Skip to content

Feature/v0.3.0/filesystem - #35

Merged
mavdol merged 18 commits into
mainfrom
feature/v0.3.0/filesystem
Jan 13, 2026
Merged

mavdol merged 18 commits into
mainfrom
feature/v0.3.0/filesystem

Conversation

@mavdol

@mavdol mavdol commented Jan 11, 2026

Copy link
Copy Markdown
Member

Filesystem Access (allowed_files)

This PR adds sandboxed filesystem access to Capsule, allowing tasks to read and write files within allowed directories.

  • New allowed_files parameter Tasks can now specify which files or folders they need access to. By default, tasks run in a fully isolated sandbox with no filesystem access.
  • Path validation and security Only relative paths within the project directory are allowed. Absolute paths and directory traversal (../) outside the project are rejected.
  • TypeScript/JavaScript support Node.js fs module is not available in the WebAssembly sandbox. A new
    files API is provided via the SDK with readText , writeText, readBytes, writeBytes, list, and exists methods.
  • WASI filesystem integration Updated capsule.wit to import wasi:filesystem. JavaScript compiler now enables filesystem support via JCO and exposes bindings through globalThis.

@mavdol
mavdol merged commit 3b84522 into main Jan 13, 2026
2 checks passed
@mavdol
mavdol deleted the feature/v0.3.0/filesystem branch January 13, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant