langchain 1.4.0: after_model middleware with jump_to='tools' bypasses HITL pending_tool_calls gate
In langchain 1.4.0, the HumanInTheLoopMiddleware records pending tool calls before interrupting. Any other after_model middleware that returns the documented {"jump_to": "tools"} outcome routes the graph directly to the tool node, skipping the HITL middleware entirely. This allows previously rejected (or not-yet-reviewed) tool calls to execute with user authority, silently defeating human-in-the-loop approval.
