mirror of
https://github.com/RooVetGit/Roo-Code.git
synced 2026-09-05 08:10:14 +00:00
fix: prevent command auto-approval bypass with queued messages
When there are queued messages and a command/tool execution ask comes up, the system now checks if auto-approval is enabled before executing commands. If auto-approval is disabled, commands are rejected to prevent unauthorized execution. This fixes a critical security vulnerability where commands could be executed without user consent when messages were queued. Fixes #9720
This commit is contained in:
parent
be7659461a
commit
88f3f106e1
1 changed files with 10 additions and 3 deletions
|
|
@ -1087,9 +1087,16 @@ export class Task extends EventEmitter<TaskEvents> implements TaskLike {
|
|||
type === "browser_action_launch" ||
|
||||
type === "use_mcp_server"
|
||||
) {
|
||||
// For tool approvals, we need to approve first, then send
|
||||
// the message if there's text/images.
|
||||
this.handleWebviewAskResponse("yesButtonClicked", message.text, message.images)
|
||||
// For tool approvals, check if auto-approval is enabled
|
||||
// If auto-approval is disabled (approval.decision === "ask"), reject the command
|
||||
// to prevent unauthorized execution, then send the queued message
|
||||
if (approval.decision === "ask") {
|
||||
// Reject the command/tool execution to prevent bypass
|
||||
this.handleWebviewAskResponse("noButtonClicked", message.text, message.images)
|
||||
} else {
|
||||
// Only approve if auto-approval is enabled
|
||||
this.handleWebviewAskResponse("yesButtonClicked", message.text, message.images)
|
||||
}
|
||||
} else {
|
||||
// For other ask types (like followup or command_output), fulfill the ask
|
||||
// directly.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue