You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The CLI suggests taskless rule restore and rule rollback to every user and only learns the plan lacks them from the service's refusal. v2 whoami now returns each organization's entitlements, including restoreRules (taskless/taskless#254, live). So the CLI can stop suggesting what the plan won't serve.
Start after #422 and #423 have both merged. This touches rule revisions output (#422), and the whoami types, plan-check.ts and the rename notice (#423). Branching from main once both land avoids a three-way conflict in api-v2.schema.json / api-v2.d.ts.
Decided
Suggestions only, never a gate. The schema calls entitlements "a hint for the client, never a gate", and says a missing value means unknown, not refused. So rule restore and rule rollback keep calling the service and relay its refusal. That refusal is the better answer anyway, since it carries the exact git log / git restore commands and the upgrade link. Blocking locally would duplicate that message and could go stale.
Unknown is today's behavior.restoreRules is unknown when whoami fails, when entitlements is absent, or when no organization matched the repository and the CLI fell back to the token's claim. In all three cases, keep suggesting restore and rollback exactly as now.
Notes
No extra request. Every command that could suggest recovery already resolves the acting organization through GET /cli/api/v2/whoami (resolveOrgSubject in packages/cli/src/auth/org.ts, called by resolveIdentity). Carry that organization's restoreRules out of the same call, for example as an optional field on Identity.
Where suggestions change when restoreRules is false:
check's notice for unsafe or missing rules (packages/cli/src/rules/plan-check.ts, the rule restore <ruleId> suggestion) gives the git recovery steps for the rule's directory instead.
rule revisions still lists revisions, since the listing works on every plan. Its closing line says rolling back isn't included in the plan, instead of giving the rule rollback command.
The recover-rule agent recipe tells agents to check the plan before offering restore or rollback. This is a topic version bump.
Probably no --json change.integrity in check --json already tells an agent what's wrong. Add a field only if the proposal finds an agent needs one.
Shape: a single PR, with an OpenSpec change touching the cli-rule-recovery and cli-check specs.
The CLI suggests
taskless rule restoreandrule rollbackto every user and only learns the plan lacks them from the service's refusal. v2whoaminow returns each organization'sentitlements, includingrestoreRules(taskless/taskless#254, live). So the CLI can stop suggesting what the plan won't serve.Start after #422 and #423 have both merged. This touches
rule revisionsoutput (#422), and thewhoamitypes,plan-check.tsand the rename notice (#423). Branching frommainonce both land avoids a three-way conflict inapi-v2.schema.json/api-v2.d.ts.Decided
entitlements"a hint for the client, never a gate", and says a missing value means unknown, not refused. Sorule restoreandrule rollbackkeep calling the service and relay its refusal. That refusal is the better answer anyway, since it carries the exactgit log/git restorecommands and the upgrade link. Blocking locally would duplicate that message and could go stale.restoreRulesis unknown whenwhoamifails, whenentitlementsis absent, or when no organization matched the repository and the CLI fell back to the token's claim. In all three cases, keep suggesting restore and rollback exactly as now.Notes
GET /cli/api/v2/whoami(resolveOrgSubjectinpackages/cli/src/auth/org.ts, called byresolveIdentity). Carry that organization'srestoreRulesout of the same call, for example as an optional field onIdentity.restoreRulesisfalse:check's notice for unsafe or missing rules (packages/cli/src/rules/plan-check.ts, therule restore <ruleId>suggestion) gives the git recovery steps for the rule's directory instead.taskless rule restore <source>, changes the same way.rule revisionsstill lists revisions, since the listing works on every plan. Its closing line says rolling back isn't included in the plan, instead of giving therule rollbackcommand.recover-ruleagent recipe tells agents to check the plan before offering restore or rollback. This is a topic version bump.--jsonchange.integrityincheck --jsonalready tells an agent what's wrong. Add a field only if the proposal finds an agent needs one.cli-rule-recoveryandcli-checkspecs.Refs taskless/taskless#254