Found while working M10a (#233), listed there as out of scope.
docs/channels.md (Security note): "A function approvers fails closed when the process does not know the pending call (after a restart); use the list form or the default for approvals that must survive one."
mayApprove() (src/channels/channelSupport.ts) gives a function approvers the pending request through ctx.approval(id), which only knows this process's pauses (agent.approvals.list()). After a restart the function cannot be consulted, so the click is refused.
Possible direction: the approval store already holds the PendingApproval (and the snapshot); a read method on ApprovalStore (or on agent.approvals) that returns a pending record by id, without resolving it, would let ctx.approval(id) answer after a restart. That touches the ApprovalStore interface (every store implementation), so it may need an owner decision.
Found while working M10a (#233), listed there as out of scope.
docs/channels.md (Security note): "A function
approversfails closed when the process does not know the pending call (after a restart); use the list form or the default for approvals that must survive one."mayApprove()(src/channels/channelSupport.ts) gives a functionapproversthe pending request throughctx.approval(id), which only knows this process's pauses (agent.approvals.list()). After a restart the function cannot be consulted, so the click is refused.Possible direction: the approval store already holds the
PendingApproval(and the snapshot); a read method onApprovalStore(or onagent.approvals) that returns a pending record by id, without resolving it, would letctx.approval(id)answer after a restart. That touches theApprovalStoreinterface (every store implementation), so it may need an owner decision.