Skip to content

FEAT: review and approve file changes with numbered diffs - #74

Merged
merefield merged 3 commits into
mainfrom
feat/file-change-approvals
Oct 7, 2026
Merged

merefield merged 3 commits into
mainfrom
feat/file-change-approvals

Conversation

@merefield

Copy link
Copy Markdown
Owner

Why

Codexometer previously displayed file-change approval requests but deliberately offered no response buttons. Users had to return to Codex even when connected to the shared app-server. This adds guarded approval of complete, matched file patches without changing ordinary command approval behaviour.

Changes

  • Capture proposed file changes from live item/started and item/fileChange/patchUpdated events, keyed by thread, turn and item.
  • Display paths, rename destinations, unified hunks, old/new line numbers, green additions and red removals. Add/delete operations correctly treat the API's diff as whole-file content. Terminal full detail remains scrollable and retains preceding commentary and justification.
  • Offer Approve Once with the existing confirmation safeguards, Decline, and Reject & Stop Turn. Inline terminal controls appear only if the complete request and patch fit; otherwise open full detail.
  • Share validated patch data and line numbering across TUI and browser. Writable web mode binds confirmation to the exact displayed patch; read-only mode displays the same changes without actions.
  • Keep missing, oversized, unsafe or changed patches non-actionable. Invalidate capabilities when the patch changes; require a fresh matching approval request. Never reconstruct proposed changes from disk. Directory-root grants and session-wide file grants remain outside this implementation.
  • Bound retained patch JSON to 64 KiB and 64 files per item, with at most 16 cached items per thread; clear item/turn state on completion. No new persistence.
  • Update README, intro post and all 17 locale fallback messages. Rebuild committed web assets and the local binary.

Validation

  • go test ./... — passed.
  • go vet ./... — passed.
  • Targeted go test -race for file approval correlation/safety/lifecycle, actual WebSocket response payloads, browser confirmation binding, and terminal diff rendering — passed.
  • npm run check and npm run build — passed.
  • Three Playwright tests passed: numbered/red-green file diffs plus confirmation/read-only mode, ordinary command confirmation, and stale/changed request rejection.

Tests use synthetic requests and local mock app-servers; no real user approval was submitted during verification.

Deliberate limits

The app-server marks directory-root grants as unstable, so those still say Reply in Codex. Missing or larger-than-limit patches also remain in Codex rather than enabling blind approval. Only one-time file approval is exposed, not broader session permissions. Existing pending requests whose patch was not observed may need review in Codex; this does not recover unseen diffs from local files.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Rename decoding, malformed-diff validation, and canonical size enforcement remain unresolved.

1 open finding
What changed in this PR

Adds guarded review and one-time approval for complete file-change patches in terminal and web interfaces.

Changes:

  • Captures, validates, correlates, and bounds live file patches.
  • Adds numbered diffs and confirmation-bound approval controls.
  • Updates tests, documentation, localization, and web assets.
File Description
web/​tests/​browser.spec.ts Browser approval and diff coverage.
web/​src/​state.svelte.ts File-diff state types.
web/​src/​Sessions.svelte Displays session diffs.
web/​src/​SessionActions.svelte Renders approval controls.
web/​src/​FileDiff.svelte Shared diff renderer.
README.md Documents file approvals.
intro-post.md Updates feature introduction.
internal/​web/​state.go Projects diffs to browsers.
internal/​web/​dist/​index.html References rebuilt assets.
internal/​web/​dist/​assets/​index-CnNJF8v9.css Replaced stylesheet.
internal/​web/​dist/​assets/​index-CLM8akQt.js Replaced bundle.
internal/​web/​dist/​assets/​index-CIiWCxs0.css Rebuilt diff styling.
internal/​web/​control.go Binds file approval offers.
internal/​web/​control_test.go Tests patch binding and staleness.
internal/​ui/​monitor_detail.go Renders terminal diffs.
internal/​ui/​monitor_context_modes.go Handles inline and full diff views.
internal/​ui/​monitor_approval.go Updates unavailable messaging.
internal/​ui/​file_approval_test.go Tests terminal diff rendering.
internal/​i18n/​locales/​zh-Hans.json Updates localized fallback text.
internal/​i18n/​locales/​tr.json Updates localized fallback text.
internal/​i18n/​locales/​sv.json Updates localized fallback text.
internal/​i18n/​locales/​ru.json Updates localized fallback text.
internal/​i18n/​locales/​pt-PT.json Updates localized fallback text.
internal/​i18n/​locales/​pt-BR.json Updates localized fallback text.
internal/​i18n/​locales/​nl.json Updates localized fallback text.
internal/​i18n/​locales/​nb.json Updates localized fallback text.
internal/​i18n/​locales/​ja.json Updates localized fallback text.
internal/​i18n/​locales/​it.json Updates localized fallback text.
internal/​i18n/​locales/​fr.json Updates localized fallback text.
internal/​i18n/​locales/​fi.json Updates localized fallback text.
internal/​i18n/​locales/​et.json Updates localized fallback text.
internal/​i18n/​locales/​es.json Updates localized fallback text.
internal/​i18n/​locales/​en-GB.json Adds fallback source text.
internal/​i18n/​locales/​de.json Updates localized fallback text.
internal/​i18n/​locales/​da.json Updates localized fallback text.
internal/​codex/​session_context.go Stores validated patches.
internal/​codex/​session_context_daemon.go Captures patch lifecycle events.
internal/​codex/​session_approval.go Extends approval capability scope.
internal/​codex/​session_approval_unix_test.go Tests approval wire responses.
internal/​codex/​file_approval.go Validates and formats patches.
internal/​codex/​file_approval_test.go Tests patch safety and numbering.

🧠 Review effort: Lite


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread internal/codex/file_approval.go
@merefield
merefield merged commit ad7f157 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants