The default capability only granted read_file/write_file/mkdir/remove/watch, but the app also calls exists(), readTextFile(), create(), and open() from @tauri-apps/plugin-fs. Each fs-plugin command requires its own explicit permission identifier in Tauri v2 — these were never added. The most visible symptom: EditorView's automation startup calls discoveryFileExists()/readDiscoveryToken() (spawn.ts) to reuse an already- running MCP server. With allow-exists and allow-read-text-file missing, both calls silently fail (the fs-plugin IPC rejection is caught and treated as "file not found"), so the app always falls through to spawning a redundant MCP server process and registers with a freshly generated auth token instead of the real one — which the already-running server then rejects, leaving automation permanently disconnected from any already-running MCP server.
68 lines
1.7 KiB
JSON
68 lines
1.7 KiB
JSON
{
|
|
"$schema": "../gen/schemas/desktop-schema.json",
|
|
"identifier": "default",
|
|
"description": "Capability for the main window",
|
|
"windows": ["main"],
|
|
"permissions": [
|
|
"core:default",
|
|
"opener:default",
|
|
"dialog:default",
|
|
"dialog:allow-save",
|
|
"dialog:allow-open",
|
|
"updater:default",
|
|
"process:default",
|
|
"clipboard-manager:allow-read-text",
|
|
"clipboard-manager:allow-write-html",
|
|
"clipboard-manager:allow-write-text",
|
|
{
|
|
"identifier": "fs:allow-read-file",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-read-text-file",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-write-file",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-exists",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-create",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-open",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-mkdir",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-remove",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
{
|
|
"identifier": "fs:allow-watch",
|
|
"allow": [{ "path": "**" }]
|
|
},
|
|
"fs:allow-unwatch",
|
|
{
|
|
"identifier": "shell:allow-spawn",
|
|
"allow": [
|
|
{ "name": "claude-agent-acp", "cmd": "claude-agent-acp", "args": true },
|
|
{ "name": "codex-acp", "cmd": "codex-acp", "args": true },
|
|
{ "name": "gemini", "cmd": "gemini", "args": true },
|
|
{ "name": "openpencil-mcp-http", "cmd": "openpencil-mcp-http", "args": true },
|
|
{ "name": "cmd", "cmd": "cmd", "args": true }
|
|
]
|
|
},
|
|
"shell:allow-stdin-write",
|
|
"shell:allow-kill"
|
|
]
|
|
}
|