Skip to main content
ComponentsOverlays

Component · Overlays

Permission Prompt

Fail-safe permission/trust surface with default-deny focus.

Kind
widget
Input
interactive
Canvas
120×40

Live preview

Loading terminal preview.

Static terminal poster. Choose Run live to start the Rust demo.

Ghosttypermission-prompt/basic
Loading terminal poster…
○ loading posterNo input — rendered state only
Permission Prompt · exact mounted Rust story

01 · Purpose

What it is for

Fail-safe permission/trust surface with default-deny focus.

Best fit: Overlays · overlay · widget

02 · Behavior

What the mounted story proves

  1. 01

    PermissionPrompt

    Representative 120×40 terminal state.

  2. 02

    Passive paint

    No keyboard or pointer action is claimed by this representative story.

  3. 03

    Evidence stays explicit

    6 covered · 8 partial · 4 missing axes.

03 · Implement

Install, then start from exact code

Install

cargo add termrock --git https://github.com/tailrocks/termrock.git --rev 5283c2acf9154d0cfcd37b1ffe821c00faf90ea2

Add TermRock once. Keep domain effects in the host application.

Minimal implementation

Exact Rust setup used by permission-prompt/basic.

Open to load code.

04 · Adapt

Variants and composition

Variants

Use the preview Variant menu when alternate registered stories exist. Each selection mounts a fresh configuration.

Composition

Overlays · overlay · widget

05 · Reference

API, tokens, accessibility

API

PermissionPromptOpen source ↗

Tokens

DesignSystemInspect exact story code for roles and capability projection.

Accessibility

Input contract mountedNo input claim in the representative story.

Contract

Evidence in progress6/23 axes covered

06 · Go deeper

Advanced guidance

Authored implementation guidance

Trust chrome keeps a muted focus-visible frame while a semantic severity rail carries risk; approval choices use the shared action-chip vocabulary.

Not a generic Allow dialog. Checklist paint: who (leaf initiator), via provenance, op + target, run @ location, access/dest, reversible, risk banners, expected result, grant scope once/session/project/always.

When to use / when not

Use PermissionPromptPrefer
Shell / file / network / MCP gates—
Product settings togglesForm / Switch
Agent prompt inputPromptComposer

Checklist fields

Initiator · provenance · action kind · target · location · accessed data · destination · expected · reversible · risk · scope · prior grant · command/pattern

Focus law

ConcernOwner
Overlay trap (High/Critical)OverlayStack AlertDialog
Surface inputHost set_accepts_input when overlay top
Action cursoraction_cursor (default Deny)
Scope cursorscope via [ ] → Allow once…always

Scene surface focus ≠ decision cursor.

Outcomes

  • Ignored
  • ActionCursorMoved / ScopeChanged
  • DetailsToggled / EditStarted / EditChanged / EditCancelled
  • Decided { request_id, generation, action, scope, edited }
  • Cancelled / QueueChanged / StaleIgnored

Intents / keys

default_permission_intent — arrows/Tab, Enter, Esc, d details. No y grant. n deny · e/p edit · [/] scope.

Safety

  • Default cursor Deny for all risks
  • Enter default → Deny, never Allow
  • Esc → cancel without grant + advance queue
  • Stale generation → StaleIgnored (no grant)
  • Concurrent queue FIFO + monotonic generations
Ownership boundary

TermRock owns reusable terminal rendering and interaction state. The host owns domain data, policy, persistence, authorization, and side effects.

Evidence status

6 covered, 8 partial, and 4 missing contract axes. Missing evidence is not a behavior claim.