FeatureFuel
0

Clarify whether session tool grants expand to participants added later

Source: n8n-io/n8n#40071 · opened by @Nakagawa-master
PR #39560 merged session-scoped Agent tool approvals today. One authorization-scope boundary from the review thread still appears unresolved in the merged storage contract. The grant table is keyed only by: and the approval context reloads grants by thread identity. There is no approval-time participant-set identity / authorization revision in the persisted grant. That means the product currently needs an explicit answer to this question: The distinction matters for shared/project-scoped conversations. Concrete scenario: If A is the intended contract, the approval UI/docs should say that future participants who later gain access to the same conversation inherit the grant. A regression should pin that widening explicitly. If B is intended, the persisted grant needs to be bound to an authorization-scope revision / participant-set identity, or invalidated when the eligible actor set broadens. This is separate from: • parent/child thread isolation; • grantKey too…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests