Permissions
Declared once, in the manifest. The Node runtime checks the calls it hands you against them, so your code doesn’t have to police itself.
"permissions": { "network": ["api.example.com"], "files": ["~/.config/my-extension/state.json"], "exec": ["/usr/bin/say"]}| Key | Gates | Notes |
|---|---|---|
network |
fetch |
A list of hostnames (*.example.com matches any subdomain). A fetch to any other host is rejected before it leaves the process, and so is a redirect to one. Empty (or omitted) means fetch reaches nothing. WebSocket follows the same list. Node’s own http, https, net, dns and child_process modules aren’t available to extensions at all, so make every request with fetch and run programs with ctx.exec. |
files |
triggers.watch, and generally any path your code reads |
Paths, ~ allowed. Not sandboxed: your code can read more than it declares, but the manifest is what people see before they install it. Declare what you actually touch. |
exec |
ctx.exec(file, …) |
The exact executable paths you’re allowed to run. ctx.exec rejects (throws) a call for anything not listed here. Like fetch, this checks the call the runtime gives you, not Node’s own child_process: run programs only through ctx.exec. |
Ask for the minimum you need. permissions.network and permissions.exec are the
first thing people see on the install sheet, before anything is installed (Sharing it).