Files
ChatApp/apps/desktop/electron/modules/fs-scoped.ts
T
byGalax 825160ee46 feat(desktop): port v0.11.4-v0.15.2 from Tauri to Electron + Discord-parity audio (v0.16.0)
Chronological port of every Tauri release commit (v0.11.4 -> v0.15.2)
into the Electron rebuild, plus Discord-style audio handling that goes
beyond the Tauri original.

Highlights:
  - All 17 Tauri release commits ported (audio fixes, custom notification
    sound, Discord-style chat UX, profile banner, changelog page,
    Discord-parity call UX, screen-share echo + re-watch UX, audio-loop
    fix).
  - Native napi-rs audio-loopback addon with WASAPI process-loopback:
      * EXCLUDE_TARGET_PROCESS_TREE for full-screen shares -> peers
        never hear themselves echoed back through the capture.
      * INCLUDE_TARGET_PROCESS_TREE for window shares -> only the
        picked window's audio is captured, not the whole OS mixer
        (Discord parity).
      * HWND -> PID resolution via Win32 GetWindowThreadProcessId.
  - Discord-style screen-source picker (thumbnail grid, screens vs
    apps tabs, live-refreshing thumbnails).
  - Hash routing fix for packaged builds (file:// can't resolve
    BrowserRouter paths).
  - Tauri sources removed (apps/desktop/src-tauri).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-06 23:35:01 +02:00

82 lines
2.7 KiB
TypeScript

// Scoped filesystem. Every renderer-supplied path is resolved under
// `app.getPath('userData')`. Post-normalisation we re-check the resolved
// absolute path is still contained in the root; anything that breaks out
// (via .., symlink, absolute path) is rejected. Binary payloads are
// base64 on the wire because JSON IPC can't carry raw bytes cleanly.
import { app, ipcMain } from 'electron';
import { promises as fs } from 'node:fs';
import path from 'node:path';
import { CHANNELS, type FsPath, type FsRenameArgs, type FsWriteArgs } from '../ipc-types';
function rootDir(): string {
return app.getPath('userData');
}
function resolveScoped(rel: FsPath): string {
const root = rootDir();
if (path.isAbsolute(rel)) {
throw new Error('fs-scoped: absolute path rejected');
}
const normalised = path.normalize(rel);
if (normalised.split(/[\\/]/).includes('..')) {
throw new Error('fs-scoped: path traversal rejected');
}
const abs = path.resolve(root, normalised);
const withSep = root.endsWith(path.sep) ? root : root + path.sep;
if (abs !== root && !abs.startsWith(withSep)) {
throw new Error('fs-scoped: escaped scope');
}
return abs;
}
export function register(): void {
ipcMain.handle(CHANNELS.FS_APP_LOCAL_DATA_DIR, async (): Promise<string> => rootDir());
ipcMain.handle(CHANNELS.FS_READ, async (_evt, rel: FsPath): Promise<string | null> => {
const abs = resolveScoped(rel);
try {
const buf = await fs.readFile(abs);
return buf.toString('base64');
} catch (err: unknown) {
if ((err as NodeJS.ErrnoException).code === 'ENOENT') return null;
throw err;
}
});
ipcMain.handle(CHANNELS.FS_WRITE, async (_evt, args: FsWriteArgs): Promise<void> => {
const abs = resolveScoped(args.path);
await fs.mkdir(path.dirname(abs), { recursive: true });
const buf = Buffer.from(args.dataBase64, 'base64');
await fs.writeFile(abs, buf);
});
ipcMain.handle(CHANNELS.FS_EXISTS, async (_evt, rel: FsPath): Promise<boolean> => {
const abs = resolveScoped(rel);
try {
await fs.access(abs);
return true;
} catch {
return false;
}
});
ipcMain.handle(CHANNELS.FS_MKDIR, async (_evt, rel: FsPath): Promise<void> => {
const abs = resolveScoped(rel);
await fs.mkdir(abs, { recursive: true });
});
ipcMain.handle(CHANNELS.FS_RENAME, async (_evt, args: FsRenameArgs): Promise<void> => {
const from = resolveScoped(args.from);
const to = resolveScoped(args.to);
await fs.mkdir(path.dirname(to), { recursive: true });
await fs.rename(from, to);
});
ipcMain.handle(CHANNELS.FS_REMOVE, async (_evt, rel: FsPath): Promise<void> => {
const abs = resolveScoped(rel);
await fs.rm(abs, { recursive: true, force: true });
});
}