diff --git a/packages/core/src/config/plugin/agent.ts b/packages/core/src/config/plugin/agent.ts index 1dbff023f4..48efe75804 100644 --- a/packages/core/src/config/plugin/agent.ts +++ b/packages/core/src/config/plugin/agent.ts @@ -60,7 +60,6 @@ export const Plugin = define({ const configuredDefault = Config.latest(documents, "default_agent") if (configuredDefault !== undefined) draft.default(AgentV2.ID.make(configuredDefault)) for (const current of draft.list()) { - yield* Effect.log({ msg: "applying permissions", id: current.id, permissions: global }) draft.update(current.id, (agent) => agent.permissions.push(...global)) } diff --git a/packages/core/test/config/agent.test.ts b/packages/core/test/config/agent.test.ts index 7085f65cd7..855659a019 100644 --- a/packages/core/test/config/agent.test.ts +++ b/packages/core/test/config/agent.test.ts @@ -77,6 +77,8 @@ describe("ConfigAgentPlugin.Plugin", () => { const buildAgent = yield* agents.get(build) if (!buildAgent) throw new Error("expected configured build agent") expect(buildAgent.permissions).toEqual([ + { action: "*", resource: "*", effect: "allow" }, + { action: "external_directory", resource: "*", effect: "ask" }, { action: "bash", resource: "*", effect: "allow" }, { action: "bash", resource: "*", effect: "ask" }, { action: "read", resource: "*", effect: "allow" }, @@ -94,6 +96,8 @@ describe("ConfigAgentPlugin.Plugin", () => { model: { providerID: "openrouter", id: "openai/gpt-5", variant: "high" }, }) expect(reviewer.permissions).toEqual([ + { action: "*", resource: "*", effect: "allow" }, + { action: "external_directory", resource: "*", effect: "ask" }, { action: "bash", resource: "*", effect: "ask" }, { action: "read", resource: "*", effect: "allow" }, { action: "edit", resource: "*", effect: "deny" }, @@ -101,6 +105,8 @@ describe("ConfigAgentPlugin.Plugin", () => { ]) expect(PermissionV2.evaluate("read", "README.md", reviewer.permissions).effect).toBe("deny") expect((yield* agents.get(AgentV2.ID.make("late")))?.permissions).toEqual([ + { action: "*", resource: "*", effect: "allow" }, + { action: "external_directory", resource: "*", effect: "ask" }, { action: "bash", resource: "*", effect: "ask" }, { action: "read", resource: "*", effect: "allow" }, { action: "edit", resource: "*", effect: "allow" }, @@ -258,13 +264,21 @@ Use native v2 fields.`, system: "Review carefully.", description: "Markdown description", request: { body: { temperature: 0.5 } }, - permissions: [{ action: "edit", resource: "*", effect: "deny" }], + permissions: [ + { action: "*", resource: "*", effect: "allow" }, + { action: "external_directory", resource: "*", effect: "ask" }, + { action: "edit", resource: "*", effect: "deny" }, + ], }) expect(yield* agents.get(AgentV2.ID.make("team/helper"))).toMatchObject({ system: "Help the team." }) expect(yield* agents.get(AgentV2.ID.make("native"))).toMatchObject({ system: "Use native v2 fields.", request: { headers: { "x-agent": "native" }, body: { effort: "high" } }, - permissions: [{ action: "edit", resource: "*", effect: "deny" }], + permissions: [ + { action: "*", resource: "*", effect: "allow" }, + { action: "external_directory", resource: "*", effect: "ask" }, + { action: "edit", resource: "*", effect: "deny" }, + ], }) expect(yield* agents.get(AgentV2.ID.make("disabled"))).toBeUndefined() expect(yield* agents.get(AgentV2.ID.make("plan"))).toMatchObject({ system: "Make a plan.", mode: "primary" })