Wave 0 + Wave 1 core of the transparent agentic-client integration: a
developer types prompts normally in Claude Code / Codex while every
certified turn still carries a full H1->H7 trace and an H6 record.
- agentic_bridge.py: stdlib-only lifecycle state machine (begin/pre-tool/
post-tool/telemetry/finalize/abort + report/doctor). Single-model
invariant (never calls a model), fail-closed at the side-effect point,
admission TTL + canonical-project/session binding, atomic state under
.specify/state/agentic-sessions/, secret redaction, null-not-zero H6.
- agentic-lifecycle.schema.json: client-agnostic JSON contract.
- adapters/claude-code + adapters/codex: thin hook renderers + config
templates that call the core bridge.
- phase-agentic-bridge-tests.sh: C1-C12 acceptance + threat suite (30/30).
- devkit templates/{claude,codex} + windows/install-agentic.ps1
(install/doctor/uninstall with manifest, path-safe).
- docs/casan Windows + security/bypass guides; plan status -> IMPLEMENTED.
- harden generate-agentops-dashboard.py aggregation against null H6 costs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
19 lines
769 B
TOML
19 lines
769 B
TOML
# CASAN Plan-20 Codex config fragment (.codex/config.toml).
|
|
# Merge these keys into the target repo's .codex/config.toml. This enables the
|
|
# project hooks in hooks.template.json after Codex trust review.
|
|
#
|
|
# For ENTERPRISE enforcement, the managed policy path pins hooks so a member
|
|
# cannot disable them (Spike-20 §4.2, Plan-20 Wave 3.3). In that deployment set
|
|
# CASAN_AGENTIC_INTEGRATION_MODE=managed_hook via managed environment/MDM, not
|
|
# in this committed file.
|
|
|
|
[hooks]
|
|
enabled = true
|
|
# project-local hooks load only after the user accepts the trust prompt.
|
|
project_hooks = true
|
|
|
|
[casan]
|
|
# Bridge feature flags — safe defaults (observe first, then enforce per Plan-20 §9).
|
|
enforcement_mode = "observe" # observe | enforce
|
|
integration_mode = "project_hook"
|