src/vs/platform/agentHost/common/agentHostResourceService.ts

168 LOC · 163 covered · 5 uncovered · 2 ranges · 58 concepts · 1 introducers · 33 tests

File neighbourhood

The centred file is linked to every concept that introduces one of its ranges, every test that runs code from the file, and the gray connector concepts standing between those tests and the file's own introducer concepts. Undirected links join concepts to every file where they introduce source and concepts to the tests they introduce; arrows show specialization between the displayed concepts and bridge only concepts omitted from this view. Concept colors match the source ranges below; connector concepts have no source color and are shown in gray.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the file

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the related-file, concept, and source links on this page.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the filesrc/vs/editor/common/services/resolverService.ts · 90 LOCservices/resolverService…src/vs/workbench/services/agentHost/common/agentHostResourceService.ts · 519 LOCcommon/agentHostResource…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways covers immediate retry without waiting for the settings write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 5 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 3 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allow for write also covers read on the same URI|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allow grants in-memory until connection closes|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways persists the grant|occurrence=1, agentHostResourceService.test|title=AgentHostResourceService allowAlways defaults to APPLICATION scope when no value is configured anywhere|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allow for read does not grant write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×3 · 3 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService request with both read and write prompts sequentially|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×8 · 22 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService write request that already has read grant still prompts for write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×3 · 6 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 2 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService request resolves immediately when already granted|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 3 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 3 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×3 · 13 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService grants for one host do not leak into another host|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService persisted "r" allows read, denies write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways skips persistence when covered by parent grant|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService persisted "rw" allows read and write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 5 introduced LOCagentHostResourceService…agentHostResourceService.ts ×3 · 18 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService… prefix|occurrence=1 · 0 introduced LOC prefix|occurrence=1agentHostResourceService.ts ×1 · 3 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check rejects path traversal via .. segments|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService connectionClosed drops implicit grants|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService implicit read grant covers descendants but not parent or sibling|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×5 · 7 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService grantImplicitRead asynchronously upgrades to realpath|occurrence=1, agentHostResourceService.test|title=AgentHostResourceService check canonicalizes via realpath so symlink to outside the grant is denied|occurrence=1, +1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 1 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 7 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 4 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService implicit grant does not allow write|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×4 · 9 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 13 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check denies when no grant exists|occurrence=1 · 0 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×2 · 5 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 2 introduced LOCagentHostResourceService…agentHostResourceService.ts ×1 · 4 introduced LOCagentHostResourceService…agentHostResourceService.ts ×28 · 436 introduced LOCagentHostResourceService… prefix|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService address normalization strips ws:// prefix|occurrence=1 prefix|occurrence=1agentHostResourceService.test|title=AgentHostResourceService allow for read does not grant write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allow for read does not grant write|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allow for write also covers read on the same URI|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allow for write also covers read on the same URI|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allow grants in-memory until connection closes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allow grants in-memory until connection closes|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways covers immediate retry without waiting for the settings write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways covers immediate retry without waiting for the settings write|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways defaults to APPLICATION scope when no value is configured anywhere|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways defaults to APPLICATION scope when no value is configured anywhere|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways for write persists rw|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways for write persists rw|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways merges with existing APPLICATION-scoped grants instead of overwriting them|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways merges with existing APPLICATION-scoped grants instead of overwriting them|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways persists into USER_LOCAL when a pre-existing value is in USER_LOCAL|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways persists into USER_LOCAL when a pre-existing value is in USER_LOCAL|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways persists the grant|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways persists the grant|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService allowAlways skips persistence when covered by parent grant|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService allowAlways skips persistence when covered by parent grant|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check canonicalizes nonexistent paths via the parent realpath|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService check canonicalizes nonexistent paths via the parent realpath|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check canonicalizes via realpath so symlink to outside the grant is denied|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService check canonicalizes via realpath so symlink to outside the grant is denied|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check denies when no grant exists|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService check denies when no grant exists|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService check rejects path traversal via .. segments|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService check rejects path traversal via .. segments|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService concurrent identical requests share one pending entry|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService concurrent identical requests share one pending entry|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService connectionClosed drops implicit grants|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService connectionClosed drops implicit grants|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService connectionClosed only affects the named address|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService connectionClosed only affects the named address|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService connectionClosed rejects pending and clears the queue|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService connectionClosed rejects pending and clears the queue|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService findPending returns the pending request by id|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService findPending returns the pending request by id|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService grantImplicitRead asynchronously upgrades to realpath|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService grantImplicitRead asynchronously upgrades to realpath|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService grants for one host do not leak into another host|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService grants for one host do not leak into another host|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService implicit grant does not allow write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService implicit grant does not allow write|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService implicit grant for a symlinked directory still covers descendants resolved through the symlink|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService implicit grant for a symlinked directory still covers descendants resolved through the symlink|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService implicit read grant covers descendants but not parent or sibling|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService implicit read grant covers descendants but not parent or sibling|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService pendingFor returns only this host's requests, with normalized address|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService pendingFor returns only this host's requests, with normalized address|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService persisted "r" allows read, denies write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService persisted "r" allows read, denies write|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService persisted "rw" allows read and write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService persisted "rw" allows read and write|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService persisted entries with malformed URI keys or unknown modes are ignored|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService persisted entries with malformed URI keys or unknown modes are ignored|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService request rejects with CancellationError on deny|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService request rejects with CancellationError on deny|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService request resolves immediately when already granted|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService request resolves immediately when already granted|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService request with both read and write prompts sequentially|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService request with both read and write prompts sequentially|occurrence=1agentHostResourceService…agentHostResourceService.test|title=AgentHostResourceService write request that already has read grant still prompts for write|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/workbench/services/agentHost/test/common/agentHostResourceService.test|title=AgentHostResourceService write request that already has read grant still prompts for write|occurrence=1agentHostResourceService…Focused file · src/vs/platform/agentHost/common/agentHostResourceService.ts · 168 LOCcommon/agentHostResource…

