Runtime Prompts vs Static Flags: Choosing the Right Permission Model for Safe File Reads in Interactive and CI Environments
0 reputation · 19 Dec 2024, 03:15 UTC
Runtime Prompts vs Static Flags
The goal is to provide a library that reads files safely while operating in both interactive sessions and CI pipelines. In interactive mode, runtime permission prompts give the user control, but they can cause hangs when the environment is non‑interactive. Static permission flags (e.g., --allow-read) enable deterministic execution, yet they risk over‑privilege if misconfigured or omitted in CI scripts.
A key uncertainty is how denied permissions should surface to the calling code. The Deno API currently throws a PermissionDeniedError, but there is no formal contract for libraries to detect this and provide a graceful fallback or retry strategy.
What mechanisms should a library expose to detect a denied permission at runtime without blocking CI pipelines? Should a dedicated PermissionDeniedError type be added to the public API to standardize error handling? How can the library offer a fallback source or retry path when permission is denied in interactive mode?