@@ -232,19 +232,28 @@ function recordDecision(
232232}
233233
234234/**
235- * Write a row for a request a newly-minted grant drained without a prompt.
236- * Every other terminal path (accept, Esc, timeout, abort) writes its own row
237- * at its own call site; this one covers the path that has none — reconcile()
238- * settles the queue entry directly, with no accept/cancel/autoDeny callback
239- * to hang a record onto. Without this, the operator's only trace of the
240- * highest-consequence event in the queue (a request that ran without being
241- * shown) is the transient grant-recorded flash, gone once it scrolls off.
235+ * Write a row for a request settled with no accept/cancel/autoDeny call site
236+ * of its own to hang a record onto: reconcile() (a newly-minted grant
237+ * covering this queued request) and drain() (session teardown denying
238+ * whatever is still queued) both settle the queue entry directly. Every
239+ * other terminal path (accept, Esc, timeout, abort) already writes its own
240+ * row at its own call site. Without this, the operator's only trace of the
241+ * highest-consequence event in the queue — a request that ran, or was
242+ * dropped, without ever being shown — is the transient grant-recorded flash
243+ * (nothing at all for teardown), gone once it scrolls off.
242244 */
243- function recordGrantDrain ( shell : AppShell , request : PermissionRequest ) : void {
245+ function recordSilentSettle (
246+ shell : AppShell ,
247+ request : PermissionRequest ,
248+ outcome : ApprovalOutcome ,
249+ ) : void {
244250 const body = middleEllipsis ( permissionBodyFromRequest ( request ) , 500 )
251+ const label = outcome . allow
252+ ? "Auto-approved (already granted)"
253+ : "Denied (session ended)"
245254 appendStreamRow ( shell , {
246255 role : "system" ,
247- text : `${ body } \n→ Auto-approved (already granted) ` ,
256+ text : `${ body } \n→ ${ label } ` ,
248257 meta : "permission" ,
249258 } )
250259}
@@ -388,24 +397,25 @@ export function wireGates(
388397 permissionQueue . settle ( id , outcome )
389398 // Set immediately before every call to settle() from a known call site
390399 // (accept, Esc, autoDeny), each of which writes its own row right after.
391- // reconcile() (src/permission/queue.ts) settles an entry directly, with
392- // no call site of its own — the resolve callback below falls back to
393- // recordGrantDrain whenever this is still false, so a request that ran
394- // without ever being shown still leaves a trace.
400+ // reconcile() and drain() (src/permission/queue.ts) both settle an entry
401+ // directly, with no call site of their own — the resolve callback below
402+ // falls back to recordSilentSettle whenever this is still false, so a
403+ // request that ran, or was dropped, without ever being shown still
404+ // leaves a trace.
395405 let recorded = false
396406 const id = permissionQueue . enqueue ( ev . request , ( outcome ) => {
397407 clearTimers ( )
398408 // Captured before closeInsetOverlay below, which — when this entry is
399409 // the one on screen — reentrantly invokes this same overlay's onCancel
400410 // (see the comment on `settle` above) and would otherwise set
401411 // `recorded` out from under this check before it runs.
402- const needsGrantDrainRecord = ! recorded
412+ const needsSilentSettleRecord = ! recorded
403413 if ( openedGeneration === undefined ) {
404414 unqueue ( open )
405415 } else if ( openedGeneration === overlayGeneration ) {
406416 closeInsetOverlay ( shell )
407417 }
408- if ( needsGrantDrainRecord ) recordGrantDrain ( shell , ev . request )
418+ if ( needsSilentSettleRecord ) recordSilentSettle ( shell , ev . request , outcome )
409419 resolve ( outcome )
410420 } )
411421
0 commit comments