Repository navigation
Conversation
…ssion refusals coasys/ad4m#1167 refuses calls that act on the node to a user session on a multi-user node. Two WE surfaces still reached them: - Consent prompts (approve an app, trust a peer) answer with agent.permitCapability and runtime.add/deleteTrustedAgents. They move from the agent-scoped group to a consent group offered only with administersNode, beside the other node-scoped controls. - The default model's status treated a refused ai.discoverModels as an error, because #1167's message matched none of the keywords. It now reads RpcError status 403 as unchecked, and leaves an endpoint's own Unauthorized as an error.
✅ This PR works against coasys/ad4m#1167Tested at The red required checks are only the ad4m pin. They clear once coasys/ad4m#1167 is
The run · updated on every push |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Paired with: coasys/ad4m#1167
What
ai.discoverModelsanswers 403). It reads the RPC status, not the wording of the message.Stacked on #227 (the SDK's
on()API), which this needs to build against an ad4m with coasys/ad4m#1193.Why
coasys/ad4m#1167 keeps user sessions on a multi-user node off calls that act on the node itself. Two of WE's surfaces still reached those calls:
runtime.addTrustedAgents,runtime.deleteTrustedAgentsadministersNodeagent.permitCapabilityAGENT PERMIT, which only the operator holds.administersNodeai.discoverModelscapabilit|forbidden|unauthori, so a user saw their working model marked broken. The same pattern also turned a provider's own "Unauthorized" into "unchecked".RpcErrorstatus 403; any other failure is an errorEverything else #1167 refuses was already gated in WE: backup export and import, languages, trusted agents, peers and AI model changes need
administersNode; a user session always reports itself initialised and unlocked, so WE never offers it generate or unlock; the dev link-language publish runs only in Electron, where WE is the operator.How
The shell already skips consent when the port has no
onConsentRequest(RuntimeStore.tsx), so no shell change is needed.packages/backend-system/ad4m/src/runtimeAdminAdapter.tsagentScopedinto aconsentgroup, spread only withadministersNodepackages/backend-system/ad4m/src/languageModelPort.tserr instanceof RpcError && err.status === 403→ uncheckedtests/runtimeAdminAdapter.test.tsonConsentRequest,approve,denytests/languageModelPort.test.tsDocs kept in sync
None applied: no doc describes which sessions get consent prompts; the adapter's own comments carry the rule.
Test plan
backend-ad4mtests for both files, against the SDK built from fix(api): keep user sessions off node operations; sign as the user ad4m#1167 (28/28)@coasys/ad4mlinked to the #1167 buildChangelog
none
— Hex, Josh's assistant ⬡