openpencil/packages
Danila Poyarkov 22d5dfe6b5
fix: refuse risky desktop writes and run every Storybook play function (#933)
* fix(desktop): refuse writes where a written file would run

The fs scope let the webview write, create folders, and delete anywhere. Documents may still be saved anywhere, but the global scope now denies login items and startup folders, PowerShell profiles, and the global package and executable folders where coding agents and OpenPencil's companions live, and writes to the MCP discovery files agents trust. requireLiteralLeadingDot keeps hidden files and folders, such as shell profiles and agent settings, out of ** on Windows as Tauri already does on macOS and Linux. A native test saves a document and is refused a LaunchAgents file, a home dotfile, and the discovery file.

* fix(ui): draw segmented controls at panel field height

Panel fields moved to 24px when sizing tokens became plain utilities, but segmented control items stayed 22px inside a 2px padding, so the Typography and resizing controls stood 2px taller than the fields beside them. The panel foundation story renders its inputs at the panel size and checks 24px.

* test(storybook): run every story and its play function

No test ran the play functions, and five had gone stale: the layer tree example labelled a wrapper with the same name as its row, the chat composer's label gained an ellipsis, the MCP failure story queried a test id attribute the app does not use, and the property primitives story still collapsed sections whose titles are static now. bun run test:storybook now renders every story and fails on a story or play function that throws.

* fix(desktop): deny protected folders themselves and writable opens of the discovery files

Each protected folder is denied alongside its contents, so a recursive remove cannot target the folder itself, and the MCP discovery files are denied to open as well as write, since opening with truncate would empty them. The native test opens the discovery file for writing without truncating, and removes only files it created. The story test waits for storyFinished, which follows afterEach, and judges exceptions and non-accessibility reports.

* test(desktop): run the file scope check only on macOS

Its protected paths are macOS ones, so other platforms skip it rather than pass for another reason.

* docs: note that documents opened from hidden folders can still be saved
2026-10-06 14:52:12 +00:00
..
cli feat: behaviours and preview mode (#893) 2026-10-06 13:23:05 +00:00
core test(core): type the behaviour tests for the test typecheck (#934) 2026-10-06 13:58:17 +00:00
demos
design-jsx feat: behaviours and preview mode (#893) 2026-10-06 13:23:05 +00:00
docs feat: behaviours and preview mode (#893) 2026-10-06 13:23:05 +00:00
dom-css feat: behaviours and preview mode (#893) 2026-10-06 13:23:05 +00:00
emit refactor: rename @open-pencil/codegen to @open-pencil/emit (#822) 2026-10-04 11:22:20 +00:00
fig feat: let a collection name the attribute its modes switch by (#913) 2026-10-06 12:35:41 +00:00
harness fix(harness): start Pi sessions with MCP tools under Node (#897) 2026-10-05 17:21:50 +00:00
kiwi test: typecheck the test suites and fix what that found (#896) 2026-10-05 12:42:38 +00:00
mcp test: typecheck the test suites and fix what that found (#896) 2026-10-05 12:42:38 +00:00
pen feat(scene-graph)!: make a stroke a paint (#864) 2026-10-04 13:38:05 +04:00
scene-graph feat: behaviours and preview mode (#893) 2026-10-06 13:23:05 +00:00
vue fix: refuse risky desktop writes and run every Storybook play function (#933) 2026-10-06 14:52:12 +00:00