Repository navigation
Retire the flow-authoring gate; agent-permissions owns it (1.5.2) - #53
Merged
Merged
Conversation
…1.5.2) flow_create / flow_edit / flow_publish / flow_delete are gated by @clawnify/agent-permissions 0.6.0, the one permission authority on the box. This plugin's own gate for them was registered through registerHook, which OpenClaw 2026.9.1 no longer dispatches for before_tool_call, so it prompted on 2026.7.1 and silently did not on 2026.9.1; and with both gates live a 2026.7.1 box prompted twice per write. Only the flow_run gate stays: it is the operator's opt-in, skippable for unattended sessions. approval.gateMutations is accepted and ignored so existing configs still validate.
Main's 1.6.0 extended the same registerHook gate to flow_trigger's mutating actions. That coverage moves to @clawnify/agent-permissions 0.6.0 with the authoring tools, so this plugin gates flow_run only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
flow_create/flow_edit/flow_publish/flow_deleteare now gated by@clawnify/agent-permissions0.6.0 (always-ask, companion PR in that repo). This plugin's own gate for them was registered throughregisterHook, which OpenClaw 2026.9.1 no longer dispatches forbefore_tool_call: it prompted on 2026.7.1 and silently did not on 2026.9.1, and with both gates live a 2026.7.1 box prompted twice per write.Only the
flow_rungate stays (operator opt-in, skippable for unattended sessions).approval.gateMutationsis accepted and ignored so existing configs still validate.Tests updated: authoring tools are asserted un-gated here under every config; flow_run and read-only behaviour unchanged. 171 tests pass; build clean;
MUTATION_VERBSis gone from the bundle.Fleet: boxes pull
mainand build (docs/internal/fleet-update.md, "Updating ClawFlow Plugin"); roll after the authority is installed on the box, one drained restart for both.