Non-interactive sessions bypass `disableBypassPermissionsMode` managed setting
未关闭
还没有人认领这个 Issue。
area:enterprise
area:non-interactive
area:permissions
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 14 小时 16 分钟
- 30 天内合并 PR
- 6
描述
Describe the bug
Non-interactive (-p / --prompt) with --allow-all / --yolo grant permissions automatically even when .github-private/copilot/managed-settings.json is configured with:
{
"permissions": {
"disableBypassPermissionsMode": "disable"
}
}
Attempting to run /allow-all / /yolo within the interactive shell correctly states:
Bypass permissions mode has been disabled by policy. Contact your administrator for more information.
Affected version
1.0.80
Steps to reproduce the behavior
- Configure
"disableBypassPermissionsMode": "disable". - Pass
--yolo -p {prompt}to copilot CLI.
Expected behavior
yolo mode is ignored and tool calls are denied.
Additional context
No response
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先跟踪 CLI 如何处理 -p/--prompt 与 --allow-all/--yolo 的组合,然后将该路径与交互式 /allow-all 策略检查进行比较。使用 .github-private/copilot/managed-settings.json,将 disableBypassPermissionsMode 设置为 disable;完成的标准是,非交互式工具调用会像在交互式 shell 中一样被拒绝。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- shell
- 领域
- authorization, cli, security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 活跃
- 描述清晰度
- 基本清楚
- 新手友好度
- 55/100