mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-09 08:22:19 +02:00
fix(security): keep the post-external-context approval gate on by default
Request authority admits whole tool families from the user's request, so a request to read email also admits send_email, delete_email and bulk_email, and agent processes inherit the host network. With the gate defaulting to off, an instruction injected through an email or a fetched page reaches those tools with no other check; dev refuses them today. Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and pin the production default with a test that imports the module in a fresh interpreter. Four routing tests written for the opt-out posture now set it explicitly.
This commit is contained in:
@@ -1109,6 +1109,9 @@ def test_tui_local_workspace_turn_hides_backend_file_tools(monkeypatch):
|
||||
|
||||
|
||||
def test_native_host_shell_call_runs_through_bridge_and_threads_result(monkeypatch):
|
||||
# Routing test written for the opt-out posture; the gate default is pinned in
|
||||
# tests/test_tool_approval_gate_default.py.
|
||||
monkeypatch.setattr("src.tool_capabilities.TOOL_APPROVAL_GATE_ENABLED", False)
|
||||
monkeypatch.setattr(al, "get_setting", lambda key, default=None: default, raising=False)
|
||||
monkeypatch.setattr(al, "get_mcp_manager", lambda: None, raising=False)
|
||||
monkeypatch.setattr(al, "estimate_tokens", lambda *args, **kwargs: 10, raising=False)
|
||||
|
||||
Reference in New Issue
Block a user