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the related-file, concept, and source links on this page while the interactive map is unavailable.

1 > /*--------------------------------------------------------------------------------------------- agentHostResourceService.ts ×28
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > import { VSBuffer } from '../../../base/common/buffer.js';
7 > import { IDisposable } from '../../../base/common/lifecycle.js';
8 > import { IObservable } from '../../../base/common/observable.js';
9 > import { URI } from '../../../base/common/uri.js';
10 > import { createDecorator } from '../../instantiation/common/instantiation.js';
11 > import {
12 > DirectoryEntry,
13 > ResourceCopyParams, ResourceDeleteParams, ResourceMkdirParams, ResourceMoveParams,
14 > ResourceRequestParams, ResourceResolveParams, ResourceResolveResult, ResourceWriteParams,
15 > } from './state/protocol/commands.js';
16 >
17 > /**
18 > * Stable sentinel address used for the in-process local agent host. Keyed
19 > * persisted grants in user settings live under this name so that "Always
20 > * allow" survives window reloads.
21 > */
22 > export const LOCAL_AGENT_HOST_ADDRESS = 'local';
23 >
24 > /** Configuration key for persisted per-host filesystem grants. */
25 > export const AgentHostLocalFilePermissionsSettingId = 'chat.agentHost.localFilePermissions';
26 >
27 > /** Persisted access mode for a granted URI. */
28 > export const enum AgentHostAccessMode {
29 > Read = 'r',
30 > ReadWrite = 'rw',
31 > }
32 >
33 > /**
34 > * Persisted shape of {@link AgentHostLocalFilePermissionsSettingId}:
35 > * `{ [normalizedAddress]: { [uriString]: 'r' | 'rw' } }`.
36 > */
37 > export type AgentHostPermissionsSetting = Record<string, Record<string, AgentHostAccessMode>>;
38 >
39 > /**
40 > * Capability a request needs from the user. The protocol-level `read` and
41 > * `write` flags are split into one or two of these requests.
42 > */
43 > export const enum AgentHostPermissionMode {
44 > Read = 'read',
45 > Write = 'write',
46 > }
47 >
48 > /** A single pending permission request awaiting user input. */
49 > export interface IPendingResourceRequest {
50 > readonly id: string;
51 > readonly address: string;
52 > readonly uri: URI;
53 > readonly mode: AgentHostPermissionMode;
54 > /** Approve and remember the grant in user settings. */
55 > allowAlways(): void;
56 > /**
57 > * Approve the request and remember it in memory for the lifetime of the
58 > * connection (cleared on connection close or window reload).
59 > */
60 > allow(): void;
61 > /** Reject this request. */
62 > deny(): void;
63 > }
64 >
65 > /**
66 > * Thrown by gated FS operations on {@link IAgentHostResourceService} when
67 > * the calling address lacks the required permission. Carries the
68 > * {@link ResourceRequestParams} that, if approved, would unlock the
69 > * operation, so wire adapters can echo it back to the agent host inside a
70 > * `PermissionDenied` frame and let the host run the standard
71 > * `resourceRequest` → retry loop.
72 > */
73 > export class AgentHostResourcePermissionError extends Error {
74 > constructor(public readonly request: ResourceRequestParams | undefined) {
75 super(request
76 ? `Access to ${request.uri} is not granted.`
77 : 'Access to the requested resource is not granted.');
78 this.name = 'AgentHostResourcePermissionError';
79 }
81 >
82 > export interface IResourceReadResult {
83 > readonly bytes: VSBuffer;
84 > }
85 >
86 > export interface IResourceListResult {
87 > readonly entries: readonly DirectoryEntry[];
88 > }
89 >
90 > export const IAgentHostResourceService = createDecorator<IAgentHostResourceService>('agentHostResourceService');
91 >
92 > /**
