diff --git a/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift b/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift index 9d73d91..76edfbf 100644 --- a/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift +++ b/NucleicRemote/NucleicRemote/Views/ApprovalCardView.swift @@ -76,7 +76,10 @@ struct ApprovalCardView: View { .disabled(!allowEnabled) } - if !store.capabilities.allowAlwaysScopes.isEmpty { + // A destructive action (rm, force-push, reset --hard, …) offers no remembered + // allow: every one must be a deliberate, one-off approval, never granted in a + // way that lets the next one through unseen. Mirrors the Mac. + if approval.risk != .destructive, !store.capabilities.allowAlwaysScopes.isEmpty { Menu("Allow always…") { ForEach(store.capabilities.allowAlwaysScopes, id: \.self) { scope in Button(alwaysLabel(scope)) {