Permission Profiles: named, switchable permission presets (global + per-repo)
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 14 小时 16 分钟
- 30 天内合并 PR
- 6
描述
### Describe the feature or problem you'd like to solve
I typically run with `/allow-all` for maximum productivity, but sometimes I want to restrict the agent (e.g., no shell execution, read-only mode, or limited directory access) for sensitive tasks or specific repos. Currently there's no way to:
1. Save a named permission configuration and switch to it quickly
2. Define per-repo permission defaults so certain repos always start restricted
3. Toggle between "full trust" and "restricted" without manually re-configuring each session
Related issues #3028 and #3050 cover parts of this (MCP tool trust and persistent directories), but neither addresses switchable named profiles.
### Proposed solution
Introduce **permission profiles** — named sets of permission rules that can be defined at two levels:
**Global profiles** (`~/.copilot/permission-profiles.json`):
```json
{
"profiles": {
"full-access": { "allowAll": true },
"read-only": {
"allowedTools": ["view", "grep", "glob", "github-mcp-server-*"],
"denyTools": ["powershell", "edit", "create"]
},
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
},
"default": "full-access"
}
```
**Per-repo profiles** (`.github/copilot-permissions.json`):
```json
{
"default": "no-shell",
"trustedDirectories": ["."],
"profiles": {
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
}
}
```
**Switching profiles in-session:**
- `/profile list` — show available profiles
- `/profile use ` — switch to a profile
- `/profile show` — show current active profile and its rules
Per-repo profiles would take precedence over global ones (team-enforced guardrails).
### Example prompts or workflows
1. Start session in infra repo → automatically applies "no-shell" profile (team policy)
2. Working on a PR review → `/profile use read-only` to ensure no accidental edits
3. Ready to implement → `/profile use full-access` to switch back
4. New session in any repo → applies user's global default without needing `/allow-all` each time
### Additional context
GitHub Copilot CLI 1.0.43
This would complement #3028 (granular MCP tool trust) and #3050 (persistent directory allow lists) by providing the overarching framework for managing permission sets.
贡献指南
调研方向
首先检查全局 ~/.copilot/permission-profiles.json 和每个仓库的 .github/copilot-permissions.json 的拟议格式,然后跟踪 CLI 当前如何处理权限设置。定义 profile 的优先级以及 /profile list、/profile use 和 /profile show 命令;完成标准是可以在会话中切换命名 profile,并且仓库默认设置覆盖全局 profile。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- shell
- 领域
- authorization, cli, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100