Skip to content
FunCoding

Search

Search docs, Skills and MCP

权限配置档

用 permission profiles 组合文件系统与网络规则,并从旧 sandbox 设置迁移。

This page has not been translated into English yet. The original Chinese version is shown below.

Permission profiles 为本地沙箱命令提供可复用的文件和网络权限,目前处于 beta。它与用于选择模型等设置的配置档是不同概念。

选择起点

内置 profile行为
:read-only本地命令保持只读
:workspace允许写入有效工作区和系统临时目录
:danger-full-access移除本地沙箱限制

用顶层 default_permissions 选择内置或自定义 profile。自定义配置建议 extends 内置只读或工作区配置,以保留其基线保护;例如继承 :workspace 会保留工作区 .codex 目录只读,除非显式覆盖。

default_permissions = "project-edit"

[permissions.project-edit]
description = "Workspace editing with project-specific restrictions."
extends = ":workspace"

可以继承其他命名 profile,但不能继承 :danger-full-access;未知父配置和循环继承会被拒绝。description 不从父配置继承。同名 profile 的条目仍按普通配置层优先级组合。

与旧配置的关系

不要同时配置 default_permissions / permissions 和 sandbox_mode / sandbox_workspace_write。任一已加载文件、选中的配置档或 --sandbox 参数包含旧 sandbox_mode 时,会使用旧设置而非 default_permissions。

受管 allowed_permission_profiles 是例外,它会要求使用 profiles。部署受管允许列表前移除旧沙箱设置;混合版本企业可暂保留 allowed_sandbox_modes 作为兼容约束,直到全部升级至 0.138.0 或更高。

继续配置

In this section