Skip to content

Tighten Tauri filesystem scope permissions #57

Description

@talmo

Summary

The current Tauri capabilities grant fs:scope with ** wildcard, allowing read/write to any path on the filesystem. This is overly broad.

Current state

In src-tauri/capabilities/default.json:

"fs:scope": ["**"]

Desired state

Restrict to directories the app actually needs:

  • User's home directory or documents folder
  • Specific project directories opened by the user
  • Temp directories for scratch files

Notes

  • Current scope is acceptable for a power-user tool during development
  • Should be tightened before wider distribution
  • Tauri v2 supports dynamic scoping — could scope per dialog selection

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions