Add repository OpenCode permission defaults (#25326)

* test(config): reproduce rejected repository OpenCode config

* Add repository OpenCode permissions and allow its reviewed root config

* fix: preserve sensitive OpenCode confirmation prompts

---------

Co-authored-by: Orca campaign recovery <campaign-recovery@example.invalid>
Co-authored-by: Orca OpenCode Campaign <opencode-campaign@local.invalid>
This commit is contained in:
Neil
2026-10-04 19:34:47 -07:00
committed by GitHub
co-authored by Orca campaign recovery Orca OpenCode Campaign
parent 46c3c3b44d
commit 822fc5bed4
3 changed files with 30 additions and 3 deletions
@@ -13,9 +13,8 @@ function readRootEntries(sha) {
return stdout.split('\0').filter(Boolean)
}
// Why: the Cloud workspace import is the one reviewed root addition; it stays
// listed until it lands on main, after which the base tree carries it.
const REVIEWED_ROOT_ENTRIES = new Set(['cloud'])
// These reviewed additions stay listed until the base tree carries them.
const REVIEWED_ROOT_ENTRIES = new Set(['cloud', 'opencode.json'])
function checkRootDirectoryEntries(argv) {
if (argv.length !== 2) {
@@ -114,6 +114,17 @@ describe('root directory guard', () => {
expect(result.status).toBe(0)
})
it('allows the reviewed repository OpenCode permission config', () => {
const fixture = makeFixture()
const head = commitFiles(fixture.root, [
['opencode.json', '{"permission":{"*":{"*":"allow"}}}\n']
])
const result = runGuard({ ...fixture, head })
expect(result.status).toBe(0)
})
it('rejects a new top-level directory', () => {
const fixture = makeFixture()
const head = commitFiles(fixture.root, [['new-folder/file.txt', 'too prominent\n']])
+17
View File
@@ -0,0 +1,17 @@
{
"$schema": "https://opencode.ai/config.json",
"permission": {
"*": {
"*": "allow"
},
"read": {
"*.env": "ask",
"*.env.*": "ask",
"*.env.example": "allow"
},
"external_directory": {
"*": "ask"
},
"doom_loop": "ask"
}
}