blog · Artikel auf Englisch

Snotra 1.13: every permission on one page

Settings › Security shows what Snotra may do in the open folder, row by row, and holds every control that changes it. 1.13.1 adds the state of each MCP server and stops an unreadable settings file from being overwritten with defaults.

Yesterday I wrote about a problem in Snotra’s interface: the rules that decide what the agent may do in your folder are sound, but the controls were spread over eight places, and nowhere did the app show their combined result. Four ways to fix that were on the table. I picked the first one — a single page — and Snotra 1.13.0 is that page. 1.13.1 followed the same evening with the MCP details the page was still missing and a fix that protects your settings files.

Settings › Security

The new section in the settings is called Security, subtitled “What Snotra may do”. It describes the folder that is open, and it starts with a header: the workspace, its default mode, the chats in it whose mode differs, and one sentence that sums up the rest of the page, for example:

In this workspace Snotra reads without asking, asks before changing a file, asks before every command (in the sandbox), asks before using the web or MCP.

Below it are six rows, one per risk class: Read, Read sensitive data, Change, Overwrite with no way back, Execute and External services. Each row shows how many tools of its kind are switched on, a one-line reason, the exceptions that apply (allowances, remembered commands, blocks) and a status: Runs, Asks or Off. Where commands would run without the sandbox, the Execute row says so in amber.

The state is not described after the fact. Snotra works it out from the same rules that decide every tool call, so the page cannot show something different from what actually happens. Change the default mode in the header, and the six rows follow.

Three questions per row

Open a row and it answers three questions, each with its controls right beneath it:

  • May Snotra do this? Every tool of the class, each with its own switch. MCP tools are switched in External services, the shell and Python switches sit in Execute.
  • Does Snotra ask first? What the mode says, followed by your exceptions — allowances, remembered commands and approvals for the current session — each with a button to remove it.
  • Where, or what exactly? It depends on the class: the folders Snotra may read and change, the patterns that count as sensitive, what exactly cannot be undone, what a command can reach (the sandbox and the program allowances), what leaves your computer. Every row lists its blocks and offers “Add a block…”; the form opens in place, with the class already filled in.

Everything on the page applies at once. The Apply button that used to cover some checkboxes and not others is gone. What loosens protection — allowing something for good, deleting a block, switching the sandbox off, “Auto” as the default — is still confirmed in a native system dialog; switching something off or taking it back needs no confirmation. That was the one condition I had set for the redesign: a clearer page must not make security easier to loosen.

Session approvals, one by one

“Allow for this session” on an approval card used to leave behind a count and a button that deleted all of them. Now every session approval still in force is listed, grouped by chat with the open chat first, each with the sentence from its card, the time you gave it, and a Revoke button. Revoke all is still there. Revoke one, and the next identical call asks again.

What moved, and what went away

Of yesterday’s list, most items disappear with the page itself:

  • Settings › Permissions is gone. The workspace default sits at the top of the Security page; the mode of a single chat is set in the mode pill as before, whose menu now ends in a link: “All permissions in Settings › Security”.
  • Settings › Tools keeps only what has no effect on security: the Python interpreter and the search key.
  • Settings › MCP keeps the server connections. The per-server tool checkboxes are gone, so an MCP tool has exactly one switch. A tool you had deselected there is carried over at the first start, and it stays off.
  • Nothing hides any more. The sandbox and the program allowances are shown even while the execution tools are off, marked with when they matter.
  • Links lead to the row. The shield in the folder panel and the “Sandbox setting” and “Program allowances” links on an approval card open the Security page at the right place.

1.13.1: MCP servers, and your settings files

Two things in External services were still unclear after 1.13.0: why a tool was missing, and what an MCP server would offer before it had been used.

  • Connection state per server. MCP tools are grouped by server, and each group says how its server is connected, in the same words as Settings › MCP: connected, with the number of tools; not connected yet, starting or switched off; or failed to start, with the reason. A server without any tools still gets its heading, so a missing tool is explained.
  • Tools before the first run. Until now the page only knew a server’s tools once it had connected in this session. It now lists the tools the server reported last time, marked “Known from the last connection”, so you can switch one off before the model is ever offered it. One gap remains: a server that has never connected has no tool names yet.

The other fix in 1.13.1 is less visible and more important. When Snotra updated one of its settings files, it read the file first — and treated any read error like a missing file. If a file could not be read for a moment, for instance because Windows was holding it, the defaults were written back over it. For the model configuration, that meant losing API keys and presets. Now only a file that truly doesn’t exist starts from the defaults. Any other read error stops the write and leaves the file as it was, and on Windows a briefly locked file is retried, when reading and when replacing it. The same lock was behind a tool switch that could flip back on its own on Windows.

Smaller things: a section picked in the settings while they are still loading now stays picked, the MCP server dialogs got a proper footer and titles that say “MCP server”, and the interpreter and API key fields in Settings › Tools look like the other fields.

If you skipped 1.12.2

1.12.2 came out yesterday, between the two. It repairs the Windows self-update, which could leave the old version in place, and it keeps images and other media in an answer from loading files from your computer.

Getting it

Snotra checks for a newer version at startup and walks you through the update, one confirmed step at a time. On Windows, coming from 1.12.1 or older, install by hand this once: the self-update of those versions cannot replace itself, and from 1.12.2 on it works again. Otherwise, download it for macOS, Windows or Linux, or read the release notes for 1.13.0 and 1.13.1 on GitHub.

The test for the page is simple: open it, and you should be able to say what Snotra may do in your folder without searching. If a row leaves you guessing, or a setting is still somewhere else, the Discussions are open for that.