93 > * Single owner of agent-host-facing filesystem operations and the
94 > * permission policy that gates them. Combines what were previously two
95 > * services (`IAgentHostPermissionService` + `IAgentHostVirtualResourceProvider`)
96 > * into one consistent interface used by both the in-process local channel
97 > * and the remote protocol client.
98 > *
99 > * Each FS method is gated by a permission check keyed on `address`: a
100 > * normalized network host for remote agent hosts, or
101 > * {@link LOCAL_AGENT_HOST_ADDRESS} for the local utility-process host.
102 > * Denied operations throw {@link AgentHostResourcePermissionError} carrying
103 > * the {@link ResourceRequestParams} that, if granted, would unlock the
104 > * operation.
105 > *
106 > * Read operations transparently fall back to virtual content (untitled
107 > * documents, notebook cells, ...) when the local file service cannot
108 > * resolve the URI.
109 > */
110 > export interface IAgentHostResourceService {
111 > readonly _serviceBrand: undefined;
112 >
113 > // ---- Gated filesystem operations ---------------------------------------
114 >
115 > list(address: string, uri: URI): Promise<IResourceListResult>;
116 > read(address: string, uri: URI): Promise<IResourceReadResult>;
117 > write(address: string, params: ResourceWriteParams): Promise<void>;
118 > del(address: string, params: ResourceDeleteParams): Promise<void>;
119 > move(address: string, params: ResourceMoveParams): Promise<void>;
120 > copy(address: string, params: ResourceCopyParams): Promise<void>;
121 > resolve(address: string, params: ResourceResolveParams): Promise<ResourceResolveResult>;
122 > mkdir(address: string, params: ResourceMkdirParams): Promise<void>;
123 >
124 > // ---- Permission requests / observables (UI) ----------------------------
125 >
126 > /**
127 > * Returns whether {@link uri} is already granted for {@link mode} on
128 > * {@link address}. Useful as a pre-check before sending data to a host
129 > * that will read it back. The same gating runs implicitly inside every
130 > * FS method on this service.
131 > */
132 > check(address: string, uri: URI, mode: AgentHostPermissionMode): Promise<boolean>;
133 >
134 > /**
135 > * Handle an inbound `resourceRequest` from a host. Resolves once access
136 > * is granted (immediately, if already covered); rejects with a
137 > * `CancellationError` if the user denies or the connection closes.
138 > */
139 > request(address: string, params: ResourceRequestParams): Promise<void>;
140 >
141 > /** Per-address observable of pending requests for UI surfaces. */
142 > pendingFor(address: string): IObservable<readonly IPendingResourceRequest[]>;
143 >
144 > /** Observable of all pending requests across every address. */
145 > readonly allPending: IObservable<readonly IPendingResourceRequest[]>;
146 >
147 > /**
148 > * Find a pending request by id, across all addresses. Returns
149 > * `undefined` once the request has been resolved or rejected.
150 > */
151 > findPending(id: string): IPendingResourceRequest | undefined;
152 >
153 > // ---- Implicit grants and lifecycle -------------------------------------
154 >
155 > /**
156 > * Register an implicit read grant for {@link uri} (and descendants) on
157 > * {@link address}. Used by call sites that are about to send a URI to a
158 > * host and therefore expect that host to read it back. The returned
159 > * disposable revokes the grant.
160 > */
161 > grantImplicitRead(address: string, uri: URI): IDisposable;
162 >
163 > /**
164 > * Notify that the connection at {@link address} has closed. Drops all
165 > * implicit grants and rejects any outstanding pending requests.
166 > */
167 > connectionClosed(address: string): void;
168 > }