A config_mutation/destructive run() queued for approval never touched agent_sessions.status — only ask_operator did that, setting awaiting_input. So a task blocked on an execution approval was indistinguishable from one still genuinely working: the frontend's "Needs input" bucket only checks status===awaiting_input (never lit up for these), and the idle-sweep safety net only excludes awaiting_input from its stale-task query, so after ~30 minutes idle it would nudge the agent and then auto-close the task with outcome=partial while the approval was still sitting there undecided. classifyAndGate now flips the session into awaiting_input the moment an execution is queued (internal/mcp/server.go), and DecideApproval flips it back to executing once the approval is approved, denied, or revoked (internal/httpapi/approvals.go) — mirroring askOperator / answerQuestion's existing pattern for session_questions. Both emit task.status so the board updates live. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
10 KiB
10 KiB