mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-12 21:53:00 -06:00
fix(codex): defer report-mode plugin approvals
Route Codex app-server report-mode PreToolUse plugin approval requirements through the matching app-server approval request instead of failing closed. Shares duplicate in-flight approvals, preserves block/rewrite fail-closed behavior, and keeps generic plugin allow-always scoped to one Codex request. Supersedes #86978; thanks @clawSean for the original docs clarification.
This commit is contained in:
committed by
GitHub
parent
44dc29f397
commit
56a5d7e865
@@ -99,6 +99,16 @@ OpenClaw can mirror selected events, but it cannot rewrite the native Codex
|
||||
thread unless Codex exposes that operation through app-server or native hook
|
||||
callbacks.
|
||||
|
||||
Codex app-server report-mode `PreToolUse` events defer plugin approval requests
|
||||
to the matching app-server approval. If an OpenClaw `before_tool_call` hook
|
||||
returns `requireApproval` while the native payload sets report approval mode
|
||||
(`openclaw_approval_mode` is `"report"`), the native hook relay records the
|
||||
plugin approval requirement and returns no native decision. When Codex sends the
|
||||
app-server approval request for the same tool use, OpenClaw opens the plugin
|
||||
approval prompt and maps the decision back to Codex. Codex `PermissionRequest`
|
||||
events are a separate approval path and can still route through OpenClaw
|
||||
approvals when the runtime is configured for that bridge.
|
||||
|
||||
Codex app-server item notifications also provide async `after_tool_call`
|
||||
observations for native tool completions that are not already covered by the
|
||||
native `PostToolUse` relay. These observations are for telemetry and plugin
|
||||
|
||||
Reference in New Issue
Block a user