Compare commits

..
Author SHA1 Message Date
shadowdaoandClaude Opus 5.5 1a31cf4128 Add Auto permission mode
Build App (Preview) / compute-version (pull_request) Successful in 5s
Secret Scan / scan (push) Successful in 5s
Build App (Preview) / test (pull_request) Successful in 4m38s
Secret Scan / scan (pull_request) Successful in 4s
Build App (Preview) / create-release (pull_request) Successful in 1s
Build App (Preview) / build-macos (pull_request) Successful in 2m47s
Build Container / build-container (pull_request) Successful in 10m19s
Build App (Preview) / build-windows (pull_request) Successful in 5m57s
Build App (Preview) / build-linux (pull_request) Canceled after 14s
Build App (Preview) / prune-previews (pull_request) Canceled after 0s
Claude Code now ships `--permission-mode auto`, where a safety classifier
approves routine actions and blocks risky ones without prompting. Expose it
as a fifth mode between Accept Edits and Bypass: terminals, resumed sessions,
the tab badge, and the scheduler's task runner all map it to the flag.

Headless scheduled runs don't stall in Auto (blocked actions are denied, not
prompted), so the task editor shows a softer note instead of the stall warning.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 09:52:50 -07:00
4 changed files with 10 additions and 18 deletions
+3 -7
View File
@@ -484,9 +484,7 @@ the way they did: one that had Full Permissions on becomes **Bypass**, one that
**Auto** sits between Accept Edits and Bypass: Claude Code's own classifier reviews each action,
lets routine work through and blocks things that look risky (such as destructive or
exfiltrating commands) — no prompts either way. Whether it is available depends on your Claude
Code account, model and backend (local and OpenAI-compatible backends usually won't
qualify). When it isn't available, Claude Code quietly starts in its normal prompting mode
instead.
Code account and model; see Claude Code's documentation on permission modes.
### When a change takes effect
@@ -504,8 +502,7 @@ instead.
> Scheduled tasks run headless (`claude -p`) and cannot answer a permission prompt. In any mode
> other than **Auto** or **Bypass**, a task may simply stop early when Claude Code asks for
> approval. In **Auto**, actions the classifier blocks are denied and the run carries on without
> them — but if Auto isn't available for the project's model or backend, Claude Code falls back
> to prompting and the task can stall the same way. Its run log records which mode it used.
> them. Its run log records which mode it used.
---
@@ -1360,8 +1357,7 @@ with `--dangerously-skip-permissions`. Because the mode travels into the contain
environment variable, **stop and start the project** after changing it for the scheduler to see the
change. Remember that a headless run cannot answer a permission prompt, so in any mode other than
**Auto** or **Bypass** a task may stop early when Claude Code asks for approval (in Auto, blocked
actions are denied instead, unless Auto is unavailable and Claude Code falls back to
prompting); the run log records the mode
actions are denied instead); the run log records the mode
that was used.
### Creating Tasks
@@ -165,11 +165,10 @@ describe("TaskEditorModal", () => {
expect(screen.queryByText(/cannot answer a permission prompt/i)).toBeNull();
});
it("tells Auto mode that blocked actions are denied, and warns of the fallback", async () => {
it("tells Auto mode that blocked actions are denied, not prompted", async () => {
await renderEditor(null, { ...baseProject, permission_mode: "auto" });
expect(screen.queryByText(/cannot answer a permission prompt/i)).toBeNull();
expect(screen.getByText(/blocks are denied/i)).toBeInTheDocument();
expect(screen.getByText(/falls back to prompting/i)).toBeInTheDocument();
});
it("spells out the stall risk in any non-Bypass mode", async () => {
@@ -302,10 +302,9 @@ export default function TaskEditorModal({ project, task, onClose, onSaved }: Pro
<strong className="text-[var(--text-primary)]">{modeLabel}</strong>).
</p>
{mode === "auto" && (
<p className="text-xs text-[var(--warning)]">
In Auto mode, actions the safety classifier blocks are denied and the run carries on
without them. If Auto isn&rsquo;t available for this project&rsquo;s model or backend,
Claude Code falls back to prompting and the task may stall.
<p className="text-xs text-[var(--text-secondary)]">
In Auto mode nothing prompts: actions the safety classifier blocks are denied and the
run carries on without them, so check the log if a task seems to have skipped a step.
</p>
)}
{mode !== "bypass" && mode !== "auto" && (
+3 -5
View File
@@ -61,11 +61,9 @@ TASK_TYPE=$(jq -r '.type' "$TASK_FILE")
# project's permission setting. Keep this mapping in sync with
# PermissionMode::cli_args() in app/src-tauri/src/models/project.rs.
# NOTE: headless `claude -p` runs cannot answer a permission prompt, so any
# mode other than "bypass" means the task may stop early when Claude Code asks
# for permission. In "auto", classifier-blocked actions are denied instead of
# prompted, but if auto mode is unavailable for the session's model/backend,
# Claude Code falls back to prompting and the same stall applies.
# Unset or unrecognized values pass no flag (Claude's default).
# mode other than "bypass" or "auto" means the task may stop early when Claude
# Code asks for permission. In "auto", actions the classifier blocks are
# denied rather than prompted, so the run continues without them. Unset or unrecognized values pass no flag (Claude's default).
PERMISSION_ARGS=()
case "${TRIPLE_C_PERMISSION_MODE:-}" in
plan) PERMISSION_ARGS=(--permission-mode plan) ;;