From ffc384499ae88fa1cfda8715cb5dad80ddd1b2bb Mon Sep 17 00:00:00 2001 From: Daniel Imms <2193314+Tyriar@users.noreply.github.com> Date: Mon, 5 Jan 2026 04:07:49 -0800 Subject: [PATCH] Add denial tests --- .../runInTerminalTool.test.ts | 93 +++++++++++++++++++ 1 file changed, 93 insertions(+) diff --git a/src/vs/workbench/contrib/terminalContrib/chatAgentTools/test/electron-browser/runInTerminalTool.test.ts b/src/vs/workbench/contrib/terminalContrib/chatAgentTools/test/electron-browser/runInTerminalTool.test.ts index dbc9a0c2940..e7f7df33093 100644 --- a/src/vs/workbench/contrib/terminalContrib/chatAgentTools/test/electron-browser/runInTerminalTool.test.ts +++ b/src/vs/workbench/contrib/terminalContrib/chatAgentTools/test/electron-browser/runInTerminalTool.test.ts @@ -1213,4 +1213,97 @@ suite('RunInTerminalTool', () => { }); }); }); + + suite('denial info in disclaimers', () => { + function getDisclaimerValue(disclaimer: string | import('../../../../../../base/common/htmlContent.js').IMarkdownString | undefined): string | undefined { + if (!disclaimer) { + return undefined; + } + return typeof disclaimer === 'string' ? disclaimer : disclaimer.value; + } + + test('should include denial reason in disclaimer when command is denied by rule', async () => { + setAutoApprove({ + npm: { approve: false } + }); + const result = await executeToolTest({ + command: 'npm run build', + explanation: 'Build the project' + }); + + assertConfirmationRequired(result, 'Run `bash` command?'); + const disclaimerValue = getDisclaimerValue(result?.confirmationMessages?.disclaimer); + ok(disclaimerValue, 'Expected disclaimer to be defined'); + ok(disclaimerValue.includes('denied'), 'Expected disclaimer to mention denial'); + ok(disclaimerValue.includes('npm'), 'Expected disclaimer to mention the denied rule'); + }); + + test('should include link to settings in denial disclaimer', async () => { + setAutoApprove({ + rm: { approve: false } + }); + const result = await executeToolTest({ + command: 'rm -rf temp', + explanation: 'Remove temp folder' + }); + + assertConfirmationRequired(result, 'Run `bash` command?'); + ok(result?.confirmationMessages?.disclaimer, 'Expected disclaimer to be defined'); + // The disclaimer should have trusted commands enabled for settings links + const disclaimer = result.confirmationMessages.disclaimer; + ok(typeof disclaimer !== 'string' && disclaimer.isTrusted, 'Expected disclaimer to be trusted for command links'); + }); + + test('should include denial reason for multiple denied sub-commands', async () => { + setAutoApprove({ + rm: { approve: false }, + sudo: { approve: false } + }); + const result = await executeToolTest({ + command: 'sudo rm -rf /', + explanation: 'Dangerous command' + }); + + assertConfirmationRequired(result, 'Run `bash` command?'); + const disclaimerValue = getDisclaimerValue(result?.confirmationMessages?.disclaimer); + ok(disclaimerValue, 'Expected disclaimer to be defined'); + ok(disclaimerValue.includes('denied'), 'Expected disclaimer to mention denial'); + }); + + test('should not include denial info when auto-approve is disabled', async () => { + setConfig(TerminalChatAgentToolsSettingId.EnableAutoApprove, false); + setAutoApprove({ + npm: { approve: false } + }); + const result = await executeToolTest({ + command: 'npm run build', + explanation: 'Build the project' + }); + + assertConfirmationRequired(result, 'Run `bash` command?'); + // When auto-approve is disabled, there should be no denial-related disclaimer + const disclaimerValue = getDisclaimerValue(result?.confirmationMessages?.disclaimer); + if (disclaimerValue) { + ok(!disclaimerValue.includes('denied'), 'Should not mention denial when auto-approve is disabled'); + } + }); + + test('should not include denial info for commands that are simply not approved', async () => { + // Command is not in auto-approve list, but not explicitly denied + setAutoApprove({ + echo: true + }); + const result = await executeToolTest({ + command: 'npm run build', + explanation: 'Build the project' + }); + + assertConfirmationRequired(result, 'Run `bash` command?'); + // There should be no denial disclaimer since npm is not explicitly denied + const disclaimerValue = getDisclaimerValue(result?.confirmationMessages?.disclaimer); + if (disclaimerValue) { + ok(!disclaimerValue.includes('denied'), 'Should not mention denial for non-denied commands'); + } + }); + }); });