From a934743b7307891cc028c0dea945113311ddf100 Mon Sep 17 00:00:00 2001 From: Lucas Fernandes Nogueira Date: Fri, 9 Oct 2026 13:07:34 -0300 Subject: [PATCH] feat(fs): allow disabling the drag and drop scope extension (#3637) In plugins/fs/src/lib.rs on_event, every path dropped onto any window is added to the global runtime scope, directories recursively, with no opt-out. Adds the `scopeDroppedPaths` plugin config option (default true, the current behaviour) so apps can turn it off. Changing the default or scoping it per window is deferred to v3. --- .changes/feat-fs-scope-dropped-paths.md | 6 ++++++ plugins/fs/src/config.rs | 5 +++++ plugins/fs/src/lib.rs | 14 +++++++++++++- 3 files changed, 24 insertions(+), 1 deletion(-) create mode 100644 .changes/feat-fs-scope-dropped-paths.md diff --git a/.changes/feat-fs-scope-dropped-paths.md b/.changes/feat-fs-scope-dropped-paths.md new file mode 100644 index 000000000..1d8aef8ae --- /dev/null +++ b/.changes/feat-fs-scope-dropped-paths.md @@ -0,0 +1,6 @@ +--- +fs: minor +fs-js: minor +--- + +Added the `scopeDroppedPaths` plugin config option (`plugins > fs > scopeDroppedPaths` in `tauri.conf.json`). Set it to `false` to stop adding the paths dropped onto any window to the fs scope, which otherwise gives every webview with an fs permission access to them (directories recursively). Defaults to `true`, the current behaviour. diff --git a/plugins/fs/src/config.rs b/plugins/fs/src/config.rs index db3bae45e..2cb162394 100644 --- a/plugins/fs/src/config.rs +++ b/plugins/fs/src/config.rs @@ -16,4 +16,9 @@ pub struct Config { /// Defaults to `true` on Unix systems and `false` on Windows // dotfiles are not supposed to be exposed by default on unix pub require_literal_leading_dot: Option, + /// Whether the paths dropped onto a window (drag and drop) are added to the runtime fs scope, + /// directories recursively, which gives every webview with an fs permission access to them. + /// + /// Defaults to `true`. + pub scope_dropped_paths: Option, } diff --git a/plugins/fs/src/lib.rs b/plugins/fs/src/lib.rs index 508a4ea45..8e04a520c 100644 --- a/plugins/fs/src/lib.rs +++ b/plugins/fs/src/lib.rs @@ -451,6 +451,7 @@ impl ScopeObject for scope::Entry { pub(crate) struct Scope { pub(crate) scope: tauri::fs::Scope, pub(crate) require_literal_leading_dot: Option, + pub(crate) scope_dropped_paths: bool, } /// Tracks which paths have active security-scoped resource access on iOS. @@ -592,6 +593,11 @@ pub fn init() -> TauriPlugin> { .config() .as_ref() .and_then(|c| c.require_literal_leading_dot), + scope_dropped_paths: api + .config() + .as_ref() + .and_then(|c| c.scope_dropped_paths) + .unwrap_or(true), scope: tauri::fs::Scope::new(app, &FsScope::default())?, }; @@ -619,7 +625,13 @@ pub fn init() -> TauriPlugin> { .. } = event { - let scope = app.fs_scope(); + let Some(scope) = app.try_state::() else { + return; + }; + if !scope.scope_dropped_paths { + return; + } + let scope = &scope.scope; for path in paths { if path.is_file() { let _ = scope.allow_file(path);