Done — approvals now render as interactive picker buttons, reusing the existing clarify/choice-picker mechanism.
Change (gateway-side only, gateway-plugin/adapter.py): added send_exec_approval(). Hermes auto-detects this method on the adapter and calls it when the agent wants to run a dangerous command. It now emits:
a high-priority approval notification (wakes a backgrounded device), and
a picker.choice card showing the command (code block) + reason, with buttons ✅ Allow Once / ✅ Allow Session / ✅ Always Allow / ❌ Deny (gated by the same allow_session/allow_permanent/smart_denied flags the Telegram/relay adapters use).
A tap resolves via resolve_gateway_approval() (the same primitive the text /approve//deny handlers use), unblocking the agent, and posts a short confirmation. No live device → reports failure so hermes falls back to the text prompt (unchanged).
No app changes needed — picker.choice cards are rendered generically.
Verified live on the phone (had to set approvals.mode: manual temporarily, since the default smart mode auto-approves low-risk commands via the aux LLM). 4 new tests added to test_android.py; full file passes 98/98.
Done — approvals now render as interactive picker buttons, reusing the existing clarify/choice-picker mechanism.
**Change** (gateway-side only, `gateway-plugin/adapter.py`): added `send_exec_approval()`. Hermes auto-detects this method on the adapter and calls it when the agent wants to run a dangerous command. It now emits:
- a high-priority `approval` notification (wakes a backgrounded device), and
- a `picker.choice` card showing the command (code block) + reason, with buttons **✅ Allow Once / ✅ Allow Session / ✅ Always Allow / ❌ Deny** (gated by the same `allow_session`/`allow_permanent`/`smart_denied` flags the Telegram/relay adapters use).
A tap resolves via `resolve_gateway_approval()` (the same primitive the text `/approve`/`/deny` handlers use), unblocking the agent, and posts a short confirmation. No live device → reports failure so hermes falls back to the text prompt (unchanged).
**No app changes needed** — `picker.choice` cards are rendered generically.
**Verified live** on the phone (had to set `approvals.mode: manual` temporarily, since the default `smart` mode auto-approves low-risk commands via the aux LLM). 4 new tests added to `test_android.py`; full file passes 98/98.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
We already have clarify and choice picker. But it's not used for approvals right now.
Done — approvals now render as interactive picker buttons, reusing the existing clarify/choice-picker mechanism.
Change (gateway-side only,
gateway-plugin/adapter.py): addedsend_exec_approval(). Hermes auto-detects this method on the adapter and calls it when the agent wants to run a dangerous command. It now emits:approvalnotification (wakes a backgrounded device), andpicker.choicecard showing the command (code block) + reason, with buttons ✅ Allow Once / ✅ Allow Session / ✅ Always Allow / ❌ Deny (gated by the sameallow_session/allow_permanent/smart_deniedflags the Telegram/relay adapters use).A tap resolves via
resolve_gateway_approval()(the same primitive the text/approve//denyhandlers use), unblocking the agent, and posts a short confirmation. No live device → reports failure so hermes falls back to the text prompt (unchanged).No app changes needed —
picker.choicecards are rendered generically.Verified live on the phone (had to set
approvals.mode: manualtemporarily, since the defaultsmartmode auto-approves low-risk commands via the aux LLM). 4 new tests added totest_android.py; full file passes 98/98.