Skip to content

fix(sync): confirm destructive watch actions - #835

Open
ctawiah wants to merge 1 commit into
mainfrom
ctawiah/AIC-3487/confirm-destructive-watch-actions
Open

ctawiah wants to merge 1 commit into
mainfrom
ctawiah/AIC-3487/confirm-destructive-watch-actions

Conversation

@ctawiah

@ctawiah ctawiah commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Context

Watch mode currently treats every filesystem-triggered sync as pre-approved. That is convenient for routine edits, but it also allows a local deletion to archive a LaunchDarkly variation, or a server deletion to remove a local file, without confirmation.

What changes

  • Continue applying create and update actions automatically in watch mode.
  • Ask for confirmation before archive or local-delete actions.
  • Preserve --watch --yes as the explicit non-interactive opt-in.
  • Reject unconfirmed destructive actions when no terminal is available.

For example:

Action: Archive the variation in LaunchDarkly

Sync these changes? [y/N]

Verification

  • go test ./internal/sync/prompt
  • go test ./...
  • git diff --check

Note

Overview
Watch mode no longer auto-applies destructive sync actions (archiving in LaunchDarkly or deleting local files). Routine creates/updates still apply without prompting when --watch is on.

Adds Plan.HasDestructiveActions() and uses it in reviewAndConfirmPlan: watch auto-apply only when the plan has no archive/delete actions. Destructive watch runs prompt "Sync these changes? [y/N]" when a TTY is available; otherwise they fail with the existing rerun with --yes path unless the user passed --watch --yes.

Refactors watch option cloning into optionsForWatchSync, which stops forcing Yes: true on every watcher-triggered sync so --yes remains an explicit opt-in per run.

Reviewed by Cursor Bugbot for commit 4923245. Bugbot is set up for automated code reviews on this repo. Configure here.

@ctawiah
ctawiah force-pushed the ctawiah/AIC-3487/confirm-destructive-watch-actions branch from 7b70b69 to 4923245 Compare September 30, 2026 15:26
@ctawiah
ctawiah marked this pull request as ready for review September 30, 2026 18:56
@ctawiah
ctawiah requested a review from a team as a code owner September 30, 2026 18:56

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4923245. Configure here.

}
if options.Yes || !plan.RequiresConfirmation() {
autoApply := options.Yes || (options.Watch && !plan.HasDestructiveActions())
if autoApply || !plan.RequiresConfirmation() {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Watch confirm ignores cancellation

Medium Severity

Watch mode now routes archive and delete through confirmApply, which blocks on stdin and never observes the watch Context. signal.NotifyContext consumes the first Ctrl+C, so that interrupt neither dismisses the prompt nor exits the watch loop. A later yes still applies the destructive plan.

Additional Locations (1)
Fix in Cursor Fix in Web

Triggered by learned rule: Watch: conflict abort must cancel the watch loop

Reviewed by Cursor Bugbot for commit 4923245. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant