Repository navigation
Make agent approval cards readable at a glance - #175
Merged
Merged
Conversation
Titles name the object (credential, value or groups) and the requester. Read cards show the full command, what it receives and the unverified purpose; write cards use fixed sections with a change summary, status tags, plain-language item rows and a value box only for new or replaced values; organize steps read as sentences with no-change and merge tags. The card body scrolls under a 680-point cap with a persistent scroll bar and an overflow line, so actions and the footer always stay visible. Buttons and the footer state each decision's consequence, the pending list uses the same object-naming verbs, and the catalog carries English and Simplified Chinese copy. Display and copy only: the Broker, Vault, approval digests and summaries are unchanged.
At the 680-point cap the panel's top sits under the menu bar and the footer slid behind the Dock on the 768-point CI screen. A 640-point cap keeps the footer visible while staying within the 680-point limit.
|
Second review, from an image-only re-review of 16 cards (English and Simplified Chinese) rendered from
Scope extension for item 1: |
Give each component of the App-side write summary a vault-keyed value digest, computed when the write is frozen. The approval digest, retransmission, consumption and commit are unchanged, and the digest never appears in a Broker response. Modify cards now tag every item as Unchanged, Replaced, New, Changed or Removed and list only new or replaced values. Instruction edits are highlighted word by word with a Removed line. Values merge into the items section, consequences sit under the primary button, overflow lines name the hidden sections, and read cards shrink their icon before scrolling, so short create cards fit without scrolling. Read rows no longer repeat the credential name, and the summary, timed-scope, overwrite, footer, bin and merge copy follow the second review.
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #173
Closes #174
Summary
Approval cards name the requester and the object in the title, show what will happen in fixed, plain-language sections, and state each button's consequence. Read cards show the full command (scrolling after 4 lines), a heading with the item count and arrow rows for what the command receives, the unverified purpose, and the scope of the timed allowance. Write cards show the purpose, a change summary that names what changes, item rows with exact status tags and masked values, the instructions with a word-level diff, and the group; create and delete state their consequence under the primary button. Organize steps read as sentences, with No change and Merge tags and hidden counts. The card body scrolls under a 640-point cap with a persistent scroll bar and an overflow line that names the hidden sections, so the actions and footer stay visible. The pending list uses the same verbs.
For #174, the App-side write summary carries one vault-keyed value digest per component, so a modify card tags each item exactly. This is
risk:security: approval digests, retransmission, consumption, commit and every Broker response are unchanged (see Item 1 below).Diff stat
git diff --stat origin/main: 27 files changed, 3163 insertions(+), 1733 deletions(-)Sources/AskKeyAppKit/App+Views/Credentials/PendingRequestPresentation.swift: 12 files, +1385 / −423 (helpers next to the cards:ApprovalCopy.swift,ApprovalScrollArea.swift,ApprovalCardComponents.swift,ApprovalTextDiff.swift; largest card file 264 lines)Localizable.xcstrings: +801 / −787Sources/AskKeyBroker/CredentialComponents.swift,Sources/AskKeyVault/Vault+AgentWriteFreeze.swift: 2 files, +22 / −2 (Show which components change in a modify approval #174)Tests: 12 files, +955 / −521Second review (
41ecea4..9670fa8): 22 files changed, 1092 insertions(+), 573 deletions(-).Second review changes (
9670fa8)risk:security).BrokerCredentialComponentSummarygainsvalueDigest: String?, documented as App-side only.Vault+AgentWriteFreeze.swiftcomponentSummaryfills it with HMAC-SHA256 over a length-prefixed encoding of the component value (text, or filename plus bytes). The HMAC key is derived from the vault key with HKDF, using infoAskKey approval component value digest v1. Without the vault key a digest cannot confirm a guessed value, and it is stable across freezes. The summary type is notCodableand is returned only byfrozenAgentWriteSummaryto the App. The approval digest still hashes the aggregatebeforeDigest/afterDigest, instructions, group andcreatesGroup; nothing in retransmission, consumption or commit reads the new field. Cards tag items as Unchanged, Replaced, New, Changed (delivery or masking only, same value) or Removed; May be replaced is gone, and only new or replaced values are listed. A summary without digests falls back to Replaced, never Unchanged.→ 环境变量 X/→ Environment variable Xand→ 临时文件(路径在 X,最多 5 分钟后删除).Tests
Head
9670fa8, base425e29e. Task build directory, deleted after use.swift build: Build complete.swift test --filter "AgentWriteComponentDigestTests|AgentCredentialMetadataWriteTests|AgentTextWriteCreationTests|AgentTextWriteApprovalLifecycleTests|AgentTextWriteConcurrencyTests|AgentTextWriteBrokerSocketTests": 26 passed, 0 failed (digest 2, metadata 12, lifecycle 6, creation 4, socket 1, concurrency 1). InAgentWriteComponentDigestTests, one same-length component of a three-item bundle is rotated: only its digest changes, and the others' digests and all sizes and deliveries are equal. The digests are keyed (not the plain SHA-256 of the value), stable across freezes, unaffected by a delivery change, and absent from the encoded Broker reply.ApprovalPromptContentTests|FrozenWriteSummaryContentTests|OrganizationApprovalContentTests|ApprovalCardLayoutTests|WorkspaceInteractionTests|LocalizationUnificationTests|ScreenPresentationTests|Batch4SettingsLanguageTests|LocalizationRemediationTests|WorkspacePrototypeContractTests|AppLanguageCatalogTests): 78 passed, 0 failed.FrozenWriteSummaryContentTests.testVaultRotationOfOneSameLengthItemShowsReplacedAndUnchangedbuilds the summary with a real Vault and asserts Unchanged for USER and Replaced for TOKEN, with only TOKEN listed.ApprovalCardLayoutTests.testShortCreateCardsFitWithoutScrollingcovers cards 06/07 in both languages.swift test --filter AskKeyAppTests: 371 passed, 0 failed, 0 skipped (main: 368 test methods in this target).Tests/AskKeyE2ETests/*.swift: type-checked withswiftc -typecheck(exit 0). Not run locally per AGENTS.md.9670fa8, run 37881786563:swift testran 1097 tests, 3 skipped, 0 failures; main425e29ehas 1092, 3 skipped. Automation: 183 ran. Hygiene and module checks passed.ScreenshotE2ETests) passed 5, failed 0, skipped 0, and exported 17 screenshots.→ Environment variablerow, the new timed scope, the cancelled note without delivery wording, and the "Authenticate and Allow Once" retry.Checks
python3 scripts/check_hygiene.py: Hygiene rules passed: size=0, test-support=0, debug=0, local-path=0, non-ascii-name=0, multica=0, cjk=0.python3 scripts/check_module_deps.py: Module dependency check passed.Deviations and questions
AppDelegate+Approval.swiftis untouched.LocalizationUnificationTests. These areQuoted name: %@,Sentence separator,New group tag,Credential value: %@(the value of %@ / %@的值),Removed phrases: %@(Removed: %@) andChange summary: instructions(instructions for agents).docs/adr/0010-agent-credential-metadata-writes.mdstill names the old Approve Organization button. Docs are outside this Scope.xcodebuildtests were running (three concurrent). Every later build waited until at most one other was running.