Multi-file V4A proposals set EditProposal.path to a comma-joined display
string, and should_auto_approve_edit evaluated it as one path: the
sensitive-name check saw only the last segment and the workspace check
resolved the joined string under the session cwd. A patch touching .env
plus a normal file auto-approved under 'session', and one carrying an
absolute path outside the workspace auto-approved under
'workspace_session' — both without the interactive prompt.
EditProposal now carries a paths tuple with every real target; the
sensitive check runs any() and the workspace check all() across them,
falling back to (path,) for single-file proposals. The joined string
remains for display only.
Fixes#115213