Skip to content

FE-1793: Scope destructive model-edit approval to one conversation - #9856

Open
kostandinang wants to merge 15 commits into
ka/fe-1793-conversation-uifrom
ka/fe-1793-conversation-permissions
Open

kostandinang wants to merge 15 commits into
ka/fe-1793-conversation-uifrom
ka/fe-1793-conversation-permissions

Conversation

@kostandinang

@kostandinang kostandinang commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

🌟 What is the purpose of this PR?

Require approval before Brunch performs destructive model edits, and provide a fresh-conversation action that resets this authority without deleting the model or saved history.

🔗 Related links

🚫 Blocked by

Stack: main → #9829 → this PR → #9857 → #9836. Voice steering #9826 is independent. This layer includes the consent, floating-minimize and Voice recovery fixes from presentation.

🔍 What does this change?

  • Keep the approval coordinator, widget, host mutation executor, input-selective interactive-tool registry, tests and documentation in one review.
  • Offer Allow, Always allow and Deny. Deny withholds that call and tells Brunch nothing changed; later calls in the same response wait for the decision, then run.
  • Scope Always allow to the current mounted conversation, until leaving/reloading. Stop cancels pending approval; historical rendering cannot grant authority. Revalidate the model after a delayed decision.
  • Let ordinary Brunch start a fresh persisted conversation while preserving the model and old history. Reset approval authority. Prepared fixtures may still disallow clearing.
  • Do not add experiment follow-up or change stock auto-layout approval behavior. No petrinaut-core changes.

Pre-Merge Checklist 🚀

🚢 Has this modified a publishable library?

  • Adds a patch changeset for @hashintel/petrinaut's input-selective interactive-tool API.

📜 Does this require a change to the docs?

  • Approval scope and fresh-conversation behavior are documented in the assistant guide.

🕸️ Does this require a change to the Turbo Graph?

  • No execution-graph changes.

⚠️ Known issues

  • See the current PR checks for CI on the main-based head. Earlier website and Playwright integration runs failed before tests because Docker could not pull the MinIO images (unauthorized: access to the requested resource is not authorized); this is not a result for the current head.
  • No real provider or microphone tests were run. Permission UI and host mutation execution use deterministic local tests.

🐾 Next steps

Review as a complete permission feature. Experiment lifecycle follows but does not supply approval authority. The history-fixture fix is retained.

🛡 What tests cover this?

  • Main-based permissions tree: all 18 Turborepo build, type-check and lint tasks passed. Both complete unit suites passed separately.
  • Petrinaut: 173 files / 1,515 tests passed. Website: 63 files / 892 tests passed.
  • Approval widget, ephemeral authority, cancellation, destructive-batch execution, model revalidation, registry selection and fresh-conversation persistence are covered by existing tests retained with this layer.
  • Before the main-based separation, the actual approval widget was rendered in a standalone local browser preview. Desktop and 390px screenshots were inspected; scope text and all three actions fit without clipping or horizontal overflow. Deny and Always allow returned the expected decisions without submitting a tool result. The rendered component sources remain unchanged; this was not a new browser run on the current head.
  • Formatting and git diff --check passed.

❓ How to test this?

  1. Run turbo run build test:unit lint:tsc lint:eslint --filter @hashintel/petrinaut --filter @apps/petrinaut-website.
  2. Run the brunch-mutation-approval, brunch-petrinaut-tools, registry and local-storage-demo-app test files.
  3. Check that destructive edits wait for a decision, Deny withholds only that call, and Always allow does not survive a new conversation or reload.
  4. Check that Clear AI chat starts a new conversation without replacing the model or claiming to delete old history.

📹 Demo

Controlled fixture using the production approval widget; no model is invoked and no mutation is executed.

