Desktop

Project workspace

Project Install, pending executable approvals, and in-app apm.yml edit.

Project workspace

Desktop Project is the repo-scoped surface. It reads apm.yml and uses the same apply loop as the CLI.

Project Install

Labeled Install in the Project header. Same command as ht install: apply with no plugin selector. The sidecar sends POST /v1/apply with plugins: [] at project scope.

Not Library Apply (a named plugin package from its detail view), not profile Switch, not Sync, and not --global.

Pending executable approvals

After apply, profile switch, or Project Install, unapproved hooks, bin/, and self-defined MCP (registry: false) from dependency packages can stay parked. Apply can succeed in that case. Do not treat the live state as fully green.

When the executable trust gate is on and packages were parked, Desktop shows a yellow banner with pill.warn (“yellow”) and Pending executable approvals. The strip is hidden when the gate is off.

Approve and Deny on the strip write project apm.yml grants, then re-apply so the yellow state can clear. A CLI hint (ht approve / ht deny) stays on the strip.

The gate itself is documented on Executable trust.

Settings → Project

Settings → Project reads and edits raw apm.yml in-app (Library Content mono chrome). Save runs existing validateProjectConfig and refuses to write on errors. Open config stays the external-editor escape. There is no form designer and no config.toml fallback.

Project empty-state copy names apm.yml.