Add per-repository automatic file approvals - #23
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bot sessions run in isolated worktrees, so a request to access their primary checkout can trigger
external_directoryapproval even when it belongs to the same repository. Per-session approval replies also do not carry over to a later round. Add an opt-in repository policy that handles these file requests across sessions without changing global OpenCode permissions.autoApproveRepositoryFilesto project configuration and individual advanced repository entries. Interactiveinitasks whether to enable it (default no);--auto-approve-repository-filesenables it noninteractively. Existing configurations retain their behavior.askdecisions forexternal_directory,read, andeditin bot sessions and native subagents. Every resource must resolve inside the configured checkout or the assigned worktree, including worktrees stored outside the checkout. Check canonical paths and existing parents of new files; leave sibling paths, symlink escapes, and unknown patterns to ordinary approval.Validation:
npm run checkpassed (218 tests, lint, type checking, native TUI rendering, and build). Additional CLI and real Git worktree assertions passed with the focused setup/executor suite (21 tests); lint and type checking passed again after those test additions. All eight Mermaid diagrams parsed, 97 local documentation links passed, andgit diff --checkis clean.For an existing repository, add
"autoApproveRepositoryFiles": trueto its.opencode/automation.json, restart the idle service, and reactivate the owner. Already-pending questions still require their explicit reply. This branch has not been deployed to the test server and does not address the separate provider rejection oftools: [].