A remote host's permission rules only count when you're in auto mode and the tool isn't ask-first.
What's wrong with this entry?
On receiving a needs_approval answer from a remote host, the session checks its own permission mode before letting the host's rules count. The host's allow, soft-deny, hard-deny and environment lines are forwarded to the decision prompt only when the local mode is auto, the host marked the call eligible, and the tool is not in ask-first mode.
- Each forwarded rule line is trimmed and empty entries dropped.
- An approval made by the automatic classifier rather than a person is now tracked as such and carried into the recovery path for dropped or timed-out calls.
classifierEligible: nn,
Strings lifted out of the shipped bundle, so the claim above can be checked against them.