Summary
The current Tauri capabilities grant fs:scope with ** wildcard, allowing read/write to any path on the filesystem. This is overly broad.
Current state
In src-tauri/capabilities/default.json:
Desired state
Restrict to directories the app actually needs:
- User's home directory or documents folder
- Specific project directories opened by the user
- Temp directories for scratch files
Notes
- Current scope is acceptable for a power-user tool during development
- Should be tightened before wider distribution
- Tauri v2 supports dynamic scoping — could scope per dialog selection
Summary
The current Tauri capabilities grant
fs:scopewith**wildcard, allowing read/write to any path on the filesystem. This is overly broad.Current state
In
src-tauri/capabilities/default.json:Desired state
Restrict to directories the app actually needs:
Notes