again / No
### Expected behavior
A single confirmation per gated tool call. The hook's ask dialog should replace the native trust prompt, not precede
it. Selecting Yes on the hook's dialog should authorize the call and run it immediately.
### Additional context
_No response_
貢獻指南
研究方向
使用報告中描述的 plugin.json、hooks/hooks.json 和 hooks/scripts/gate.ps1 設定重現問題,然後執行載入外掛程式的 copilot CLI 命令。從 permissionDecision "ask" 的 PreToolUse 處理開始,追蹤 hook 核准如何到達原生信任提示。選取 hook 對話框中的 Yes 後,工具無需第二次原生提示即可執行,即表示完成。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- powershell, shell
- 領域
- authorization, cli
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 55/100