feat(pi-permission-inner-cmd): authorize inner commands behind timeout wrappers

- recover the full bash command from the session by tool-call id
- add recognizer for the strict timeout wrapper grammar
- add authorizer mapping inner allow/ask/deny and forwarding agent name
- defer fail-closed on session mismatch, nested wrappers, and errors
- add unit tests for recovery, recognizer, authorizer, and lifecycle
- document the decision in ADR 0001
This commit is contained in:
2026-08-11 16:33:08 +08:00
parent c4d76ad284
commit 24153412c9
11 changed files with 1438 additions and 7 deletions
@@ -14,12 +14,13 @@
"peerDependencies": {
"@earendil-works/pi-ai": "*",
"@earendil-works/pi-coding-agent": "*",
"@gotgenes/pi-permission-system": ">=20.10.0"
"@gotgenes/pi-permission-system": ">=24.0.0"
},
"devDependencies": {
"@earendil-works/pi-ai": "*",
"@earendil-works/pi-coding-agent": "*",
"@gotgenes/pi-permission-system": ">=20.10.0",
"@gotgenes/pi-permission-system": ">=24.0.0",
"@types/node": "^26.0.0",
"typescript": "^5",
"vitest": "^3"
},