Approval interaction

pr-9856-approval-interaction.mp4

@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hash Ready Ready Preview Sep 30, 2026 8:17pm UTC
petrinaut Ready Ready Preview Sep 30, 2026 8:17pm UTC
petrinaut-docs Ready Ready Preview Sep 30, 2026 8:17pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
hashdotdesign-tokens Ignored Ignored Preview Sep 30, 2026 8:17pm UTC

Request Review

@github-actions github-actions Bot added area/infra Relates to version control, CI, CD or IaC (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > frontend Owned by the @frontend team area/apps labels Sep 28, 2026
@kostandinang
kostandinang force-pushed the ka/fe-1793-conversation-permissions branch from 29ef0d7 to aaffa2d Compare September 28, 2026 17:19
@kostandinang kostandinang self-assigned this Sep 28, 2026
@kostandinang
kostandinang added this pull request to stack #9861 September 28, 2026 18:43
@kostandinang
kostandinang force-pushed the ka/fe-1793-conversation-permissions branch from 1aee06a to 59e656d Compare September 28, 2026 19:19
@kostandinang
kostandinang removed this pull request from stack #9861 September 28, 2026 19:19
@kostandinang
kostandinang added this pull request to stack #9863 September 28, 2026 19:19
@kostandinang kostandinang changed the title FE-1793: Scope destructive-edit approvals to the current conversation FE-1793: Scope destructive model-edit approval to one conversation Sep 28, 2026
@kostandinang
kostandinang marked this pull request as ready for review September 28, 2026 21:31

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread apps/petrinaut-website/src/main/app/local-storage-demo/local-storage-demo-app.tsx Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread libs/@hashintel/petrinaut/src/ui/types/ai-interactive-tool.ts Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread apps/petrinaut-website/src/main/app/local-storage-demo/local-storage-demo-app.tsx Outdated
kostandinang and others added 10 commits September 30, 2026 16:23
Destructive canonical Petrinaut calls from Brunch, every remove tool and deleteItemsByIds, wait for approval inside their in-band browser call turn, so later calls stay queued behind them. Allow runs the call, Deny settles it as not applied so Brunch accepts the result instead of failing the follow-up, and Stop cancels a pending approval. An inline approval lists the requested removals while the call waits.

Clear AI chat in ordinary Brunch starts a fresh, persisted conversation and resets conversation-only approvals without replacing the model or deleting old history.

Always allow lasts only for the current mounted conversation until leaving or reloading. Keep experiment lifecycle work in the next layer and leave stock approvals unchanged.

Refs FE-1793
Every destructive tool was registered as interactive, so its widget replaced the normal tool row everywhere: rows went blank while a call was claimed or after a decision, and completed deletions lost their usual tool row. The approval is now registered only for tools with a call waiting on the coordinator; every other row keeps its normal presentation.
Approval widgets were matched by tool name, so while one removal waited, earlier rows of the same tool swapped to the widget until the decision settled. Petrinaut interactive tools can now choose which validated inputs they handle, and the approval matches only the input of the call waiting on the coordinator.
…picking a row

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Amp <amp@ampcode.com>
Co-authored-by: Amp <amp@ampcode.com>
Co-authored-by: Amp <amp@ampcode.com>
…ation

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread libs/@hashintel/petrinaut/src/ui/types/ai-interactive-tool.ts Outdated
kube
kube previously approved these changes Sep 30, 2026
lunelson
lunelson previously approved these changes Sep 30, 2026

@lunelson lunelson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks — all threads addressed. Per-call Deny is fine as documented.

kube
kube previously approved these changes Sep 30, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6334ad6. Configure here.

Document that shouldHandle only suppresses the widget for tools the host executes itself, and name the declined call instead of reporting a registered tool as unknown.

Refs FE-1793

Co-authored-by: Cursor <cursoragent@cursor.com>

This branch was successfully deployed

4 active (1 outdated) deployments
Preview – hash — 14afd888 Deployed Sep 30, 2026 by vercel[bot]
Preview – petrinaut-docs — 14afd888 Deployed Sep 30, 2026 by vercel[bot]
Preview – petrinaut — 14afd888 Deployed Sep 30, 2026 by vercel[bot]
Preview – hashdotdesign-tokens — 8acba1df Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/apps area/infra Relates to version control, CI, CD or IaC (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > frontend Owned by the @frontend team

Development

Successfully merging this pull request may close these issues.

3 participants