Fix role binding filter when mapping is empty

should_apply_workspace_role_filter no longer requires at least one bound skill. With binding enabled and an empty map, the catalog shows only public workspace skills per role (matches prewarm and runtime). Update Admin copy and add regression test.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-05-11 16:07:34 +08:00
parent 091a5626e7
commit 4dbb834c95
3 changed files with 30 additions and 8 deletions

View file

@ -128,17 +128,15 @@ def _all_installed_skill_names(store: Any) -> set[str]:
def should_apply_workspace_role_filter(*, store: Any, skill_binding_role: str | None) -> bool:
"""When role binding is enabled, always filter the workspace skill catalog by role.
Empty binding maps still apply: each role then only sees ``public`` workspace skills
(see :func:`allowed_workspace_skill_names_for_role`), not the full install tree.
"""
if not str(skill_binding_role or "").strip():
return False
if not skill_role_binding_enabled(store=store):
return False
raw = load_skill_role_binding_dict(store)
normalized = normalize_skill_role_binding(
mapping_raw=raw,
valid_skill_names=_all_installed_skill_names(store),
)
if not mapping_has_any_skill_names(normalized):
return False
return True