fix(security): keep the post-external-context approval gate on by default

Request authority admits whole tool families from the user's request, so a
request to read email also admits send_email, delete_email and bulk_email,
and agent processes inherit the host network. With the gate defaulting to
off, an instruction injected through an email or a fetched page reaches those
tools with no other check; dev refuses them today.

Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and
pin the production default with a test that imports the module in a fresh
interpreter. Four routing tests written for the opt-out posture now set it
explicitly.
This commit is contained in:
Léo
2026-10-06 19:49:15 +02:00
parent 8f0a28c05e
commit ee13ed1eee
8 changed files with 80 additions and 13 deletions
+3 -3
View File
@@ -101,9 +101,9 @@ SEARXNG_INSTANCE=http://localhost:8080
# Skip the external-context exact-approval pause for unattended local agents.
# Keep false for shared or internet-exposed deployments.
# Optional post-external-context tool approval gate. Off by default because it
# can block normal agent work; enable only for deployments that want this fence.
# ODYSSEUS_TOOL_APPROVAL_GATE=0
# Post-external-context tool approval gate. On by default; set to 0 only for
# trusted single-user setups that accept injected content reaching side-effect tools.
# ODYSSEUS_TOOL_APPROVAL_GATE=1
# Mark session cookies Secure. Left unset, this follows the request scheme:
# an HTTPS login gets a Secure cookie, a plain-HTTP one does not. Set true to