Skip to content

fix(plugin)!: move the user network config commands under Tauri's ACL - #15

Merged
zippy merged 3 commits into
mainfrom
security/user-network-acl
Sep 30, 2026
Merged

zippy merged 3 commits into
mainfrom
security/user-network-acl

Conversation

@zippy

@zippy zippy commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

get_, default_ and set_user_network_config were app commands, so any webview in the app could call them, including set, which repoints the conductor's bootstrap and relay servers and restarts the app. They are now plugin commands (plugin:hc|…), so Tauri's capability system decides who may call them.

hc:default grants the two reads. set needs hc:allow-set-user-network-config, granted by name to the window that hosts the settings screen. permissions/default.toml documents what is left out of the default set and why. Calling any of the three without a managed UserNetworkConfigPath returns Error::UserNetworkConfigPathNotManaged instead of panicking.

Breaking for consumers: remove the three commands from generate_handler!, keep .manage(UserNetworkConfigPath(..)), and invoke them with the plugin:hc| prefix. Rust stops compiling until the first step is done; the JS invoke calls fail at run time until the third. The generator template is updated; emergence has the matching edits pending.

TODO:

  • CHANGELOG updated with appropriate info
  • npm run ci passes

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: d4628cd7-a8c9-4a7e-94f0-674d200a7402


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zippy
zippy force-pushed the security/user-network-acl branch from 826140a to 5d96747 Compare September 24, 2026 18:13
@zippy
zippy marked this pull request as ready for review September 25, 2026 14:37
@zippy
zippy requested a review from zo-el September 25, 2026 14:37
Comment thread crates/tauri-plugin-hc/src/user_network.rs
@mattyg
mattyg requested a review from a team September 28, 2026 19:55
mattyg
mattyg previously approved these changes Sep 28, 2026

@mattyg mattyg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting a few tests, otherwise lgtm

get_, default_ and set_user_network_config were app commands, so any webview
could call them. As plugin commands (plugin:hc|...) the capability system
decides: hc:default grants the two reads, and set, which repoints bootstrap and
relay and restarts the app, needs hc:allow-set-user-network-config. A missing
UserNetworkConfigPath is now an error instead of a panic.
@zippy
zippy force-pushed the security/user-network-acl branch from 59b6f4f to c84377e Compare September 29, 2026 17:47
@zippy
zippy requested a review from mattyg September 29, 2026 17:50
@cocogitto-bot

cocogitto-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

✔️ 1671a0e...3b2d5fc - Conventional commits check succeeded.

@zippy
zippy merged commit 90d9b6c into main Sep 30, 2026
6 checks passed
@zippy
zippy deleted the security/user-network-acl branch September 30, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants