Introduction

DSH uses a plugin-based architecture, and developers often need fine-grained control over model operations on the filesystem. When the model invokes tools such as write, edit, or str_replace_editor, this plugin inserts a confirmation bar in the input area, intercepts file write operations, and ensures changes are manually confirmed before execution.

Core Features

  1. Intercept write operations: Intercepts file writing tools such as write, edit, and str_replace_editor.
  2. Diff preview: A confirmation bar appears in the input area and directly shows diff text with red and green highlights. write displays new content (green), while edit displays line-level comparison (red deletions and green additions).
  3. Allow/deny mechanism: The user clicks “Allow This Time” to allow the operation, or clicks “Deny” to end the tool call as failed; the model can then adjust its strategy accordingly.
  4. Long text support: Long diffs are not truncated, and can be viewed by scrolling within the block.

Installation and Activation

Install it using the official command:

dsh plugin --profile web add dsh-file-confirm

After installation, restart dsh web and refresh the browser.

Configuration

Configure the plugin in cordis.patch.yml to adjust the interception scope:

- insert:
    - id: file-confirm
      name: dsh-file-confirm
      config:
        tools: [write, edit, str_replace_editor]   # 拦截的工具列表
        # pathPattern: '^src/'                     # 可选:仅对匹配路径确认
        # enabled: true

Configuration options:
* tools: By default, intercepts write, edit, and str_replace_editor.
* pathPattern: A regular expression string used to restrict file paths.
* enabled: Master switch.

Working Principle

The plugin leverages DSH’s official extension points and consists of two halves, Host and Browser, to achieve zero-invasive behavior:
* Host half: Listens to tools/pre-execute. For file modification tools, it returns { kind: 'ask', reason }; other tool calls are delegated.
* Browser half: Registers a priority 0 entry in the conversation.composer chain slot. Its selector matches file modification approvals and takes over rendering.
* Response reuse: Reuses the built-in wait.respond encoding, and audit records are written as usual.

Notes

  • Only intercepts file write operations; tool calls such as read, search, and bash are not affected.
  • Approvals for other tools (such as bash sandbox upgrades) still use the DSH built-in panel.
  • Zero-invasive design: it does not modify any built-in packages.

Summary

This plugin focuses on the high-risk process of file writing. Through built-in diff preview and an allow/deny mechanism, it provides DSH with simple, direct file review capability.