Problem
T3 currently exposes Supervised, Auto-accept edits, and Full access for Pi, but interactive pi-acp sessions execute Pi tools locally without sending session/request_permission first. The restricted modes therefore do not yet enforce the behavior promised by the composer.
Cursor review: #3 (comment)
Adapter-side prerequisite: IanWorley/pi-acp#1
Background title, branch, commit, and PR generation was separately made tool-free in 04f8aa6. This issue covers interactive sessions only.
Acceptance criteria
- Supervised requests approval before execute and edit operations.
- Auto-accept edits approves edit/write operations while still requesting approval for bash/execute operations.
- Full access automatically selects an allow outcome.
- Denied and cancelled requests block the Pi tool before any side effect.
- Runtime-mode changes cannot leave an existing Pi session on stale permissions.
- The UI does not advertise a restricted Pi mode until it is actually enforced.
- Focused adapter tests cover each runtime mode and approval outcome.
- An end-to-end test proves a denied Pi write or bash call produces no side effect.
Problem
T3 currently exposes Supervised, Auto-accept edits, and Full access for Pi, but interactive
pi-acpsessions execute Pi tools locally without sendingsession/request_permissionfirst. The restricted modes therefore do not yet enforce the behavior promised by the composer.Cursor review: #3 (comment)
Adapter-side prerequisite: IanWorley/pi-acp#1
Background title, branch, commit, and PR generation was separately made tool-free in 04f8aa6. This issue covers interactive sessions only.
Acceptance criteria