Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add configurable default access mode for new threads - #3086

Closed
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode
Closed

Add configurable default access mode for new threads#3086
JustMarkDev wants to merge 7 commits into
pingdotgg:mainfrom
JustMarkDev:feature/default-permission-mode

Conversation

@JustMarkDev

@JustMarkDevJustMarkDev commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

What Changed

Added a persisted defaultRuntimeMode client setting and exposed it in apps/web settings UI as Default access. New draft threads now initialize with that setting instead of always starting in full-access.

Also updated the relevant settings and persistence tests to cover the new field.

Why

This makes the app remember the user’s preferred permission mode for new threads, so they do not have to reselect it every time. The change is scoped to client-side defaults and preserves existing behavior for saved data by falling back to the current full-access default when the new setting is absent.

UI Changes

Progetto.senza.titolo.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Closes#2662


Note

Low Risk
Client-side default for new draft permission mode only; schema defaults preserve prior behavior when the field is absent.

Overview
Adds a persisted defaultRuntimeMode server setting (defaulting to the existing full-access constant when unset) and a Default access control in settings so users can choose Supervised, Auto-accept edits, or Full access for new draft threads.

New drafts no longer hardcode DEFAULT_RUNTIME_MODE: buildNewDraftExecutionDefaults sets runtimeMode from the setting and keeps the provider default interaction mode; ChatView, useHandleNewThread, and the active composer fallback read settings.defaultRuntimeMode instead of the constant. Restore-to-defaults and the changed-settings list include the new field; server settings persistence tests cover round-tripping.

Reviewed by Cursor Bugbot for commit ea95e48. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add configurable default access mode for new threads in server settings and UI

  • Adds defaultRuntimeMode to ServerSettings and ServerSettingsPatch schemas in settings.ts, defaulting to DEFAULT_RUNTIME_MODE.
  • Introduces buildNewDraftExecutionDefaults in chatThreadActions.ts to initialize new draft threads with runtimeMode from the configured default and interactionMode from the provider default.
  • Updates ChatView.tsx and useHandleNewThread.ts to use settings.defaultRuntimeMode instead of the hardcoded DEFAULT_RUNTIME_MODE constant.
  • Adds a 'Default access' select control in SettingsPanels.tsx so users can view, change, and reset the default runtime mode; restore-to-defaults also resets this field.

Macroscope summarized ea95e48.

- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
@coderabbitai

coderabbitaiBot commented Jun 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: ec51989d-445f-46ca-a83b-27056716c368

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Jun 14, 2026
@macroscopeapp

macroscopeappBot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Introduces a new user-facing settings option that controls the default access mode for new threads. New features adding configuration capabilities warrant human review even when implementation is straightforward.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 2a7e5af to 4d589e8CompareJune 19, 2026 06:38
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Jun 19, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Jun 19, 2026
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4d589e8 to 4642fd2CompareJune 19, 2026 18:45
@macroscopeapp
macroscopeappBot dismissed their stale reviewJune 19, 2026 18:45

Dismissing prior approval to re-evaluate 4642fd2

@juliusmarminge

Copy link
Copy Markdown
Member

should be server setting imo

Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadapps/web/src/hooks/useSettings.ts Outdated
JustMarkDevand others added 2 commits June 19, 2026 11:56
- Persist client-side default runtime mode in settings
- Use it when creating draft threads and new local threads
- Surface the setting in the UI and cover it with tests
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the feature/default-permission-mode branch from 4642fd2 to 860f0c6CompareJune 19, 2026 18:58
Comment threadapps/web/src/lib/newThreadSettings.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx
… into feature/default-permission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/components/settings/SettingsPanels.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	apps/web/src/localApi.test.ts
#	packages/contracts/src/settings.test.ts
…mission-mode
# Conflicts:
#	apps/web/src/components/ChatView.tsx
#	apps/web/src/hooks/useHandleNewThread.ts
#	packages/contracts/src/settings.test.ts
@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

Sorry for the late response. I’ve fixed the merge conflicts, and the preference is now stored as a server setting.

@benglewis

benglewis commented Jul 27, 2026

Copy link
Copy Markdown

@juliusmarminge Honestly, I'm trying to make sense of this:

  1. Why do you trust LLMs with full access to your machines? What if the agent just casually deletes your entire disk? Or it casually sends your credentials to various websites out to the world for others to use. Prompt injection in LLMs still exists and is not entirely preventable at this stage AFAIK, so this is like using software from some random supplier who you are not sure has protection against SQL injection and then giving them all of your computer user and all of its current permissions. What makes you feel safe / comfortable doing that?
  2. Given this is the default behaviour, do you really have a good reason not to merge this PR allowing others to change their default setting when using T3 Code? This is the number 1 reason that I cannot realistically use T3 Code right now

@JustMarkDev

Copy link
Copy Markdown
ContributorAuthor

I created this pr because I thought it would be a simple change to implement while learning agenting engineering (I read the code of course), I actually wouldn't be that affected by this change since I usually always run as always-approve, models are quite good at avoiding critical errors like eliminating a codebase, i've seen a couple of tweets of it happening but nothing a bit of better prompting or context management wouldn't fix. Also and I think this is the biggest reason as to why he's not merging: they are focused on other things, the new sidebar and mobile support (t3 cloud) and also i'm not a vouched contributor (not that I wanna be)

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

We are not adding a configurable default access mode for new threads through this implementation. It applies the selected mode to every new thread through a server setting.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

@t3dotggt3dotgg closed this Aug 28, 2026
@hillerstorm

Copy link
Copy Markdown

personally, anything that would default me to Auto instead of Full Access / Dangerously Skip Permissions / YOLO is fine. Having yolo as default might work for open source stuff but it's straight up irresponsible otherwise 😅
Sure, it remembers what I previously selected sometimes, sometimes not, unique per project, not sticky across phone/desktop, which is very error-prone.

Just my 2 cents

@JustMarkDev
JustMarkDev deleted the feature/default-permission-mode branch August 31, 2026 16:37
@elmarbeckmann

Copy link
Copy Markdown

I'd like to make a case for revisiting this, as a user who just ran into it. I can't reopen the PR myself, so I'm leaving it here.

The close note says the problem is that the setting applies the selected mode to every new thread. But that is already what happens today, just with the value nobody would pick deliberately: every new thread starts in Full access. DEFAULT_RUNTIME_MODE is hardcoded to "full-access" on current nightly, a thread inherits a mode only when it has a carry source (carryRuntimeMode ?? DEFAULT_RUNTIME_MODE), and there is no setting key anywhere to change that. So the choice isn't between "blanket default" and "no blanket default" — it's between a blanket default the user chose and one they didn't.

Doing it outside the app isn't possible either: T3 passes --permission-mode explicitly when it launches the Claude CLI, and that flag outranks permissions.defaultMode in ~/.claude/settings.json.

If one global value feels too blunt, a per-project default with a global fallback would solve the same problem and would match how the app already remembers a default model selection per project. #6508 is asking for roughly that shape. I'd be happy with either.

For context on why I care: this runs on a machine with cloud credentials, kubectl contexts pointing at production and push access to our repos. Full access skips the classifier and the sandbox, so a bad command or an injected one from a web page or an issue body executes with no confirmation. I'd rather opt into that per thread than out of it every time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: store preference setting for permission mode

6 participants

@JustMarkDev@juliusmarminge@benglewis@t3dotgg@hillerstorm@elmarbeckmann