ApprovalManager class final

Holds the approval state of a session and resolves policy per tool call.

Resolution order (see the library doc for the model):

  1. An explicit per-tool deny override refuses the call.
  2. A skill's disallowed-tools (turn-scoped) refuses the call.
  3. A critical bash pattern forces a prompt — except in unattended mode, where there is no user to answer one.
  4. A per-tool allow/prompt override applies.
  5. A skill's allowed-tools (turn-scoped) auto-allows the call.
  6. The session always-allow set (from "approve always" answers) applies.
  7. The session mode compares against the tool's tier.

When resolution lands on ApprovalPolicy.prompt and no prompt callback is installed, the call is DENIED with a "no approval UI" reason — the safe default for headless/non-interactive runs.

Constructors

ApprovalManager({ApprovalMode mode = ApprovalMode.yolo, Map<String, ApprovalPolicy> overrides = const {}, Map<String, String> overrideOrigins = const {}, Set<String> alwaysAllow = const {}, ApprovalPrompt? prompt})
Creates a manager. overrides and alwaysAllow seed the per-tool policy map and the session always-allow set (both are copied). overrideOrigins names where an override came from (config scope, host always-prompt guard, …) — surfaced in the prompt reason so a surprise override is self-diagnosing (issue #380 AC3).

Properties

alwaysAllowedTools → List<String>
Names in the session always-allow set, sorted.
no setter
hashCode → int
The hash code for this object.
no setterinherited
mode ↔ ApprovalMode
The active session mode. Mutable at runtime (/approval, settings UI).
getter/setter pair
prompt ↔ ApprovalPrompt?
The prompt surface. When null, any call resolving to ApprovalPolicy.prompt is denied (safe default).
getter/setter pair
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

allowAlways(String toolName) → void
Adds toolName to the session always-allow set.
authorize({required String toolName, required ApprovalTier tier, required Map<String, dynamic> arguments}) → Future<ApprovalOutcome>
Resolves the policy for one tool call and, when it lands on ApprovalPolicy.prompt, awaits the user's decision via prompt.
clearOverride(String toolName) → void
Removes the per-tool override for toolName.
clearTurnGrants() → void
Clears the turn-scoped grants (called when the user sends a new message).
grantForTurn({Iterable<String> allow = const [], Iterable<String> deny = const []}) → void
Grants/revokes tool permissions for the current turn (skill allowed-tools/disallowed-tools).
isAlwaysAllowed(String toolName) → bool
Whether toolName is in the session always-allow set.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
overrideFor(String toolName) → ApprovalPolicy?
The per-tool override for toolName, or null when unset.
overrideOriginFor(String toolName) → String?
Where toolName's override came from (see setOverride's origin), or null when unset — the settings-surface hook for showing the override's scope (issue #380 AC3).
setOverride(String toolName, ApprovalPolicy policy, {String? origin}) → void
Sets (or replaces) the per-tool override for toolName. origin names where the override comes from (config scope, host always-prompt guard, …) — shown in the prompt reason.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited