Skip to content

fix(server): Claude Auto mode asks before commands it escalates - #15360

Open
TonybynMp4 wants to merge 1 commit into
pingdotgg:mainfrom
TonybynMp4:investigate/permission-prompts-bypass
Open

TonybynMp4 wants to merge 1 commit into
pingdotgg:mainfrom
TonybynMp4:investigate/permission-prompts-bypass

Conversation

@TonybynMp4

Copy link
Copy Markdown
Contributor

Fixes #15353.

On orchestrator v2, a Claude thread in Auto never asks about anything. Commands that Claude escalates for a human decision, such as a git push matching a user permissions.ask rule, run without a prompt, the same as Full access. The permission modes guide says Auto approves routine actions "and asks about others".

Cause

In auto mode, Claude approves routine actions with its classifier and sends the rest (ask-rule matches, protected paths, classifier escalations) to the SDK canUseTool callback. The adapter's callback answers allow whenever requiresClaudeApproval is false, and installPermissionCallback was true only for Supervised and Auto-accept edits. So every escalation in Auto was approved without raising a request. The V1 adapter asked in every mode except Full access. #13786 fixed the same gap for Auto-accept edits.

Fix

The callback now asks in every mode except Full access. Auto still lets Claude's classifier approve routine actions before the callback runs, so only escalations reach the user. Full access and explicit approvalPolicy overrides are unchanged.

Verification

  • vp test run apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts: 132 passed.
  • New tests drive the real callback through a stubbed query runner:
    • Auto raises a command request for an escalated git push, and accepting it allows the command.
    • Auto denies the command when the request is declined.
    • Full access allows the command without raising a request.
    • Auto-accept edits still asks before a command (existing test, moved to a shared helper).
  • The Auto policy test now expects the callback to ask.
  • With the source change reverted, the three Auto tests fail.
  • apps/server typecheck passes.

Fixed with Claude Opus 5.5 in Claude Code, run through T3 Code.

🤖 Generated with Claude Code

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 3, 2026
@TonybynMp4
TonybynMp4 force-pushed the investigate/permission-prompts-bypass branch from cacb784 to 54ab8f1 Compare October 3, 2026 22:12
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d31817d1-3cd5-4289-b901-83c85ee47d5b

📥 Commits

Reviewing files that changed from the base of the PR and between fe465bb and a472a56.


📒 Files selected for processing (2)
  • apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts
  • apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.



📝 Walkthrough

Walkthrough

When no explicit approval policy is set, the Claude adapter now installs a permission callback for all runtime modes except Full access. Tests cover command approval requests and allow or deny outcomes across Auto-accept edits, Auto, and Full access.

Changes

Claude Permission Handling

Layer / File(s) Summary
Runtime permission callback and approval tests
apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.ts, apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts
The adapter installs the callback for runtime modes other than Full access when no explicit approval policy is set. Tests verify approval requests, user acceptance or decline, and Full access behavior.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge


Merge Risk

Merge Risk: ⚪ Minimal · up to a472a

No actionable issue is established before merge. The tests cover approval after an escalation reaches the callback, though they do not verify SDK routing of a configured ask rule.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a472a

Auto-mode escalations now wait for approval rather than being allowed immediately. No new privilege expansion was established. Remaining uncertainty concerns actual escalation delivery and approval cleanup during interruption or restart.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed gate applies to ordinary escalated tool requests in Auto threads using this adapter, not just the git push example. The PR adds a decision requirement within existing tool authority; the production diff does not add credentials, privileged sinks, or cross-service access. Maximum deployment and tenant exposure was not established.

Trust Boundaries and Controls

  • observed — The normal response route looks up the request by thread and request identity and rejects a request no longer pending. Delivery additionally requires a live response capability matching the designated provider session. The adapter resolves only the matching live pending request.
  • observed — Existing launch arguments can override the policy-derived SDK permission mode, including selecting bypassPermissions. That precedence predates this PR. Its interaction with SDK callback dispatch remains unverified and is not treated as a newly introduced bypass.

Resilience and Maintainability Implications

  • observed — An aborted approval signal yields cancellation and therefore denial with interruption. Orchestrator interruption settlement can mark the run's pending requests cancelled and not resumable, including when its provider session is dead. These controls support failure containment, although universal query-close signal propagation and restart cleanup remain unproven.



Pre-merge checks | Passed 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Issue #15353 requires Claude Auto to ask for approval when Claude escalates an action, including an ask-rule command. ClaudeAdapterV2.ts now installs the permission callback for Auto and every mode …
Out of Scope Changes check Passed The reviewed change summary contains only the permission-policy change in ClaudeAdapterV2.ts and supporting tests in ClaudeAdapterV2.test.ts. The tests directly verify the linked issue behavior an…
Title check Passed The title clearly identifies the server-side fix: Claude Auto mode now asks before commands that require escalation.
Description check Passed The description explains the problem, cause, fix, linked issue, affected modes, and focused verification results. It does not use the exact “Scope and approval” heading, but it provides the relevant i…


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR


  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@TonybynMp4
TonybynMp4 force-pushed the investigate/permission-prompts-bypass branch from 54ab8f1 to fe465bb Compare October 7, 2026 12:47
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@TonybynMp4
TonybynMp4 force-pushed the investigate/permission-prompts-bypass branch from fe465bb to a472a56 Compare October 9, 2026 20:00

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Claude Auto mode on orchestrator v2 runs ask-rule commands without prompting

1 participant