Skip to content

Feat/v0.0.5 beta access requests - #2

Merged
Brian-Mwangi-developer merged 2 commits into
mainfrom
feat/v0.0.5-beta-access-requests
Jun 13, 2026
Merged

Brian-Mwangi-developer merged 2 commits into
mainfrom
feat/v0.0.5-beta-access-requests

Conversation

@Brian-Mwangi-developer

@Brian-Mwangi-developer Brian-Mwangi-developer commented Jun 13, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added access request and approval system for denied capability calls, enabling out-of-band human authorization with configurable TTL and approval scopes (call, value, capability, global).
    • Introduced approval rules management with revocation capabilities and encrypted persistence.
    • Added audit logging for access request workflows.
  • Tests

    • Comprehensive test suite covering access request manager, approval store, and integration scenarios.
  • Chores

    • Updated .gitignore and .npmignore configurations.
    • Version bumped to 0.0.5-1.

Brian-Mwangi-developer and others added 2 commits June 12, 2026 19:47
Add suspend-and-resume access request flow: when an agent is denied by
constraints, the call blocks waiting for out-of-band human approval via
HMAC-signed verification codes the agent cannot forge.

- AccessRequestManager: HMAC-SHA256 code generation, pending request
  tracking, approve/deny/expire with rate limiting
- ApprovalStore: encrypted tamper-proof rule storage with HMAC integrity
  checks (rules wiped if store is tampered with)
- 4 approval scopes: call (one-time), value (session), capability
  (session), global (persistent across restarts)
- Context preservation: blocked calls suspend on a Promise closure
  holding capability, args, and targetFn — resumes exactly where
  it left off after approval
- Pluggable AccessRequestNotifier interface for email/SMS/push/webhook
- AppChain.approve()/deny()/getPendingRequests()/getApprovalRules()/
  revokeApproval() API surface
- 57 new tests covering manager, store, and full integration

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…execution

The call scope rule was not handled in getExpandedConstraints, so the
re-execution after approval hit the same constraint violation again.
Fix: treat call scope the same as value scope when expanding the in list.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 13, 2026 02:16
@coderabbitai

coderabbitai Bot commented Jun 13, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR adds a complete access request and approval workflow system to AgentChain, enabling agents to request out-of-band human approval for denied capability calls. The implementation includes HMAC-verified request codes, scoped approval rules, encrypted persistent storage with integrity checking, and seamless integration into the capability execution interception path.

Changes

Access Request and Approval Workflow

Layer / File(s) Summary
Type contracts and configuration
src/types/access-request.ts, src/types/audit.ts, src/types/chain.ts
New exported types for approval scopes, TTLs, request statuses, decisions, rules, and notifier interface; extended AuditResult and AuditEntry with access-workflow variants and metadata; added accessRequests config field to AppChainConfig.
AccessRequestManager
src/access/access-request-manager.ts
Manager creates HMAC-signed access requests with per-agent pending limits, verifies human-submitted codes using constant-time comparison, resolves/rejects suspended calls on approve/deny, sweeps expired requests every 30 seconds, and invokes notifier callbacks.
ApprovalStore
src/access/approval-store.ts
Encrypted in-memory cache backed by EncryptedStore for persisting approval rules; creates rules from approved decisions with TTL/expiration, finds matching rules by capability and scope (with call/value/capability/global semantics), merges expanded constraints across active rules, supports rule revocation, and validates integrity via HMAC on load.
AppChain integration
src/chain.ts
Conditionally initializes AccessRequestManager and ApprovalStore when config.accessRequests is present; exposes public approval/denial methods, pending request listing, approval rule querying, and revocation APIs; passes managers into wrap interception context; extends destroy() to clean up manager.
AppWrapper execution flow
src/app/app-wrapper.ts
Extracted auth/execution logic into executeWithAccessRequest; applies effective constraints (merging approval-store rule expansions); on requestable ChainAuthError codes, creates access request and suspends call, then on human approval creates rule and re-executes with optional call-scope revocation; re-invokes immediately if matching rule already exists.
Error codes and exports
src/errors/chain-error.ts, src/index.ts
Added access_request_pending, access_request_denied, and access_request_expired error codes; added barrel exports for AccessRequestManager, ApprovalStore, and access-request types.
Test suite
src/__tests__/access-requests.test.ts
Comprehensive tests for AccessRequestManager (request creation, verification codes, notifier callbacks, approve/deny paths, rate limiting, expiry); ApprovalStore (rule creation by scope, TTL handling, constraint expansion, revocation, encrypted integrity); AppChain integration (disabled/enabled behavior, scope-specific approval effects, denial/wrong-code handling, audit logging, revocation, cleanup).
Configuration and package
.gitignore, .npmignore, package.json
Updated ignore patterns (add OVERVIEW.md, expand to *.env*); version bump from 0.0.45 to 0.0.5-1; added access-requests.test.js to test script.

