Skip to content

[REQ-112][CODE] 阻止插件入口绕过云审批并返回可恢复状态 #5

Description

@jinjunnn

Parent requirement

REQ-112:https://github.com/jinjunnn/alpha-work/issues/15

Outcome

插件入口遇到需审批的云动作时返回稳定 approval-required 状态/链接,绝不将其当成功、重试或旁路执行。

Covers

  • REQ-112 AC1、AC3–AC7 的插件入口。

Owning boundary

插件只适配平台契约,不持久化审批 grant,也不自行 resume Workflow。

Out of scope

  • 不在插件进程保管云凭据。

Exit criteria

  • 所有插件云入口消费同一 approval/status contract。
  • 审批前无副作用;批准、拒绝、过期和取消可恢复展示。
  • 与现有 purpose-bound credentials、job idempotency 和 consent 契约兼容。

Dependencies

  • 112-platform(使用 GitHub 原生 blocked-by 维护)
  • PLUGIN1(使用 GitHub 原生 blocked-by 维护)
  • PLUGIN2(使用 GitHub 原生 blocked-by 维护)
  • PLUGIN3(使用 GitHub 原生 blocked-by 维护)

Verification evidence

  • 附确定性测试或适合本能力的部署态/安全证据。
  • 记录未覆盖项、失败语义和剩余风险。
  • PR 只使用 Fixes 关闭本子 Issue,不直接关闭父需求。

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:contractsContracts, schemas, or compatibilityarea:integrationRepository, API, or external integrationarea:runtimeServices, jobs, infrastructure, or operationsarea:securitySecurity or access controltype:featureNew user or system capability

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions