feat(runtime): bind browser resources to authority

This commit is contained in:
Alexandre Teixeira
2026-10-02 18:54:09 +01:00
parent b648f9ddbe
commit e175bea752
27 changed files with 2120 additions and 3153 deletions
+13
View File
@@ -32,6 +32,7 @@ if TYPE_CHECKING:
from src.agent_runtime.remote_resources import BoundBackendOperation
from src.agent_runtime.owned_resources import BoundOwnedOperation
from src.agent_runtime.process_resources import BoundProcessOperation
from src.browser_identity import BoundBrowserOperation
DEFAULT_APPROVAL_TTL_SECONDS = 10 * 60
@@ -129,6 +130,7 @@ def _binding_payload(
backend_operation=None,
owned_operation=None,
process_operation=None,
browser_operation=None,
) -> dict[str, Any]:
return {
"owner": _normalized_owner(owner),
@@ -154,6 +156,7 @@ def _binding_payload(
"backend_operation": backend_operation.to_dict() if backend_operation is not None else None,
"owned_operation": owned_operation.to_dict() if owned_operation is not None else None,
"process_operation": process_operation.to_dict() if process_operation is not None else None,
"browser_operation": browser_operation.to_dict() if browser_operation is not None else None,
}
@@ -188,6 +191,7 @@ class PendingToolApproval:
backend_operation: BoundBackendOperation | None = None
owned_operation: BoundOwnedOperation | None = None
process_operation: BoundProcessOperation | None = None
browser_operation: BoundBrowserOperation | None = None
def public_payload(self, *, reason: str | None = None) -> dict[str, Any]:
return {
@@ -301,6 +305,7 @@ class ExactToolApproval:
backend_operation=self.pending.backend_operation,
owned_operation=self.pending.owned_operation,
process_operation=self.pending.process_operation,
browser_operation=self.pending.browser_operation,
)
return _canonical_digest(expected) == self.pending.digest
@@ -397,6 +402,7 @@ class ToolApprovalStore:
backend_operation = None
owned_operation = None
process_operation = None
browser_operation = None
from src.agent_runtime.remote_resources import BoundBackendOperation, resolve_backend
from src.agent_runtime.owned_resources import needs_owned_binding, resolve_owned_operation
from src.agent_runtime.resources import NativeBackendResource
@@ -412,6 +418,11 @@ class ToolApprovalStore:
from src.agent_runtime.process_resources import needs_process_binding, resolve_process_operation
if request_authority is not None and needs_process_binding(operation, backend):
process_operation = resolve_process_operation(request_authority, operation, backend)
from src.browser_identity import native_browser, resolve_browser_operation
if native_browser(operation, backend):
if request_authority is None:
raise ValueError("Browser approval requires originating resource authority")
browser_operation = resolve_browser_operation(request_authority, operation)
if isinstance(backend, NativeBackendResource) and needs_owned_binding(operation):
resolved_owned = resolve_owned_operation(operation, owner=_normalized_owner(owner),
thread_id=str(session_id or ""), request_id=backend_operation.request_id,
@@ -460,6 +471,7 @@ class ToolApprovalStore:
backend_operation=backend_operation,
owned_operation=owned_operation,
process_operation=process_operation,
browser_operation=browser_operation,
)
pending = PendingToolApproval(
approval_id=secrets.token_urlsafe(32),
@@ -488,6 +500,7 @@ class ToolApprovalStore:
backend_operation=backend_operation,
owned_operation=owned_operation,
process_operation=process_operation,
browser_operation=browser_operation,
)
with self._lock:
self._purge_expired_locked(now)