From 6a268abbb90f1a2824b71c3bd590543d35f26c63 Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Fri, 3 Jul 2026 18:57:19 -0700 Subject: [PATCH] =?UTF-8?q?nvrsion:=20Add=20re-sync=20from=20dev=20for=20V?= =?UTF-8?q?ERSION=20and=20adjust=20Appcast=20releases;=20fix=20permission?= =?UTF-8?q?=20flow=20by=20removing=20the=20=E2=80=9Callow=20always?= =?UTF-8?q?=E2=80=9D=20button=20from=20approval=20views=20and=20docs;=20fi?= =?UTF-8?q?x=20build=20script=20error=20by=20removing=20obsolete=20sh=20de?= =?UTF-8?q?pendency=20from=20Makefile.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nucleic-Promote: 1 Co-authored-by: Nucleic --- NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift b/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift index 9d73d91..76edfbf 100644 --- a/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift +++ b/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift @@ -76,7 +76,10 @@ struct ApprovalCardView: View { .disabled(!allowEnabled) } - if !store.capabilities.allowAlwaysScopes.isEmpty { + // A destructive action (rm, force-push, reset --hard, …) offers no remembered + // allow: every one must be a deliberate, one-off approval, never granted in a + // way that lets the next one through unseen. Mirrors the Mac. + if approval.risk != .destructive, !store.capabilities.allowAlwaysScopes.isEmpty { Menu("Allow always…") { ForEach(store.capabilities.allowAlwaysScopes, id: \.self) { scope in Button(alwaysLabel(scope)) {