Repository navigation
disable permissions via config #697
Description
Activity
please provide more context
What "permissions" means in Zero
Zero has a permission mode system that controls whether the agent prompts the user before taking side-effectful actions (writing files, running shell commands, network access, etc.). The modes are:
ask— interactive default; prompts before every write/shell/network actionauto— auto-approves low-risk tools, prompts for higher-risk onesunsafe— disables permission prompts entirely; all tool calls are auto-allowed (the sandbox still enforces hard blocks like out-of-workspace writes)
The current situation
Right now, the only way to run in
unsafemode is to pass--skip-permissions-unsafeas a CLI flag on every invocation, or use--auto highwithzero exec. There is no way to persist this preference in the config file.The
FileConfigstruct (internal/config/types.go) supports fields likesandbox,notify,tools,mcp, etc., but has nopermissionModefield.What this feature request is asking for
Add a
permissionMode(or similar) key to the config file (e.g.~/.config/zero/config.jsonor the project-level config) so users can set their preferred mode persistently. For example:{ "permissionMode": "unsafe" }Use case
This is useful for trusted local environments or CI pipelines where the user doesn't want to pass
--skip-permissions-unsafeon every run, and doesn't want to be interrupted by permission prompts. It's essentially a "remember my choice" for the permission mode.@yookibooki what are you trying to get to here? Asking because there are already a few ways to turn the friction down, and which one fits depends on what is actually in your way:
"sandbox": {"enabled": false}in your user config turns OS sandboxing off entirely.- Permission mode can be set per run, and feat(tui): full-auto permission mode, and classify local dev servers separately #883 adds a full-auto mode that stops asking for anything inside the workspace.
- Individual tools and commands can be pre-approved so you are not prompted for the ones you always allow.
If none of those cover it, say which prompt is getting in your way and I will look at that specifically.
Holding off on approving a blanket "disable permissions" switch, because the permission gate is the thing Zero is actually for. A single config key that turns it all off is the one setting most likely to be copied from a blog post into a machine where it should not be, and it would apply to project config unless carefully scoped. Happy to be shown a case that needs it.
add option to disable permissions in config