In plan mode, artifact page reads and publishes always need you to approve them yourself.
What's wrong with this entry?
The first artifact page-data read and any artifact publish made from plan mode can no longer be approved automatically, and approval granted in plan mode is stored as a distinct human approval rather than reused as a generic session grant.
- Both call paths are marked as not approvable by the auto-permission classifier.
- A hidden input key records that the request originated in plan mode, so the session-wide approval is persisted separately as a human approval.
- When plan mode has no usable consent surface, publish is denied outright; the page-data read still asks, with an explanation that nobody is present to answer it.
Plan-mode publish egress requires a live human consent surface
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.