Repository navigation
FEAT: review and approve file changes with numbered diffs - #74
Merged
Merged
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Rename decoding, malformed-diff validation, and canonical size enforcement remain unresolved.
1 open finding
What changed in this PR
Adds guarded review and one-time approval for complete file-change patches in terminal and web interfaces.
Changes:
- Captures, validates, correlates, and bounds live file patches.
- Adds numbered diffs and confirmation-bound approval controls.
- Updates tests, documentation, localization, and web assets.
| File | Description |
|---|---|
web/tests/browser.spec.ts |
Browser approval and diff coverage. |
web/src/state.svelte.ts |
File-diff state types. |
web/src/Sessions.svelte |
Displays session diffs. |
web/src/SessionActions.svelte |
Renders approval controls. |
web/src/FileDiff.svelte |
Shared diff renderer. |
README.md |
Documents file approvals. |
intro-post.md |
Updates feature introduction. |
internal/web/state.go |
Projects diffs to browsers. |
internal/web/dist/index.html |
References rebuilt assets. |
internal/web/dist/assets/index-CnNJF8v9.css |
Replaced stylesheet. |
internal/web/dist/assets/index-CLM8akQt.js |
Replaced bundle. |
internal/web/dist/assets/index-CIiWCxs0.css |
Rebuilt diff styling. |
internal/web/control.go |
Binds file approval offers. |
internal/web/control_test.go |
Tests patch binding and staleness. |
internal/ui/monitor_detail.go |
Renders terminal diffs. |
internal/ui/monitor_context_modes.go |
Handles inline and full diff views. |
internal/ui/monitor_approval.go |
Updates unavailable messaging. |
internal/ui/file_approval_test.go |
Tests terminal diff rendering. |
internal/i18n/locales/zh-Hans.json |
Updates localized fallback text. |
internal/i18n/locales/tr.json |
Updates localized fallback text. |
internal/i18n/locales/sv.json |
Updates localized fallback text. |
internal/i18n/locales/ru.json |
Updates localized fallback text. |
internal/i18n/locales/pt-PT.json |
Updates localized fallback text. |
internal/i18n/locales/pt-BR.json |
Updates localized fallback text. |
internal/i18n/locales/nl.json |
Updates localized fallback text. |
internal/i18n/locales/nb.json |
Updates localized fallback text. |
internal/i18n/locales/ja.json |
Updates localized fallback text. |
internal/i18n/locales/it.json |
Updates localized fallback text. |
internal/i18n/locales/fr.json |
Updates localized fallback text. |
internal/i18n/locales/fi.json |
Updates localized fallback text. |
internal/i18n/locales/et.json |
Updates localized fallback text. |
internal/i18n/locales/es.json |
Updates localized fallback text. |
internal/i18n/locales/en-GB.json |
Adds fallback source text. |
internal/i18n/locales/de.json |
Updates localized fallback text. |
internal/i18n/locales/da.json |
Updates localized fallback text. |
internal/codex/session_context.go |
Stores validated patches. |
internal/codex/session_context_daemon.go |
Captures patch lifecycle events. |
internal/codex/session_approval.go |
Extends approval capability scope. |
internal/codex/session_approval_unix_test.go |
Tests approval wire responses. |
internal/codex/file_approval.go |
Validates and formats patches. |
internal/codex/file_approval_test.go |
Tests patch safety and numbering. |
🧠 Review effort: Lite
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Why
Codexometer previously displayed file-change approval requests but deliberately offered no response buttons. Users had to return to Codex even when connected to the shared app-server. This adds guarded approval of complete, matched file patches without changing ordinary command approval behaviour.
Changes
item/startedanditem/fileChange/patchUpdatedevents, keyed by thread, turn and item.Validation
go test ./...— passed.go vet ./...— passed.go test -racefor file approval correlation/safety/lifecycle, actual WebSocket response payloads, browser confirmation binding, and terminal diff rendering — passed.npm run checkandnpm run build— passed.Tests use synthetic requests and local mock app-servers; no real user approval was submitted during verification.
Deliberate limits
The app-server marks directory-root grants as unstable, so those still say Reply in Codex. Missing or larger-than-limit patches also remain in Codex rather than enabling blind approval. Only one-time file approval is exposed, not broader session permissions. Existing pending requests whose patch was not observed may need review in Codex; this does not recover unseen diffs from local files.