openpencil/desktop/capabilities/default.json
Danila Poyarkov bd7acd6e34
fix(desktop): pin every command line the app may start (#922)
* fix(desktop): pin every command line the app may start

On Windows the app starts npm-installed CLIs through cmd /c, and the shell scope let cmd take any arguments, so any code running in the webview could run any command. Each program now has a scope entry with its exact arguments, and Windows shims go through their own cmd-<name> entries with fixed /c <name> arguments. The agents and the MCP server no longer accept arbitrary arguments either. A test checks that every command the app starts has a matching entry on both platforms.

* test(desktop): expect Windows shims through their own scope entries

* test(desktop): check the executable of each shell scope entry

* test(desktop): allow no shell scope entry beyond the programs the app starts

An extra entry with a permissive validator passed the per-program checks.
2026-10-06 11:19:05 +00:00

86 lines
2.7 KiB
JSON

{
"$schema": "../gen/schemas/desktop-schema.json",
"identifier": "default",
"description": "Capability for the main window",
"windows": ["main"],
"permissions": [
"core:default",
"core:window:allow-destroy",
"opener:default",
"dialog:default",
"dialog:allow-save",
"dialog:allow-open",
"updater:default",
"process:default",
"clipboard-manager:allow-read-text",
"clipboard-manager:allow-write-html",
"clipboard-manager:allow-write-text",
{
"identifier": "fs:allow-read-file",
"allow": [{ "path": "**" }]
},
{
"identifier": "fs:allow-stat",
"allow": [{ "path": "**" }]
},
{
"identifier": "fs:allow-open",
"allow": [{ "path": "**" }]
},
"fs:allow-fstat",
"fs:allow-seek",
"fs:allow-read",
{
"identifier": "fs:allow-read-text-file",
"allow": [
{ "path": "$HOME/Library/Application Support/OpenPencil/mcp.json" },
{ "path": "$LOCALDATA/OpenPencil/mcp.json" },
{ "path": "$RUNTIME/openpencil/mcp.json" },
{ "path": "$HOME/.openpencil/mcp.json" }
]
},
{
"identifier": "fs:allow-write-file",
"allow": [{ "path": "**" }]
},
{
"identifier": "fs:allow-exists",
"allow": [
{ "path": "$HOME/Library/Application Support/OpenPencil/mcp.json" },
{ "path": "$LOCALDATA/OpenPencil/mcp.json" },
{ "path": "$RUNTIME/openpencil/mcp.json" },
{ "path": "$HOME/.openpencil/mcp.json" }
]
},
{
"identifier": "fs:allow-mkdir",
"allow": [{ "path": "**" }]
},
{
"identifier": "fs:allow-remove",
"allow": [{ "path": "**" }]
},
{
"identifier": "fs:allow-watch",
"allow": [{ "path": "**" }]
},
"fs:allow-unwatch",
{
"identifier": "shell:allow-spawn",
"allow": [
{ "name": "claude-agent-acp", "cmd": "claude-agent-acp", "args": false },
{ "name": "codex-acp", "cmd": "codex-acp", "args": false },
{ "name": "gemini", "cmd": "gemini", "args": ["--acp"] },
{ "name": "openpencil-mcp-http", "cmd": "openpencil-mcp-http", "args": false },
{ "name": "openpencil-harness", "cmd": "openpencil-harness", "args": false },
{ "name": "cmd-claude-agent-acp", "cmd": "cmd", "args": ["/c", "claude-agent-acp"] },
{ "name": "cmd-codex-acp", "cmd": "cmd", "args": ["/c", "codex-acp"] },
{ "name": "cmd-gemini", "cmd": "cmd", "args": ["/c", "gemini", "--acp"] },
{ "name": "cmd-openpencil-mcp-http", "cmd": "cmd", "args": ["/c", "openpencil-mcp-http"] },
{ "name": "cmd-openpencil-harness", "cmd": "cmd", "args": ["/c", "openpencil-harness"] }
]
},
"shell:allow-stdin-write",
"shell:allow-kill"
]
}