github / github/copilot-cli

Permission Profiles: named, switchable permission presets (global + per-repo)

Đang mở
#3,176 0 bình luận 2 reaction 0 người được giao Xem trên GitHub
area:configuration area:permissions
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the feature or problem you'd like to solve

I typically run with `/allow-all` for maximum productivity, but sometimes I want to restrict the agent (e.g., no shell execution, read-only mode, or limited directory access) for sensitive tasks or specific repos. Currently there's no way to:

1. Save a named permission configuration and switch to it quickly
2. Define per-repo permission defaults so certain repos always start restricted
3. Toggle between "full trust" and "restricted" without manually re-configuring each session

Related issues #3028 and #3050 cover parts of this (MCP tool trust and persistent directories), but neither addresses switchable named profiles.

### Proposed solution

Introduce **permission profiles** — named sets of permission rules that can be defined at two levels:

**Global profiles** (`~/.copilot/permission-profiles.json`):
```json
{
"profiles": {
"full-access": { "allowAll": true },
"read-only": {
"allowedTools": ["view", "grep", "glob", "github-mcp-server-*"],
"denyTools": ["powershell", "edit", "create"]
},
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
},
"default": "full-access"
}
```

**Per-repo profiles** (`.github/copilot-permissions.json`):
```json
{
"default": "no-shell",
"trustedDirectories": ["."],
"profiles": {
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
}
}
```

**Switching profiles in-session:**
- `/profile list` — show available profiles
- `/profile use ` — switch to a profile
- `/profile show` — show current active profile and its rules

Per-repo profiles would take precedence over global ones (team-enforced guardrails).

### Example prompts or workflows

1. Start session in infra repo → automatically applies "no-shell" profile (team policy)
2. Working on a PR review → `/profile use read-only` to ensure no accidental edits
3. Ready to implement → `/profile use full-access` to switch back
4. New session in any repo → applies user's global default without needing `/allow-all` each time

### Additional context

GitHub Copilot CLI 1.0.43

This would complement #3028 (granular MCP tool trust) and #3050 (persistent directory allow lists) by providing the overarching framework for managing permission sets.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by reviewing the proposed global ~/.copilot/permission-profiles.json and per-repository .github/copilot-permissions.json formats, then trace how the CLI currently handles permission settings. Define the profile precedence and the /profile list, /profile use, and /profile show commands; done means named profiles can be switched in-session and repository defaults override global profiles.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
shell
Lĩnh vực
authorization, cli, security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.