Skip to content

fix(sync): confirm destructive watch actions - #835

Merged
ctawiah merged 2 commits into
mainfrom
ctawiah/AIC-3487/confirm-destructive-watch-actions
Oct 7, 2026
Merged

ctawiah merged 2 commits into
mainfrom
ctawiah/AIC-3487/confirm-destructive-watch-actions

Conversation

@ctawiah

@ctawiah ctawiah commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Context

Watch mode currently treats every filesystem-triggered sync as pre-approved. That is convenient for routine edits, but it also allows a local deletion to archive a LaunchDarkly variation, or a server deletion to remove a local file, without confirmation.

What changes

  • Continue applying create and update actions automatically in watch mode.
  • Ask for confirmation before archive or local-delete actions.
  • Preserve --watch --yes as the explicit non-interactive opt-in.
  • Reject unconfirmed destructive actions when no terminal is available.

For example:

Action: Archive the variation in LaunchDarkly

Sync these changes? [y/N]

Verification

  • go test ./internal/sync/prompt
  • go test ./...
  • git diff --check

Related changes

Review the stack in this order:

  1. Confirm destructive watch actions
  2. Guarantee prompt fingerprint convergence
  3. Add searchable attachment API foundations
  4. Reconcile variation attachments
  5. Attach tools and skills to variations
  6. Render attachment-aware review output
  7. Safely clean unreferenced attachments
  8. Persist sync manifests in LaunchDarkly

Note

Overview
Watch mode no longer auto-applies every sync. Create/update plans still apply without a prompt when --watch is on, but archive and local delete actions now require the same interactive confirmation (or explicit --yes) as a normal sync.

Adds Plan.HasDestructiveActions() to detect those actions. reviewAndConfirmPlan uses it so watch only auto-applies non-destructive work; destructive plans show Sync these changes? [y/N] unless --yes is set. Confirmation runs through confirmApplyWithContext so a cancelled watch context (e.g. interrupt) aborts a blocking prompt instead of hanging.

Watch sync options are built via optionsForWatchSync, which still clears one-shot flags like --add/--link but stops forcing Yes: true, so --watch --yes remains the non-interactive opt-in for destructive changes.

Reviewed by Cursor Bugbot for commit 5cf69d7. Bugbot is set up for automated code reviews on this repo. Configure here.

@ctawiah
ctawiah force-pushed the ctawiah/AIC-3487/confirm-destructive-watch-actions branch from 7b70b69 to 4923245 Compare September 30, 2026 15:26
@ctawiah
ctawiah marked this pull request as ready for review September 30, 2026 18:56
@ctawiah
ctawiah requested a review from a team as a code owner September 30, 2026 18:56

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4923245. Configure here.

Comment thread internal/sync/prompt/terminal.go
@ctawiah
ctawiah force-pushed the ctawiah/AIC-3487/confirm-destructive-watch-actions branch from 7046994 to 5cf69d7 Compare October 7, 2026 15:41
@ctawiah
ctawiah merged commit 6b2fb00 into main Oct 7, 2026
10 checks passed
@ctawiah
ctawiah deleted the ctawiah/AIC-3487/confirm-destructive-watch-actions branch October 7, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants