Capabilities & security
Grant each frontend the native operations it actually needs.
Experimental source release. Production hardening and published SDK packages are still in progress.
Capabilities match origins#
Add capability entries under app.security.capabilities. Each entry names the allowed origins and ShellAPI methods. The method selector * includes all registered methods for those origins; filesystem, URL, and window scopes still apply. Playground groups tuffite.fs.* and tuffite.window.* while keeping resource reads separate from writable directories. Namespace group scopes apply only to methods that consume resources. Use narrow method permissions and explicit filesystem scopes. The manifest schema validates the shape; tuff check also validates semantic restrictions.
{
"identifier": "main-window",
"origins": ["myapp://main"],
"shellApi": ["myapp.commands.ping", "tuffite.window.current"]
}Configure CSP and asset routes#
app.security.csp controls the frontend content security policy. app.assets maps explicit origins and request paths to packaged files. Asset routes and native permissions are separate contracts: registering a file does not grant a native capability.
Authenticated development mode#
tuff dev refreshes a native development package and launches a loopback web server. A per-run token and readiness probe authenticate the renderer override. A compatible Framework must include the development-mode feature. Do not expose the development server or CDP port publicly.