Commit d2ae57b
authored
feat(tools): FunctionTool require_confirmation — HITL approval (Part 7) (#594)
* feat(tools): add FunctionTool require_confirmation (human-in-the-loop approval)
Part 7/9 of the feature/workflows split.
- tools/function_tool: a `requireConfirmation` option so a FunctionTool pauses
for human approval before executing.
- agents/processors/request_confirmation_llm_request_processor: handles the
confirmation request/resume round-trip for such tools.
This tool-approval HITL is independent of the workflow engine (it works for any
FunctionTool), so it is a small, self-contained slice.
Tests: tools/function_tool_confirmation_test (5). Full core suite green (2481),
docs:check + tsc clean.
* fix(tools): gate and harden plain-text tool confirmation (PR #594)
Addresses the security/API review on FunctionTool require_confirmation:
- The plain-text confirmation fallback no longer runs on every LlmAgent
invocation. It is now opt-in via a new `RunConfig.plainTextToolConfirmation`
flag (default off), which the interactive `adk run` CLI sets — so on a web/API
surface an ordinary chat message is never silently reinterpreted as a tool-gate
decision. The structured FunctionResponse path is unchanged.
- Harden the fallback itself: resolve only the SINGLE most-recent pending
confirmation (never a broadcast across every unanswered gate), require the
reply to IMMEDIATELY follow the request (no intervening user turn), and treat
unrecognized text as NO decision — the gate stays pending instead of being
silently denied (only explicit negatives deny).
- Extract a `RequireConfirmation<TParameters>` type with a `toolContext` (not
snake_case `tool_context`) parameter, reuse it for both the option and the
field, and export it from common.ts.
- Correct the `requireConfirmation` doc: the HITL gate is enforced on the
LlmAgent path; a workflow ToolNode does not yet route through it (it returns
the "requires confirmation" error as node output rather than pausing).
- Inline the redundant `await` in runAsync and drop the stale comment.
* test(tools): cover the confirmation resume round-trip (PR #594)
- Add end-to-end tests that drive a session event list back through
RequestConfirmationLlmRequestProcessor with a real LlmAgent + real
FunctionTool (no mocks) and assert the original tool is actually re-invoked
with the right decision — the step where an id mismatch on resume would show
up, and the first coverage of the plain-text fallback: opt-in gating,
single-gate binding, unrecognized-text-stays-pending, and no cross-gate
broadcast.
- Replace the `agent: ... as never` fixture with a real LlmAgent instance so it
breaks if InvocationContext's contract changes.1 parent 5334b45 commit d2ae57b
6 files changed
Lines changed: 599 additions & 1 deletion
File tree
- core
- src
- agents
- processors
- tools
- test/tools
- dev/src/cli
Lines changed: 143 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
99 | 99 | | |
100 | 100 | | |
101 | 101 | | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
102 | 119 | | |
103 | 120 | | |
104 | 121 | | |
| |||
190 | 207 | | |
191 | 208 | | |
192 | 209 | | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
193 | 336 | | |
194 | 337 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
99 | 99 | | |
100 | 100 | | |
101 | 101 | | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
102 | 110 | | |
103 | 111 | | |
104 | 112 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
258 | 258 | | |
259 | 259 | | |
260 | 260 | | |
| 261 | + | |
261 | 262 | | |
262 | 263 | | |
263 | 264 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
46 | 58 | | |
47 | 59 | | |
48 | 60 | | |
| |||
57 | 69 | | |
58 | 70 | | |
59 | 71 | | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
60 | 90 | | |
61 | 91 | | |
62 | 92 | | |
| |||
111 | 141 | | |
112 | 142 | | |
113 | 143 | | |
| 144 | + | |
| 145 | + | |
114 | 146 | | |
115 | 147 | | |
116 | 148 | | |
| |||
130 | 162 | | |
131 | 163 | | |
132 | 164 | | |
| 165 | + | |
133 | 166 | | |
134 | 167 | | |
135 | 168 | | |
| |||
157 | 190 | | |
158 | 191 | | |
159 | 192 | | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
160 | 202 | | |
161 | 203 | | |
162 | 204 | | |
| |||
167 | 209 | | |
168 | 210 | | |
169 | 211 | | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
170 | 253 | | |
0 commit comments