Block release-class tasks from automatic triage dispatch unless they come from a user-authored source with explicit authorization. - Add release intent classification and authorization-marker enforcement before final triage transitions. - Record activity/log details when release tasks are parked awaiting manual approval. - Surface the new release-authorization activity in dashboard activity views. - Cover release gating behavior with engine tests and document the architecture pattern. - Add a changeset for the published CLI package. Files changed: .changeset/fn-6481-release-triage-authorization.md | 5 + .../release-triage-requires-user-authorization.md | 33 +++++ packages/core/src/types.ts | 2 + packages/core/vitest.config.ts | 4 + packages/dashboard/app/components/ActivityFeed.tsx | 5 + .../dashboard/app/components/ActivityLogModal.tsx | 6 + .../__tests__/triage-release-authorization.test.ts | 158 +++++++++++++++++++++ .../engine/src/triage-release-authorization.ts | 100 +++++++++++++ packages/engine/src/triage.ts | 51 +++++++ scripts/lib/test-quarantine.json | 8 +- 10 files changed, 371 insertions(+), 1 deletion(-) Fusion-Task-Id: FN-6481 Fusion-Task-Lineage: 0bddb77a-87e5-4fa5-b31a-e773bdae7a29
1.8 KiB
category, module, tags, problem_type, applies_when
| category | module | tags | problem_type | applies_when | |||||
|---|---|---|---|---|---|---|---|---|---|
| architecture | engine |
|
security |
|
Release-class triage requires explicit user authorization
Problem
Autonomous agents can draft tasks that mention release mechanics such as pnpm release --yes, scripts/release.mjs, changeset publish, npm publish, semver tags, or release-version commits. Without a triage boundary, an agent-authored release task can be dispatched to execution and reach publish-class commands without a user intentionally authorizing the release.
Solution
Release authorization is enforced as a pure triage gate before finalize dispatch moves work to todo:
- Classify release-class tasks from the combined title, description, and prompt text.
- For release-class tasks, require a user-authored source (
dashboard_ui,quick_chat,chat_session, orcli). - Require the prompt marker
**Release Authorized By User:** yesfor those user-authored sources. - Fail closed for unknown, internal, API, imported, duplicated, refined, workflow, recovery, research, cron, and agent-authored sources.
The marker alone is intentionally insufficient. A non-user source that embeds the marker remains blocked because agents and integrations can write prompt text.
Verification
Use the pure classifier tests in packages/engine/src/__tests__/triage-release-authorization.test.ts to cover the invariant without store, network, or timer dependencies. The test matrix should include the FN-6469 incident shape, all documented release signal patterns, all user-authored sources, representative non-user sources, marker parsing, and non-release pass-through behavior.