* Python: align GitHub Copilot approval to SDK on_pre_tool_use hook Replace the bespoke on_function_approval enforcement in the GitHub Copilot provider with the Copilot SDK's native on_pre_tool_use hook. When no caller hook is supplied, a default hook returns 'ask' for approval_mode='always_require' tools (routed to on_permission_request) and defers others; a caller-supplied on_pre_tool_use takes precedence and logs a warning for any unenforced approval tool. Fixes #6746 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix type-checker errors and restore load_dotenv in sample Use a complete PreToolUseHookInput in on_pre_tool_use hook tests so pyright/pyrefly/ty/zuban no longer report missing required TypedDict keys. Restore load_dotenv() in the function-approval sample for consistency with the other GitHub Copilot samples (PR review feedback). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Deprecate on_function_approval instead of removing it Per PR review feedback, keep the on_function_approval callback working (still enforced in the tool handler for approval_mode='always_require' tools) but emit a DeprecationWarning at construction, so existing users get a signal rather than a silent behavior change. The default on_pre_tool_use ask-hook is not installed when on_function_approval is set, avoiding double-gating. Precedence: user on_pre_tool_use > on_function_approval > default ask-hook. Adds tests for the deprecated path and documents it in the package README. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Make on_function_approval and on_pre_tool_use mutually exclusive Per automated review feedback, instead of a precedence ordering between the deprecated on_function_approval callback and the new on_pre_tool_use hook (which silently double-gated when both were set), raise ValueError if both are supplied - at construction (both in default_options) or per run (per-run on_pre_tool_use with a construction-time on_function_approval). This matches the repo convention for deprecated-vs-new params (see _workflows/_workflow.py) and removes the flag-threading. Updates tests and the package README. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2.6 KiB
Get Started with Microsoft Agent Framework GitHub Copilot
Please install this package via pip:
pip install agent-framework-github-copilot --pre
GitHub Copilot Agent
The GitHub Copilot agent enables integration with GitHub Copilot, allowing you to interact with Copilot's agentic capabilities through the Agent Framework.
Tool approval (approval_mode="always_require")
The GitHub Copilot SDK owns the tool-calling loop for this provider, so approval for custom function tools is enforced through the SDK's native pre-execution hook rather than the standard Agent Framework approval round-trip.
When you register a FunctionTool declared with approval_mode="always_require" and you
do not supply your own on_pre_tool_use hook, GitHubCopilotAgent installs a default
on_pre_tool_use hook that returns "ask" for that tool and defers (None) for all other
tools. The "ask" decision routes to your on_permission_request handler, where you
approve or deny the call:
from agent_framework import tool
from agent_framework.github import GitHubCopilotAgent, GitHubCopilotOptions
from copilot.session import PermissionHandler
@tool(approval_mode="always_require")
def delete_file(path: str) -> str:
"""Delete a file."""
...
agent = GitHubCopilotAgent(
tools=[delete_file],
# The "ask" decision is routed here; approve or deny the call.
default_options=GitHubCopilotOptions(on_permission_request=PermissionHandler.approve_all),
)
⚠️ If you provide your own
on_pre_tool_usehook, it takes precedence and the agent does not install its default approval hook. In that case you are fully responsible for enforcing approval — including for anyapproval_mode="always_require"tool (e.g. by returning a"deny"or"ask"decision). The agent logs a warning naming any approval-required tool that your hook must handle.Note: with the default (deny-all) permission handler, an
always_requiretool is denied unless you wire an approvingon_permission_request.
Deprecated: on_function_approval
The on_function_approval callback is deprecated. It still works (and is still enforced
inside the tool handler for backward compatibility), but it emits a DeprecationWarning and
will be removed in a future version. Migrate to the on_pre_tool_use + on_permission_request
model described above. When on_function_approval is set, it gates always_require tools and
the default ask-hook is not installed. It is mutually exclusive with on_pre_tool_use —
setting both (whether at construction or per run) raises ValueError.