arrow949/dsh-turn-approval
Turn-scoped "Allow for this task" approvals for DeepSeek Harness.
Adds 'Allow for this task' to DSH Web approval cards: when the agent requests danger-full-access, the card shows [拒绝] [允许一次] [允许本次任务]. 'Allow for this task' auto-allows subsequent same-type danger-full-access upgrades within the current turn; the grant expires immediately after turn/end. Default DSH permissions stay workspace-write + ask — the plugin never switches the whole session to full access, never leaks grants across sessions, only auto-allows exact danger-full-access matches (workspace-write and other approvals still ask one by one), grants can only be established by the card button (no model-side entry), and auto-allowed events keep full audit records. On endpoint failure the card shows a retryable error — it never pretends the grant was established or silently degrades to 'allow once'.
Install
dsh plugin --profile web add github:arrow949/dsh-turn-approval#<commit-sha>dsh plugin --profile web add github:arrow949/dsh-turn-approval#<commit-sha> — pinning a commit SHA is recommended so future repo updates can't silently change what runs locally. Local dir: dsh plugin --profile web add ./dsh-turn-approval. Pure ESM with committed build artifacts — no prepare script or pnpm allowBuilds permission needed from GitHub. Restart DSH Web and hard-refresh (Ctrl+Shift+R); a third button appears on approval cards. English README (README.en.md).
Compatibility
DSH Web approval cards (conversation.composer chain); in-memory only — grants never hit disk, die on process restart/plugin uninstall/session release (fail-closed); binds to session + turn; subagents use independent sessions and don't inherit grants.
Details
- Repo: arrow949/dsh-turn-approval
- Category: Agent Capabilities
- Stars: 2
- Version: GitHub source (commit-pinned install recommended)
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
turn-scoped danger-full-access approval; auto-expires at turn/end; fail-closed in-memory grants; audit trail; no permission widening.
FAQ
- What does 'Allow for this task' do?
- It auto-allows subsequent same-type danger-full-access requests within the current turn; the grant expires at turn/end.
- Does it widen default permissions?
- No — default DSH permissions stay workspace-write + ask; only exact danger-full-access upgrades can be turn-authorized, and only via the card button.
- Do grants persist?
- No — in-memory only; they die on process restart, plugin uninstall, or session/agent release (fail-closed).
Alternatives
Letter2025/dsh-approval-llm · Andy8647/dsh-auto-approval · ang-XWBWZ/dsh-approval-ai