Add sidebar run permission preset for scheduled jobs.

Default inherits Host new-session access mode; humans can raise to workspace-write or full access. Agents never see or set the field.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-10 22:08:39 +08:00
parent ad6e90f197
commit 8cf624ce7f
8 changed files with 140 additions and 4 deletions

View file

@ -434,6 +434,12 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
agentAccessAllow: '允许 Agent 用工具管理(默认)',
agentAccessDeny: '仅人工(禁止 Agent 暂停/恢复/重触发/删除)',
agentAccessHint: '仅侧栏可改;Agent 看不到此开关。默认保持现状(允许)。关掉后 Agent 仍可查询进度,但无法改任务。',
permissionPreset: '操作权限',
permissionPresetDefault: '跟随 Host 默认(当前行为)',
permissionPresetReadOnly: '仅可查看',
permissionPresetWorkspaceWrite: '可写入工作区',
permissionPresetFullAccess: '完全权限',
permissionPresetHint: '仅侧栏可改。默认不指定,触发时沿用 Host「新会话」默认权限;可手工提权到可写/完全权限。Agent 不可见也不可改。',
loginRequired: '登录后才能使用定时任务',
runNoSession: '这次运行没有可打开的会话',
runOpenFailed: '打不开这次对话,会话可能已被删除',
@ -506,6 +512,12 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
agentAccessAllow: 'Allow agents to manage via tools (default)',
agentAccessDeny: 'Human only (block agent pause/resume/retrigger/delete)',
agentAccessHint: 'Sidebar only; agents never see this toggle. Default keeps current behavior (allow). When denied, agents can still query progress but cannot mutate the job.',
permissionPreset: 'Run permission',
permissionPresetDefault: 'Host default (current behavior)',
permissionPresetReadOnly: 'Read only',
permissionPresetWorkspaceWrite: 'Workspace write',
permissionPresetFullAccess: 'Full access',
permissionPresetHint: 'Sidebar only. Leave default to inherit the Host new-session permission preset; raise manually to workspace write or full access. Agents cannot see or change this.',
loginRequired: 'Sign in to use scheduled tasks',
runNoSession: 'This run has no session to open',
runOpenFailed: 'Could not open this chat; the session may have been deleted',
@ -764,6 +776,7 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
imTargetId: '',
mirrorToSession: false,
agentAccess: 'allow',
permissionPreset: '',
labelsText: '',
persistKind: 'retain',
archiveEndpoint: '',
@ -791,6 +804,7 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
imTargetId: job.delivery?.targetId || '',
mirrorToSession: job.mirrorToSession === true,
agentAccess: job.agentAccess === 'deny' ? 'deny' : 'allow',
permissionPreset: job.permissionPreset || '',
labelsText: formatLabelsText(job.labels),
persistKind: persistHistoryKind(job),
archiveEndpoint: job.persistHistory?.kind === 'archive' ? (job.persistHistory.endpoint || '') : '',
@ -1441,6 +1455,18 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
),
),
h('span', { className: 'dsh-ct-cwdHint' }, t('agentAccessHint')),
h('label', null, t('permissionPreset'),
h('select', {
value: form.permissionPreset || '',
onChange: (e) => setForm({ ...form, permissionPreset: e.target.value }),
},
h('option', { value: '' }, t('permissionPresetDefault')),
h('option', { value: 'read-only' }, t('permissionPresetReadOnly')),
h('option', { value: 'workspace-write' }, t('permissionPresetWorkspaceWrite')),
h('option', { value: 'danger-full-access' }, t('permissionPresetFullAccess')),
),
),
h('span', { className: 'dsh-ct-cwdHint' }, t('permissionPresetHint')),
h('label', { className: 'dsh-ct-check' },
h('input', {
type: 'checkbox',
@ -1710,6 +1736,7 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
: { kind: 'dsh' },
mirrorToSession: form.mirrorToSession === true,
agentAccess: form.agentAccess === 'deny' ? 'deny' : 'allow',
permissionPreset: form.permissionPreset || '',
labels: parseLabelsText(form.labelsText),
persistHistory: form.persistKind === 'forever'
? { kind: 'forever' }