Skip to content

feat: add skip-permissions option for claude sessions - #4

Draft
davidsprague-udisc wants to merge 2 commits into
tSquaredd:mainfrom
davidsprague-udisc:feat/skip-permissions
Draft

davidsprague-udisc wants to merge 2 commits into
tSquaredd:mainfrom
davidsprague-udisc:feat/skip-permissions

Conversation

@davidsprague-udisc

Copy link
Copy Markdown
Contributor

Summary

Adds an optional --dangerously-skip-permissions passthrough for Claude Code sessions launched by the dashboard. Opt-in per task: a new wizard step in the new-task flow and a resume-time prompt let the user choose, and both use a multi-option Select rather than a y/n Confirm so a single keystroke can't bypass the security-sensitive choice.

Key changes

  • New-task wizard gains a stepSkipPermissions step; selection is wired through LaunchConfig.SkipPermissions and added as --dangerously-skip-permissions in SpawnInTab.
  • Resume overlay prompts for the same choice before spawning a Claude tab on an existing task.
  • LaunchConfig documents that PlanMode and SkipPermissions are mutually exclusive; when both are set, PlanMode wins.

Review fixes folded in

  • Resume prompt stores taskName (string) instead of *TaskView — the tasks slice is replaced on every 5s refresh tick, so a pointer captured at prompt-open time goes stale.
  • executeResume re-resolves the task by name and re-checks HasSession before spawning; if a session appeared while the prompt was open, it attaches instead of duplicating.
  • Extracted advanceResumePrompt helper so the two form-completion sites (Update fall-through and handleKey) can't drift.
  • WindowSizeMsg now mirrors width/height into the resume prompt (parity with the new-task overlay).
  • Warp terminal: polls frontmost of process "Warp" instead of blind delay calls so keystrokes can't leak to the wrong app under load. Captures osascript output and translates macOS error -1719 into a targeted "enable Accessibility permission" message.

Notes

  • The skip-permissions prompt uses huh.NewSelect[bool] rather than huh.NewConfirm specifically to prevent y/n hotkey bypass on the security-sensitive prompt. The user must move the cursor and press enter.
  • Also lands the design docs for this feature and the already-merged Warp terminal support under docs/brainstorms/ and docs/plans/.

Adds an optional `--dangerously-skip-permissions` passthrough for
Claude Code sessions launched by the dashboard. The option is opt-in
per task: a new wizard step in the new-task flow and a resume-time
prompt both use a multi-option Select (rather than a y/n Confirm) so a
single keystroke can't bypass the security-sensitive choice.

Also includes:
- Stale-pointer fix on the resume prompt: the overlay now stores the
  task name instead of a *TaskView, and re-resolves at execute time.
  Re-checks HasSession before spawning so a session started while the
  prompt is open attaches instead of duplicating.
- Shared helper for the resume overlay's form-completion handling so
  the two call sites can't drift.
- Window-resize propagation for the resume overlay (mirrors the
  existing new-task overlay behavior).
- Warp terminal: poll `frontmost of process "Warp"` instead of using
  blind `delay` calls so keystrokes can't leak to the wrong app under
  load; capture osascript output and translate error -1719 into a
  targeted Accessibility-permission message.
- LaunchConfig: document that PlanMode and SkipPermissions are
  mutually exclusive and prefer PlanMode (the safer option) if both
  are set.

Also lands the skip-permissions and warp-terminal design docs under
docs/brainstorms and docs/plans.
These design docs are kept local-only and shouldn't have been
committed. Add docs/ to .gitignore so they stay out of future PRs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant