Skip to content

feat(computer): make the policy decision point pluggable - #694

Open
Harbor404 wants to merge 1 commit into
CopilotKit:mainfrom
Harbor404:feat/350-pluggable-policy-decider
Open

Harbor404 wants to merge 1 commit into
CopilotKit:mainfrom
Harbor404:feat/350-pluggable-policy-decider

Conversation

@Harbor404

Copy link
Copy Markdown

What this changes

Refs #350.

Adds an additive decision-point seam to the computer gateway:

  • exports PolicyDecider, (PolicyContext) => PolicyDecision | Promise<PolicyDecision>
  • adds optional ComputerGatewayOptions.decide
  • keeps evaluateActionPolicy(options.policy(), context) as the default when decide is absent
  • awaits the selected decider inside the existing async govern path

A host can now replace the evaluator without changing the default rules path or the audit/forwarding order. Decider errors propagate unchanged and the action is not carried out. No external policy engine or new public semantics are introduced.

Where it runs

  • New state that outlives a request? None. The decider is a factory-level function; each decision uses the request's resolved PolicyContext.
  • What happens on the second replica? Each replica runs the configured decider locally and then follows the same resolve → decide → audit → act path. No in-process decision state is added.
  • Anything serialised? No new writes or shared state.
  • Anything fanned out to a browser? None.
  • New listener, port, or schedule? None.

Boundary and audit

  • Every acting call still goes through the gateway: resolve, decide, audit, then act.
  • Custom refusals use the same audit row and ActionRefusedError path as built-in refusals.
  • Nothing new is trusted from the client; the decider receives the server-resolved context.
  • Default behavior is unchanged when decide is not supplied.
  • Decider errors propagate before the action reaches the computer; no new wall-clock timeout was added in this minimal increment.

Changelog

No deployment behavior changes unless an embedder opts into decide, so no CHANGELOG.md entry is needed.

Proof

  • bun test server/tests/computer-policy-decider.test.ts — 5 pass, 0 fail
  • bun test server/tests/computer-policy.test.ts server/tests/computer-gateway.test.ts — 116 pass, 0 fail
  • bun run typecheck — app, server, worker exit 0
  • bun run lint — 983 files checked, no fixes applied
  • bunx biome check server/src/computer/gateway.ts server/src/computer/policy.ts server/tests/computer-policy-decider.test.ts — clean

The new tests cover the built-in evaluator, async custom evaluator/context injection, denial, the default fail-closed path with no rules, and error propagation without carrying out the action.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant