feat(fs): allow disabling the drag and drop scope extension (#3637)

In plugins/fs/src/lib.rs on_event, every path dropped onto any window is
added to the global runtime scope, directories recursively, with no
opt-out.

Adds the `scopeDroppedPaths` plugin config option (default true, the
current behaviour) so apps can turn it off. Changing the default or
scoping it per window is deferred to v3.
This commit is contained in:
Lucas Fernandes Nogueira authored and GitHub committed 2026-10-09 13:07:34 -03:00
1 parent 085a02835d
commit a934743b73
3 files changed
+24 -1

No files matched your search

+6
View File
@@ -0,0 +1,6 @@
---
fs: minor
fs-js: minor
---
Added the `scopeDroppedPaths` plugin config option (`plugins > fs > scopeDroppedPaths` in `tauri.conf.json`). Set it to `false` to stop adding the paths dropped onto any window to the fs scope, which otherwise gives every webview with an fs permission access to them (directories recursively). Defaults to `true`, the current behaviour.
+5
View File
@@ -16,4 +16,9 @@ pub struct Config {
/// Defaults to `true` on Unix systems and `false` on Windows
// dotfiles are not supposed to be exposed by default on unix
pub require_literal_leading_dot: Option<bool>,
/// Whether the paths dropped onto a window (drag and drop) are added to the runtime fs scope,
/// directories recursively, which gives every webview with an fs permission access to them.
///
/// Defaults to `true`.
pub scope_dropped_paths: Option<bool>,
}
+13 -1
View File
@@ -451,6 +451,7 @@ impl ScopeObject for scope::Entry {
pub(crate) struct Scope {
pub(crate) scope: tauri::fs::Scope,
pub(crate) require_literal_leading_dot: Option<bool>,
pub(crate) scope_dropped_paths: bool,
}
/// Tracks which paths have active security-scoped resource access on iOS.
@@ -592,6 +593,11 @@ pub fn init<R: Runtime>() -> TauriPlugin<R, Option<config::Config>> {
.config()
.as_ref()
.and_then(|c| c.require_literal_leading_dot),
scope_dropped_paths: api
.config()
.as_ref()
.and_then(|c| c.scope_dropped_paths)
.unwrap_or(true),
scope: tauri::fs::Scope::new(app, &FsScope::default())?,
};
@@ -619,7 +625,13 @@ pub fn init<R: Runtime>() -> TauriPlugin<R, Option<config::Config>> {
..
} = event
{
let scope = app.fs_scope();
let Some(scope) = app.try_state::<Scope>() else {
return;
};
if !scope.scope_dropped_paths {
return;
}
let scope = &scope.scope;
for path in paths {
if path.is_file() {
let _ = scope.allow_file(path);