* fix(desktop): allow reading recent .fig files for thumbnails
The recent-files thumbnail loader stats a .fig file, opens it, and seeks
and reads its thumbnail entry, but the desktop capability granted none of
those fs commands, so the WebView rejected the first call ("fs.stat not
allowed") and no thumbnail ever loaded. Grant stat and open with the same
path scope as read-file, plus the handle commands they lead to.
A native spec runs the loader's command sequence on a real .fig file.
* test(desktop): check the bytes the recent-file thumbnail read returns
The native spec discarded the read result, so a read returning nothing would pass. Assert the zip signature and the byte count the fs plugin appends, through a bytes variant of the native invoke helper.
82 lines
2.3 KiB
JSON
82 lines
2.3 KiB
JSON
{
|
|
"$schema": "../gen/schemas/desktop-schema.json",
|
|
"identifier": "default",
|
|
"description": "Capability for the main window",
|
|
"windows": ["main"],
|
|
"permissions": [
|
|
"core:default",
|
|
"core:window:allow-destroy",
|
|
"opener:default",
|
|
"dialog:default",
|
|
"dialog:allow-save",
|
|
"dialog:allow-open",
|
|
"updater:default",
|
|
"process:default",
|
|
"clipboard-manager:allow-read-text",
|
|
"clipboard-manager:allow-write-html",
|
|
"clipboard-manager:allow-write-text",
|
|
{
|
|
"identifier": "fs:allow-read-file",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-stat",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-open",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
"fs:allow-fstat",
|
|
"fs:allow-seek",
|
|
"fs:allow-read",
|
|
{
|
|
"identifier": "fs:allow-read-text-file",
|
|
"allow": [
|
|
{ "path": "$HOME/Library/Application Support/OpenPencil/mcp.json" },
|
|
{ "path": "$LOCALDATA/OpenPencil/mcp.json" },
|
|
{ "path": "$RUNTIME/openpencil/mcp.json" },
|
|
{ "path": "$HOME/.openpencil/mcp.json" }
|
|
]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-write-file",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-exists",
|
|
"allow": [
|
|
{ "path": "$HOME/Library/Application Support/OpenPencil/mcp.json" },
|
|
{ "path": "$LOCALDATA/OpenPencil/mcp.json" },
|
|
{ "path": "$RUNTIME/openpencil/mcp.json" },
|
|
{ "path": "$HOME/.openpencil/mcp.json" }
|
|
]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-mkdir",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-remove",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-watch",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
"fs:allow-unwatch",
|
|
{
|
|
"identifier": "shell:allow-spawn",
|
|
"allow": [
|
|
{ "name": "claude-agent-acp", "cmd": "claude-agent-acp", "args": true },
|
|
{ "name": "codex-acp", "cmd": "codex-acp", "args": true },
|
|
{ "name": "gemini", "cmd": "gemini", "args": true },
|
|
{ "name": "openpencil-mcp-http", "cmd": "openpencil-mcp-http", "args": true },
|
|
{ "name": "openpencil-harness", "cmd": "openpencil-harness", "args": false },
|
|
{ "name": "cmd", "cmd": "cmd", "args": true }
|
|
]
|
|
},
|
|
"shell:allow-stdin-write",
|
|
"shell:allow-kill"
|
|
]
|
|
} |