锁定桌面壳系统调用顺序
桌面壳配置检查新增导出文件 payload 校验早于系统保存对话框的顺序门禁 桌面壳配置检查新增本地通知 payload 校验早于通知权限访问的顺序门禁 共享决策记录补充桌面壳系统能力调用顺序约定
This commit is contained in:
@@ -1040,6 +1040,14 @@ function extractFunctionBody(source, functionName) {
|
||||
throw new Error(`unable to read Rust function body ${functionName}`);
|
||||
}
|
||||
|
||||
function assertSnippetOrder(source, firstSnippet, secondSnippet, label) {
|
||||
const firstIndex = source.indexOf(firstSnippet);
|
||||
const secondIndex = source.indexOf(secondSnippet);
|
||||
if (firstIndex < 0 || secondIndex < 0 || firstIndex > secondIndex) {
|
||||
throw new Error(`${label} must call ${firstSnippet} before ${secondSnippet}`);
|
||||
}
|
||||
}
|
||||
|
||||
function extractDesktopDialogFilter(source, ownerName, filterLabel) {
|
||||
const ownerBody = extractFunctionBody(source, ownerName);
|
||||
const match = ownerBody.match(
|
||||
@@ -1102,6 +1110,19 @@ function assertDesktopDialogBoundary(method, functionName, filterLabel, expected
|
||||
}
|
||||
}
|
||||
|
||||
function assertDesktopFileExportPayloadOrder(method, functionName, payloadFunction) {
|
||||
const fileFunctionBody = extractFunctionBody(
|
||||
desktopHostBridgeFilesSource,
|
||||
functionName,
|
||||
);
|
||||
assertSnippetOrder(
|
||||
fileFunctionBody,
|
||||
payloadFunction,
|
||||
'.dialog()',
|
||||
`desktop shell ${method} export boundary`,
|
||||
);
|
||||
}
|
||||
|
||||
function assertNoRawHostContextUrl(urlValue, label) {
|
||||
const rawUrl = String(urlValue ?? '');
|
||||
const blockedQueryKeys = [
|
||||
@@ -2555,6 +2576,12 @@ if (
|
||||
'desktop shell notification HostBridge method must delegate to notifications module',
|
||||
);
|
||||
}
|
||||
assertSnippetOrder(
|
||||
extractFunctionBody(desktopHostBridgeNotificationsSource, 'show_desktop_local_notification'),
|
||||
'local_notification_payload(request)',
|
||||
'app.notification()',
|
||||
'desktop shell notification boundary',
|
||||
);
|
||||
for (const snippet of [
|
||||
'tauri_plugin_notification::{NotificationExt, PermissionState}',
|
||||
'HOST_BRIDGE_LOCAL_NOTIFICATION_DELIVERED_TO_SYSTEM_ACTION',
|
||||
@@ -2687,6 +2714,21 @@ assertDesktopDialogBoundary(
|
||||
['mp3', 'm4a', 'wav', 'ogg', 'webm'],
|
||||
'save',
|
||||
);
|
||||
assertDesktopFileExportPayloadOrder(
|
||||
'file.exportText',
|
||||
'export_desktop_host_bridge_text_file',
|
||||
'export_text_payload(request)',
|
||||
);
|
||||
assertDesktopFileExportPayloadOrder(
|
||||
'file.exportImage',
|
||||
'export_desktop_host_bridge_image_file',
|
||||
'export_image_payload(request)',
|
||||
);
|
||||
assertDesktopFileExportPayloadOrder(
|
||||
'file.exportAudio',
|
||||
'export_desktop_host_bridge_audio_file',
|
||||
'export_audio_payload(request)',
|
||||
);
|
||||
for (const snippet of [
|
||||
'.dialog()',
|
||||
'blocking_save_file',
|
||||
|
||||
Reference in New Issue
Block a user