Repository navigation
fix(server): Claude Auto mode asks before commands it escalates - #15360
Open
TonybynMp4 wants to merge 1 commit into
Open
TonybynMp4 wants to merge 1 commit into
TonybynMp4 wants to merge 1 commit into
Conversation
TonybynMp4
force-pushed
the
investigate/permission-prompts-bypass
branch
from
October 3, 2026 22:12
cacb784 to
54ab8f1
Compare
TonybynMp4
force-pushed
the
investigate/permission-prompts-bypass
branch
from
October 7, 2026 12:47
54ab8f1 to
fe465bb
Compare
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
TonybynMp4
force-pushed
the
investigate/permission-prompts-bypass
branch
from
October 9, 2026 20:00
fe465bb to
a472a56
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #15353.
On orchestrator v2, a Claude thread in Auto never asks about anything. Commands that Claude escalates for a human decision, such as a
git pushmatching a userpermissions.askrule, run without a prompt, the same as Full access. The permission modes guide says Auto approves routine actions "and asks about others".Cause
In
automode, Claude approves routine actions with its classifier and sends the rest (ask-rule matches, protected paths, classifier escalations) to the SDKcanUseToolcallback. The adapter's callback answersallowwheneverrequiresClaudeApprovalis false, andinstallPermissionCallbackwas true only for Supervised and Auto-accept edits. So every escalation in Auto was approved without raising a request. The V1 adapter asked in every mode except Full access. #13786 fixed the same gap for Auto-accept edits.Fix
The callback now asks in every mode except Full access. Auto still lets Claude's classifier approve routine actions before the callback runs, so only escalations reach the user. Full access and explicit
approvalPolicyoverrides are unchanged.Verification
vp test run apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts: 132 passed.git push, and accepting it allows the command.apps/servertypecheck passes.Fixed with Claude Opus 5.5 in Claude Code, run through T3 Code.
🤖 Generated with Claude Code