This repository was archived by the owner on Oct 9, 2026. It is now read-only.
Repository navigation
Conversation
Contributor
Author
|
Superseded by #63, which includes this change or replaces it. |
mekjr1
added a commit
that referenced
this pull request
Oct 9, 2026
Compa 4.0.0: one owner, on WhatsApp and Slack. - **Channels:** the web chat, WhatsApp (native linked device, QR linking, files up to 50 MB), Slack (bot and app tokens), and the Slack and Teams webhooks. The other chat apps are no longer included. - **Owner only:** the accounts in Allow From, in direct messages. Pairing binds the first account. - **Message tool:** sends to any chat by default. Cron results, heartbeat messages and approval requests also go to the webhooks. - **Dependencies:** - llmgw-core 1.9.1, llm-provider-auth 1.0.1, llm-translate 0.4.0. - Go 1.26.9 and golang.org/x/net 0.60.0, which fix vulnerabilities. - **Go module path:** github.com/xibodev/compa/v4. - **Release archives:** they hold THIRD_PARTY_NOTICES. - **Upgrades:** a config.json saved by 1.0.0 loads. - **Docs and website:** rewritten. - **From the earlier PRs:** the fixes and features of #45 to #52 and #57 to #61.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #38.
tools.exec.custom_allow_patterns(Config → Run Commands → Command Whitelist) never let a command through.guardCommandchecked every deny pattern first and refused any match. It read the allow patterns only for a strict allowlist (allowPatterns) that nothing set.Now the setting does what its hint says, by the rule the issue suggests:
ExecToolkeeps the built-in deny patterns (denyPatterns) apart fromcustom_deny_patterns(customDenyPatterns). A command that matches a custom allow pattern skips the built-in patterns. The custom deny patterns apply to every command, so the protectionTestShellTool_CustomAllowDoesNotBypassDenyPatternscovers stays: a whitelistedjqstill can't read$ENVpast a blacklist rule. The workspace limits apply as before.POST /api/config/test-command-patterns) checks the blacklist first. A command that both lists match shows as blocked; it showed as allowed. The page already showsblockedthat way.allowPatterns,SetAllowPatternsand its "not in allowlist" refusal.A whitelist pattern is matched against the whole command line, as the blacklist is. So
^git\s+push\balso lets whatever is chained aftergit pushskip the built-in patterns. End a pattern with$to allow a single command.The whitelist hint now says which patterns a match skips and that the blacklist still applies, in all five languages.
docs/use.mdlists the whitelist among the command controls. CHANGELOG line.Tests:
TestShellTool_CustomAllowPatternsnow callsguardCommand. It calledExecutewithoutaction, which refused before the guard ran. It checks that:TestShellTool_CustomAllowDoesNotBypassDenyPatternsalso fails under the second.TestHandleTestCommandPatterns_BlacklistOutranksWhitelistfails with the old tester.