🎯 4 (Complex) | ⏱️ ~60 minutes

A rabbit hops through permissions bright,
When agents ask "may I?" in flight,
HMAC codes verify the plea,
Rules expand scope, and approvals decree—
Suspended calls wake when humans say "yes," the night! 🐰✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main feature addition: a beta implementation of access requests in version 0.0.5, which aligns with the substantial changeset introducing AccessRequestManager, ApprovalStore, and related access control workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/v0.0.5-beta-access-requests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Brian-Mwangi-developer
Brian-Mwangi-developer merged commit ef326bf into main Jun 13, 2026
2 of 3 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds an optional “access request” escalation flow to the AppChain runtime so that denied/constraint-violating agent calls can be suspended and later resumed after out-of-band human approval, with approvals stored as encrypted rules.

Changes:

  • Introduces access-request domain types plus AccessRequestManager (pending requests + HMAC verification codes) and ApprovalStore (encrypted approval rules with integrity tagging).
  • Integrates access-request suspension/resume and approval-rule constraint expansion into wrapApp() execution.
  • Exposes new APIs/exports on AppChain and adds a comprehensive test suite for the access-request system.

Reviewed changes

Copilot reviewed 12 out of 13 changed files in this pull request and generated 9 comments.

Show a summary per file
File Description
src/types/chain.ts Adds accessRequests config surface to enable the feature.
src/types/audit.ts Extends audit result/entry types for access-request-related outcomes/metadata.
src/types/access-request.ts Introduces access-request, decision, notifier, and approval-rule type definitions.
src/index.ts Exports the new access-request modules and types from the public entrypoint.
src/errors/chain-error.ts Adds new access_request_* error codes to ChainErrorCode.
src/chain.ts Wires access-request manager/store creation, lifecycle, and new AppChain APIs.
src/app/app-wrapper.ts Implements suspend/resume flow and constraint expansion during capability execution.
src/access/approval-store.ts New encrypted approval-rule store with integrity checking and rule querying.
src/access/access-request-manager.ts New access request lifecycle manager (create/approve/deny/expire) with HMAC codes.
src/tests/access-requests.test.ts Adds unit + integration tests for the access-request system.
package.json Updates package version and expands the test script to include new tests.
.npmignore Minor ignore-file formatting adjustment.
.gitignore Ignores OVERVIEW.md.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/app/app-wrapper.ts
Comment on lines +266 to 273
const fieldMatch = err.message.match(/field "([^"]+)"/);
const valueMatch = err.message.match(/field "[^"]+": "([^"]*)"/) ??
err.message.match(/field "[^"]+": (\S+)/);

return {
violatedField: fieldMatch?.[1],
violatedValue: valueMatch?.[1],
};
Comment thread src/app/app-wrapper.ts
Comment on lines +172 to +176
// Rule exists but constraint enforcement still failed —
// this shouldn't happen if getEffectiveConstraints worked.
// Re-execute with fresh auth token (the approval rule
// will take effect via getEffectiveConstraints).
return executeWithAccessRequest(capabilityName, callArgs, ctx, targetFn);
Comment on lines +119 to +131
/**
* Get the expanded constraints from all active rules for a capability.
* These get merged into the grant constraints before enforcement.
*/
/**
* Get the expanded constraints from all active rules for a capability.
* These get merged into the grant constraints before enforcement.
*
* Returns:
* - `null` → a capability/global rule bypasses ALL constraints
* - `undefined` → no matching rules found, no expansions (use original constraints)
* - `GrantConstraints` → merged expansions to apply on top of the grant constraints
*/
Comment on lines +269 to +275
if (inc.not_in) {
// Remove from not_in if we're approving it
merged.not_in = (merged.not_in ?? []).filter(
(v) => !inc.in?.includes(v)
);
if (merged.not_in.length === 0) delete merged.not_in;
}
Comment thread src/errors/chain-error.ts
Comment on lines +20 to +22
| "access_request_pending"
| "access_request_denied"
| "access_request_expired";
Comment thread package.json
{
"name": "agents-chain",
"version": "0.0.45",
"version": "0.0.5-1",
Comment thread src/app/app-wrapper.ts
Comment on lines +299 to +300
const existing = merged[field];
if (!existing) continue; // Don't add new constraints, only expand existing ones
Comment on lines +17 to +18
/** Verification codes are truncated to this many hex chars for human-friendliness. */
const CODE_LENGTH = 8;
Comment on lines +108 to +110
capability: params.capability,
args: params.args,
reason: params.reason,
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants