gemini-cli icon indicating copy to clipboard operation
gemini-cli copied to clipboard

feat: Persistent "Always Allow" policies with granular shell & MCP support

Open allenhutchison opened this issue 2 weeks ago • 2 comments

Description

This PR introduces the ability for users to persist "Always Allow" decisions for tools, streamlining the user experience by reducing repetitive confirmations. It includes granular control for shell commands and full support for MCP tools.

Changes

  • "Always Allow" Persistence: Users can now choose to always allow a tool execution, which saves a policy to the configuration.
  • Granular Shell Control: Added commandPrefix and argsPattern to policy configuration. This allows users to whitelist specific shell commands (e.g., git status) without granting blanket access to the shell tool.
  • MCP Tool Support: Implemented mcpName in policy configuration to distinguish tools from different MCP servers.
  • UI Enhancements: Updated the ToolConfirmationMessage UI to include the "Always allow" option.
  • Testing: Added new tests in packages/core/src/policy/persistence.test.ts to verify policy persistence and matching logic.

Commits

  • feat: implement always allow and save to policy option
  • feat: Add commandPrefix and argsPattern to policies for granular tool control and persistence.
  • feat: implement mcpName in policy updates and configuration for multi-cloud platform tools.

Fixes: #14421

allenhutchison avatar Dec 08 '25 20:12 allenhutchison

Summary of Changes

Hello @allenhutchison, I'm Gemini Code Assist[^1]! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the tool interaction experience by introducing persistent 'Always Allow' policies. It allows users to save their approval decisions, reducing friction for frequently used tools. The changes also bring granular control over shell commands and full support for Multi-Cloud Platform tools, ensuring that policy management is both flexible and robust.

Highlights

  • Always Allow Policy Persistence: Users can now choose to persist 'Always Allow' decisions for tools, saving these policies to the configuration to avoid repetitive confirmations.
  • Granular Shell Control: Policy configurations now support commandPrefix and argsPattern, enabling users to whitelist specific shell commands (e.g., 'git status') without granting broad access.
  • Multi-Cloud Platform (MCP) Tool Support: The policy configuration has been extended with mcpName to correctly distinguish and manage tools originating from different MCP servers.
  • UI Enhancements: The ToolConfirmationMessage UI has been updated to include the new 'Always allow and save to policy' option, providing a clear user choice for persistence.
  • New Policy Persistence Tests: New tests have been added in packages/core/src/policy/persistence.test.ts to thoroughly verify the functionality of policy persistence and its matching logic.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with :thumbsup: and :thumbsdown: on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

[^1]: Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

gemini-code-assist[bot] avatar Dec 08 '25 20:12 gemini-code-assist[bot]

Size Change: +5.1 kB (+0.02%)

Total Size: 21.6 MB

Filename Size Change
./bundle/gemini.js 21.6 MB +5.1 kB (+0.02%)
ℹ️ View Unchanged
Filename Size
./bundle/sandbox-macos-permissive-closed.sb 1.03 kB
./bundle/sandbox-macos-permissive-open.sb 890 B
./bundle/sandbox-macos-permissive-proxied.sb 1.31 kB
./bundle/sandbox-macos-restrictive-closed.sb 3.29 kB
./bundle/sandbox-macos-restrictive-open.sb 3.36 kB
./bundle/sandbox-macos-restrictive-proxied.sb 3.56 kB

compressed-size-action

github-actions[bot] avatar Dec 08 '25 20:12 github-actions[bot]