Skip to content

Channels: function-form approvers fail closed after a restart #280

Description

@LinuxDevil

Found while working M10a (#233), listed there as out of scope.

docs/channels.md (Security note): "A function approvers fails closed when the process does not know the pending call (after a restart); use the list form or the default for approvals that must survive one."

mayApprove() (src/channels/channelSupport.ts) gives a function approvers the pending request through ctx.approval(id), which only knows this process's pauses (agent.approvals.list()). After a restart the function cannot be consulted, so the click is refused.

Possible direction: the approval store already holds the PendingApproval (and the snapshot); a read method on ApprovalStore (or on agent.approvals) that returns a pending record by id, without resolving it, would let ctx.approval(id) answer after a restart. That touches the ApprovalStore interface (every store implementation), so it may need an owner decision.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions