refactor(headless): extract permission-intervention decision engine from task-agent-controller.ts
#1,410 opened on Jul 23, 2026
Repository metrics
- Stars
- (1 star)
- PR merge metrics
- (PR metrics pending)
Description
Part of #1084 (second-pass sink-file and boundary governance). Scope re-verified against current main (task-agent-controller.ts, 1744 lines).
Scope
Move handlePermissionIntervention (~L956, incl. the fail_closed/park branches, post-hoc grant matching, and inbox/approval event writes), PermissionInterventionInput (~L936), PermissionInterventionResult (~L952), and DEFAULT_INTERVENTION_POLICY (~L847) into permission-intervention.ts beside the existing permission-grants.ts. The controller keeps only the two call sites (~L402 main path, ~L514 repair path).
Invariants
Same as #1084: behavior-neutral; stable exports; no reverse imports; flat PR off main.
Verification
Typecheck/build + task-agent-controller tests.