From 72f5aac524c147b5375a3f1405cb73a8473b9504 Mon Sep 17 00:00:00 2001 From: Prud'homme Date: Thu, 13 Aug 2026 16:33:03 +0200 Subject: [PATCH 1/3] fix(fs): open documents from any folder the user opened MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Since 0.11.0 documents are read through `read_document`, which only allowed paths under the home dir or the bundled resource dir. Opening a folder anywhere else — /tmp, /Volumes, a repo cloned outside home — listed its files in the sidebar but refused to open any of them: the listing goes through the fs plugin (scoped to `/**`), the read did not. The failure was invisible. `loadFile` only logged to the console, so selecting a file just did nothing, which reads as an unresponsive click rather than a refusal. Confining to the home dir also had the threat model backwards: it allowed ~/.ssh and ~/.aws while blocking /tmp. Confine to the folder the user opened instead — the access they actually granted — so a crafted relative link still cannot escape it, and every folder they can browse, they can read. The resource dir stays allowed for the bundled examples. Surface load failures in the content area (FR + EN) so a file that cannot be opened says so instead of silently doing nothing. Claude-Session: https://claude.ai/code/session_01NcJuB2iR4WEfuQVLpYqWi4 --- index.html | 19 +++++++++++++++++++ src-tauri/src/lib.rs | 27 ++++++++++++++++++++------- src/locales/en.json | 11 ++--------- src/locales/fr.json | 11 ++--------- src/main.ts | 21 ++++++++++++++++++++- 5 files changed, 63 insertions(+), 26 deletions(-) diff --git a/index.html b/index.html index 8c1065f..9f9b7f3 100644 --- a/index.html +++ b/index.html @@ -1902,6 +1902,22 @@ line-height: 1.45; } #slow-read-notice[hidden] { display: none; } + + /* Same shape as the slow-read notice, in an error tone. */ + #load-error { + display: flex; + align-items: flex-start; + gap: 10px; + margin: 0 0 24px; + padding: 10px 14px; + border: 1px solid var(--border); + border-left: 3px solid #dc2626; + border-radius: 6px; + color: var(--text); + font-size: 13px; + line-height: 1.45; + } + #load-error[hidden] { display: none; } #slow-read-notice .srn-text { flex: 1; } #slow-read-notice .srn-close { flex: none; @@ -2049,6 +2065,9 @@

Markdown Viewer

+ +
+
+ + Ouverture depuis le Finder + + + Quand un document est déjà ouvert + +
+
+ + +
+