fix(runtime): enforce local control across Cookbook wrappers

This commit is contained in:
Alexandre Teixeira
2026-10-02 23:39:13 +01:00
parent bcc0e54e1b
commit 3834cd72b1
6 changed files with 68 additions and 10 deletions
+2
View File
@@ -260,6 +260,8 @@ def needs_owned_binding(operation):
"notes", "memory", "vault", "upload", "uploads", "attachments",
"shell", "model", "cookbook"}
segments = path.strip("/").split("/")
if len(segments) >= 3 and segments[:3] == ["api", "codex", "cookbook"]:
raise ResourceIdentityError("Cookbook wrappers require a dedicated resource-bound tool")
if len(segments) >= 2 and segments[0] == "api" and segments[1].casefold() in private:
raise ResourceIdentityError("Owned records require a dedicated resource-bound tool")
return False