* fix(desktop): pin every command line the app may start On Windows the app starts npm-installed CLIs through cmd /c, and the shell scope let cmd take any arguments, so any code running in the webview could run any command. Each program now has a scope entry with its exact arguments, and Windows shims go through their own cmd-<name> entries with fixed /c <name> arguments. The agents and the MCP server no longer accept arbitrary arguments either. A test checks that every command the app starts has a matching entry on both platforms. * test(desktop): expect Windows shims through their own scope entries * test(desktop): check the executable of each shell scope entry * test(desktop): allow no shell scope entry beyond the programs the app starts An extra entry with a permissive validator passed the per-program checks. |
||
|---|---|---|
| .. | ||
| acp-transport.test.ts | ||
| automation-files.test.ts | ||
| command.test.ts | ||
| document-io.test.ts | ||
| fig-export.test.ts | ||
| file-actions.test.ts | ||
| font-cache.test.ts | ||
| fonts.test.ts | ||
| harness-process.test.ts | ||
| http.test.ts | ||
| mcp-spawn.test.ts | ||
| mock-cleanup.test.ts | ||
| processes.test.ts | ||