mirror of
https://github.com/LCE-Hub/LCE-Emerald-Launcher.git
synced 2026-07-20 17:27:07 +00:00
three changes: 1. file_dialogs::write_binary_file / read_binary_file used to accept arbitrary paths with no validation, no dialog, no scope. now they refuse all paths. callers must use pick_file / save_file_dialog. 2. plugins::list_directory used to accept arbitrary paths with no validation. now it refuses all paths. callers must use get_plugins_dir. 3. capabilities/default.json had opener:allow-open-path scoped to path: "**" which let the webview launch ANY local path. removed that entry entirely. opener:allow-reveal-item-in-dir is left for now (used by the file manager UI). combined, these close the webview -> arbitrary write+execute primitive. the proper fix is to scope opener:allow-open-path to a specific games directory once we know what paths the launcher actually needs to open. |
||
|---|---|---|
| .. | ||
| capabilities | ||
| gen/schemas | ||
| icons | ||
| resources/DLC/Emerald Skin Pack | ||
| scripts | ||
| src | ||
| .gitignore | ||
| build.rs | ||
| Cargo.lock | ||
| Cargo.toml | ||
| tauri.conf.json | ||
| tauri.nightly.conf.json | ||