feat(frontend): surface MCP tool permissions per agent — Permissions panel (#82 lot UX/F)
Adds the "Tools MCP IdeA" tab to the project Permissions panel, alongside the existing "Système" (file/command) tab. Lets the user grant/revoke MCP tool capabilities per agent or project-wide default, grouped by domain (Lecture projet, Lecture tickets, Délégation agents, Contexte et mémoire, Tickets, Travail et exécution, Skills) instead of a flat 25-checkbox list, per the UX conception in carnet #82. - domain/ports/adapters (Tauri, HTTP, mock): wire get_mcp_tool_permissions, update_project_mcp_tool_permissions, update_agent_mcp_tool_permissions (already merged backend API, #82 lots B1-B4) onto PermissionGateway. - useMcpToolPermissions: view-model owning the durable MCP tool policy document, distinct from the file/command permissions in usePermissions. - McpToolPermissionsPanel: target selector (Défaut projet + agents with Hérité/Override badges) and grouped editor — inherited agents are read-only until "Créer un override" (prefilled with the effective allowlist), per-row Ajouté/Retiré diffing against the project default, inline confirmation before granting a write tool at project-default level, and unsaved-draft protection on target change. - mcpToolGroups.ts: presentational-only domain grouping and short French labels — the read/write classification itself always comes from the backend-provided catalogue, never hardcoded here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@ -32,11 +32,13 @@ import type {
|
||||
MemoryIndexEntry,
|
||||
MemoryLink,
|
||||
MemoryType,
|
||||
McpToolPolicy,
|
||||
OpenCodeConfig,
|
||||
EffectivePermissions,
|
||||
PairedDevice,
|
||||
PairingCode,
|
||||
PermissionSet,
|
||||
ProjectMcpToolPermissions,
|
||||
PageDirection,
|
||||
Project,
|
||||
ProjectPermissions,
|
||||
@ -797,6 +799,23 @@ export interface PermissionGateway {
|
||||
projectId: string,
|
||||
agentId: string,
|
||||
): Promise<EffectivePermissions | null>;
|
||||
/**
|
||||
* Reads the project's durable MCP tool permission document plus the
|
||||
* backend-canonical catalogue classification (ticket #82). Distinct
|
||||
* document from the file/command permissions above.
|
||||
*/
|
||||
getMcpToolPermissions(projectId: string): Promise<ProjectMcpToolPermissions>;
|
||||
/** Replaces or removes the project-wide default MCP tool policy. */
|
||||
updateProjectMcpToolPermissions(
|
||||
projectId: string,
|
||||
policy: McpToolPolicy | null,
|
||||
): Promise<ProjectMcpToolPermissions>;
|
||||
/** Replaces or removes one agent's MCP tool policy override. */
|
||||
updateAgentMcpToolPermissions(
|
||||
projectId: string,
|
||||
agentId: string,
|
||||
policy: McpToolPolicy | null,
|
||||
): Promise<ProjectMcpToolPermissions>;
|
||||
}
|
||||
|
||||
/** Read-only live work-state read-model for conversations/delegations. */
|
||||
|
||||
Reference in New Issue
Block a user