docs(approval): _get_approval_config returns the live cache sub-dict

Review follow-up on the #76194 salvage: the readonly swap makes this
function leak the live config-cache 'approvals' sub-dict to callers.
All current callers are read-only (audited); the docstring now carries
the do-not-mutate contract for future ones.
This commit is contained in:
kshitij
2026-08-02 19:45:15 +05:30
parent 48e8254567
commit 024f3e044b

View File

@@ -2601,7 +2601,11 @@ def _normalize_approval_mode(mode) -> str:
def _get_approval_config() -> dict:
"""Read the approvals config block. Returns a dict with 'mode', 'timeout', etc."""
"""Read the approvals config block. Returns a dict with 'mode', 'timeout', etc.
Returns the LIVE config-cache sub-dict (load_config_readonly contract) —
callers must not mutate it or any nested structure.
"""
try:
from hermes_cli.config import load_config_readonly
config = load_config_readonly()