feat(permission): permissions projection unit and /permission command

The read side becomes the 'permissions' session projection: src/types.ts is
the key declaration's one home (PermissionSelect = whole select: table
options in declaration order plus a current-only 'custom'), served through
./types and the ./client re-export. The unit folds the three whole-value
knob events (permission/preset, sandbox/mode, approval/policy) into a plain
KnobState and views the select over the composition defaults the service
already owns; current() shares the same derive step, so the fold exists
once. The write side becomes the /permission command (the /plan
registration shape): bare invocation reports the current preset and the
table, a preset argument switches through set() immediately — no turn
anchoring (knob events need no enclosure), no dedicated RPC. Both children
activate only when their registry is composed.
This commit is contained in:
imccyu
2026-07-28 22:23:39 +08:00
parent 1c76286472
commit 451b7b0446
8 changed files with 336 additions and 19 deletions

9
pnpm-lock.yaml generated
View File

@@ -4569,10 +4569,16 @@ importers:
schemastery:
specifier: ^3.18.0
version: 3.18.0
zod:
specifier: ^4.4.3
version: 4.4.3
devDependencies:
'@deepseek-ai/dsh-bash':
specifier: workspace:^
version: link:../../bash/bash
'@deepseek-ai/dsh-commands':
specifier: workspace:^
version: link:../commands
'@deepseek-ai/dsh-invariants':
specifier: workspace:^
version: link:../../support/invariants
@@ -4585,6 +4591,9 @@ importers:
'@deepseek-ai/dsh-session':
specifier: workspace:^
version: link:../../core/session
'@deepseek-ai/dsh-session-projection':
specifier: workspace:^
version: link:../../session-projection/session-projection
'@deepseek-ai/dsh-user-approval':
specifier: workspace:^
version: link:../user-approval