Commit graph

2 commits

Author SHA1 Message Date
Danila Poyarkov bd7acd6e34
fix(desktop): pin every command line the app may start (#922)
* fix(desktop): pin every command line the app may start

On Windows the app starts npm-installed CLIs through cmd /c, and the shell scope let cmd take any arguments, so any code running in the webview could run any command. Each program now has a scope entry with its exact arguments, and Windows shims go through their own cmd-<name> entries with fixed /c <name> arguments. The agents and the MCP server no longer accept arbitrary arguments either. A test checks that every command the app starts has a matching entry on both platforms.

* test(desktop): expect Windows shims through their own scope entries

* test(desktop): check the executable of each shell scope entry

* test(desktop): allow no shell scope entry beyond the programs the app starts

An extra entry with a permissive validator passed the per-program checks.
2026-10-06 11:19:05 +00:00
Danila Poyarkov 5b2334ba2d
fix(acp): launch Windows command shims (#425)
- Route npm-installed ACP and MCP launchers through cmd on Windows
- Preserve inherited agent environment and current MCP transport settings
- Cover Windows process resolution and document the user-facing fix

Co-authored-by: Damián Briones <insertnickname1@gmail.com>
2026-07-26 08:47:20 +03:00