Conversation
Harbor404
requested review from
MikeRyanDev,
davidmckayv,
guidovizoso,
mxmzb and
tylerslaton
as code owners
October 1, 2026 13:45
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
Refs #350.
Adds an additive decision-point seam to the computer gateway:
PolicyDecider,(PolicyContext) => PolicyDecision | Promise<PolicyDecision>ComputerGatewayOptions.decideevaluateActionPolicy(options.policy(), context)as the default whendecideis absentgovernpathA host can now replace the evaluator without changing the default rules path or the audit/forwarding order. Decider errors propagate unchanged and the action is not carried out. No external policy engine or new public semantics are introduced.
Where it runs
PolicyContext.Boundary and audit
ActionRefusedErrorpath as built-in refusals.decideis not supplied.Changelog
No deployment behavior changes unless an embedder opts into
decide, so noCHANGELOG.mdentry is needed.Proof
bun test server/tests/computer-policy-decider.test.ts— 5 pass, 0 failbun test server/tests/computer-policy.test.ts server/tests/computer-gateway.test.ts— 116 pass, 0 failbun run typecheck— app, server, worker exit 0bun run lint— 983 files checked, no fixes appliedbunx biome check server/src/computer/gateway.ts server/src/computer/policy.ts server/tests/computer-policy-decider.test.ts— cleanThe new tests cover the built-in evaluator, async custom evaluator/context injection, denial, the default fail-closed path with no rules, and error propagation without carrying out the action.