| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
Reviewers: 5 | Confidence: 92% | Result: All clear
Reviewed: Correctness, Security Reliability, Test Coverage, Failure Modes, Design Approach
Automated review by westey-m's agents
Sorry, something went wrong.
There was a problem hiding this comment.
This PR makes the .NET HarnessAgent’s file access capability least-privilege by switching FileAccessProvider from default-on (opt-out) to opt-in (enabled only when a FileAccessStore is explicitly provided), and updates the API surface, tests, and samples accordingly.
Changes:
Copilot reviewed 10 out of 10 changed files in this pull request and generated 1 comment.
Show a summary per file| File | Description |
|---|---|
| dotnet/tests/Microsoft.Agents.AI.Harness.UnitTests/HarnessAgentTests.cs | Updates FileAccess provider expectations (absent by default; present when store provided) and adds an options-focused test. |
| dotnet/tests/Microsoft.Agents.AI.Harness.UnitTests/HarnessAgentOptionsTests.cs | Aligns option default/value tests with removal of DisableFileAccess and addition of FileAccessProviderOptions. |
| dotnet/src/Microsoft.Agents.AI.Harness/HarnessAgentOptions.cs | Removes disable flag, documents opt-in behavior, and introduces FileAccessProviderOptions. |
| dotnet/src/Microsoft.Agents.AI.Harness/HarnessAgent.cs | Makes FileAccessProvider opt-in by FileAccessStore presence and passes provider options through. |
| dotnet/samples/02-agents/Harness/Harness_Step05_Loop/Program.cs | Removes redundant DisableFileAccess configuration. |
| dotnet/samples/02-agents/Harness/Harness_Step04_CodeExecution/Program.cs | Explicitly enables file access via FileAccessStore and updates explanatory comments. |
| dotnet/samples/02-agents/Harness/Harness_Step03_DataProcessing/README.md | Updates documentation to reflect opt-in file access and the need to set FileAccessStore. |
| dotnet/samples/02-agents/Harness/Harness_Step03_DataProcessing/Program.cs | Updates comments and explicitly sets FileAccessStore for the sample’s working folder. |
| dotnet/samples/02-agents/Harness/Harness_Step02_Research_WithBackgroundAgents/Program.cs | Removes redundant DisableFileAccess lines since file access is no longer default-on. |
| dotnet/samples/02-agents/Harness/Harness_Step01_Research/Program.cs | Removes redundant DisableFileAccess configuration. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Motivation & Context
The HarnessAgent previously enabled its FileAccessProvider by default (opt-out via HarnessAgentOptions.DisableFileAccess), implicitly rooting a FileSystemAgentFileStore at {cwd}/working unless the caller disabled it. File access grants the agent read/write/delete tools over a working directory, so enabling it implicitly is surprising and violates least-privilege.
As part of preparing the harness for release, file access is now opt-in: it is only wired up when the caller deliberately supplies a FileAccessStore. This mirrors the existing opt-in pattern used for BackgroundAgents (presence of the value enables the provider; no Disable* flag).
Description & Review Guide
What are the major changes?
What is the impact of these changes?
What do you want reviewers to focus on?
Related Issue
Related to #7092 (the issue covers both .NET and Python, so this PR does not close it).
Contribution Checklist