Add an opt-in toggle (require_admin_for_exec_approval, default false) that restricts who can click Approve/Deny on a dangerous-command prompt to admins listed in allow_admin_from. Off by default, so the v0.16-restored user-scope behavior is unchanged. When on, the clicker must pass the normal admission check AND be an admin; fails closed (logged) when no admins are configured. Only ExecApprovalView is gated — model picker / clarify / update-prompt stay user-scope. |
||
|---|---|---|
| .. | ||
| features | ||
| messaging | ||
| secrets | ||
| skills | ||
| _category_.json | ||
| checkpoints-and-rollback.md | ||
| cli.md | ||
| configuration.md | ||
| configuring-models.md | ||
| desktop.md | ||
| docker.md | ||
| git-worktrees.md | ||
| managed-scope.md | ||
| multi-profile-gateways.md | ||
| profile-distributions.md | ||
| profiles.md | ||
| security.md | ||
| sessions.md | ||
| tui.md | ||
| windows-native.md | ||
| windows-wsl-quickstart.md | ||