LCE-Emerald-Launcher/src-tauri
M1noa 8c941a6b72 fix(LCEL-01): disable arbitrary-path IPC + remove opener ** scope
three changes:

1. file_dialogs::write_binary_file / read_binary_file used to accept
   arbitrary paths with no validation, no dialog, no scope. now they
   refuse all paths. callers must use pick_file / save_file_dialog.

2. plugins::list_directory used to accept arbitrary paths with no
   validation. now it refuses all paths. callers must use
   get_plugins_dir.

3. capabilities/default.json had opener:allow-open-path scoped to
   path: "**" which let the webview launch ANY local path. removed
   that entry entirely. opener:allow-reveal-item-in-dir is left for
   now (used by the file manager UI).

combined, these close the webview -> arbitrary write+execute primitive.
the proper fix is to scope opener:allow-open-path to a specific games
directory once we know what paths the launcher actually needs to open.
2026-07-16 20:25:58 -05:00
..
capabilities fix(LCEL-01): disable arbitrary-path IPC + remove opener ** scope 2026-07-16 20:25:58 -05:00
gen/schemas fix(versions): custom path empty directory, fixes #127 (#131) 2026-07-12 10:06:37 +03:00
icons feat(icon): macOS style (#106) 2026-06-30 22:31:11 +03:00
resources/DLC/Emerald Skin Pack fix: Permission Issue on Release (#1) 2026-04-13 19:40:46 +03:00
scripts ci: build artifacts 2026-05-16 20:37:13 +03:00
src fix(LCEL-01): disable arbitrary-path IPC + remove opener ** scope 2026-07-16 20:25:58 -05:00
.gitignore revert the revert 2026-04-02 16:02:58 +03:00
build.rs revert the revert 2026-04-02 16:02:58 +03:00
Cargo.lock bump (#133) 2026-07-12 20:11:06 +03:00
Cargo.toml bump (#133) 2026-07-12 20:11:06 +03:00
tauri.conf.json bump (#133) 2026-07-12 20:11:06 +03:00
tauri.nightly.conf.json bump (#133) 2026-07-12 20:11:06 +03:00