Skip to content

[Fix] Auto denials no longer point to a transcript control that doesn't exist - #3332

Merged
daniel-lxs merged 2 commits into
developfrom
fix/auto-deny-agent-message
Sep 30, 2026
Merged

daniel-lxs merged 2 commits into
developfrom
fix/auto-deny-agent-message

Conversation

@daniel-lxs

@daniel-lxs daniel-lxs commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Related issue

Internal follow-up to #3116; no separate issue is linked.

Why this PR exists

  • A maintainer explicitly invited this PR in the linked issue or discussion
  • I am a maintainer / this is internal Roomote work

What changed

When Auto denies a tool call because the session owner is away, the agent used to be told "The session owner can allow this tool from its call in the transcript." No such control exists: an auto-rejected call leaves nothing in the transcript to allow. The agent repeated this to users, so they were sent to look for a button that isn't there.

The agent is now told to continue without the call, tell the owner what was skipped, and that they can ask for it again while they are in the session and approve it when asked. Sessions and tasks share one message, describeIntegrationToolAutoAbsentDenial in @roomote/types, so the two paths can't drift apart again.

How it was tested

  • Fast tool-approval tests (68) and worker OpenCode relay tests (12) pass, with new assertions that the message offers asking again and never mentions the transcript.
  • Type checks for types, cloud-agents and worker, pnpm lint, and formatting pass.
  • Live on a local stack with Auto on and the owner away: the call was auto-rejected, and the agent told the user what was skipped and to ask again once back in the session. It didn't mention the transcript.

Checklist

  • The PR title follows the repo convention: [Fix], [Feat], [Improve], [Refactor], [Docs], or [Chore] followed by a user-facing description
  • This PR is small and scoped to one change
  • pnpm lint and pnpm check-types pass locally
  • I added tests or included a clear manual validation note above
  • I removed secrets, tokens, private keys, and customer data from code, logs, and screenshots
  • If this change should appear in the changelog, I ran pnpm changeset (not needed: Auto is a nightly-only experiment)

Combined local smoke (2026-09-30)

All six Auto/approval PRs (#3332, #3334, #3335, #3337, #3338, #3339) were merged together locally and run on a local stack. It used a real web session with Auto on, Jev through OpenRouter, and a local MCP server whose tools only log (list_files, delete_file, pay_invoice). The PRs merge cleanly into develop in any order, except #3332 and #3337: both add an export next to each other in packages/types, and whichever lands second needs a trivial rebase. The combined build passes uncached pnpm check-types, pnpm lint, and the approval suites (cloud-agents 131, sdk 23, worker 13, db 32).

# Scenario PR Result
S1 "Delete old-notes.txt": the delete runs with no card #3335, #3338 Pass. delete_file auto-approved (authorization 0.97, highest risk level). A list_files with no arguments now shows a card instead of failing the insert.
S2 "Pay invoice INV-11 for $120": asks, even though requested #3335, #3339 Pass. A card on the first attempt (it used to be auto-rejected as "away" in a new session), and the call never ran.
S3 A subagent calls an Ask first tool #3334 Pass. A card appeared and the call ran after Allow once. The subagent's list_files was assessed by Auto (auto-approved row).
S4 Flagged call while the owner is away #3332, #3339 Pass. Auto-rejected about 19 seconds after the message (presence recheck). The agent said "When you're back, ask again", with no mention of the transcript.
S5 Judgment model unavailable #3337 Pass. Two calls failed together, both were rejected, one notice was posted, and the session was marked paused. After "ok, continue", both got plain cards and ran once allowed.
S6 Auto turned off after a pause #3337 Pass. The next call ran with no card (new turn; the mid-turn path is covered by a unit test).
S7 "Delete draft-1, draft-2 and draft-3": all run #3335 Pass. Three deletes auto-approved (authorization 0.92 to 0.96), no cards.

Not covered live: chat surfaces (Slack, Telegram, Discord) and the task (sandbox) path, because there's no local worker. Both are covered by unit tests.

@roomote-community

roomote-community Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

No new code issues found. See task

  • packages/types/src/integration-tool-approvals.ts:121 The capitalized Session makes the required Judgement check fail.

Reviewed 00ffbc2

Comment thread packages/types/src/integration-tool-approvals.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant