mirror of
https://github.com/NeuralNomadsAI/CodeNomad.git
synced 2026-08-25 16:22:28 +00:00
## Summary - Follow up #578 by consolidating desktop persistence, restore reconciliation, lifecycle coordination, and regression coverage. - Preserve active drafts and attachments, request-scoped workspace ownership, deletion tombstones, renderer authority, and bounded shutdown behavior. - Fix the reported macOS cleanup failure with targeted BSD process queries and random-token-guarded process-group cleanup, without an unverified PID fallback. ## Platform hardening - Ignore development renderer origins in packaged Electron builds. - Preserve staged Tauri navigation authority and handle confirmed Windows session-end shutdown on the UI thread. - Bound workspace launch preflight, runtime startup, and health readiness. - Retain cleanup ownership after unexpected leaders exit and verify portable POSIX descendants by immutable identity or inherited launch token. - Add real Darwin-only process-group integration tests for macOS CI. ## Scope - 96 files changed. - 6,295 additions and 12,167 deletions, a net reduction of 5,872 lines from the merged implementation. - Consolidated duplicated tests while retaining focused race, durability, cleanup, and platform contracts. ## Validation - pm run typecheck - pm run typecheck --workspace @neuralnomads/codenomad - Electron native suite: 60 passed - Tauri suite: 49 passed - Focused server lifecycle/identity suite: 31 passed, 2 Darwin-only skipped on Windows - Focused UI restore/codec/reconciliation suite: 36 passed - Broader server suite: 59 passed, 3 platform skips - Broader UI suite: 97 passed, 1 skip; 2 Node 25 solid-toast loader failures reproduced on the merged baseline - git diff --check - Final limited gatekeeper: PASS for server/macOS, UI restore, and Electron/Tauri
48 lines
1.5 KiB
TypeScript
48 lines
1.5 KiB
TypeScript
import { session, systemPreferences } from "electron"
|
|
import { isAllowedRendererOrigin } from "./renderer-origin"
|
|
|
|
export { isAllowedRendererOrigin } from "./renderer-origin"
|
|
|
|
const isMac = process.platform === "darwin"
|
|
|
|
export function configureMediaPermissionHandlers(getAllowedOrigins: () => string[]) {
|
|
const isAudioMediaRequest = (permission: string, details?: unknown) => {
|
|
if (permission !== "media") {
|
|
return false
|
|
}
|
|
|
|
const mediaTypes = (details as { mediaTypes?: string[] } | undefined)?.mediaTypes ?? []
|
|
return mediaTypes.length === 0 || mediaTypes.includes("audio")
|
|
}
|
|
|
|
session.defaultSession.setPermissionCheckHandler((_webContents, permission, requestingOrigin, details) => {
|
|
if (!isAudioMediaRequest(permission, details)) {
|
|
return false
|
|
}
|
|
|
|
return isAllowedRendererOrigin(requestingOrigin, getAllowedOrigins())
|
|
})
|
|
|
|
session.defaultSession.setPermissionRequestHandler((webContents, permission, callback, details) => {
|
|
if (!isAudioMediaRequest(permission, details)) {
|
|
callback(false)
|
|
return
|
|
}
|
|
|
|
const requestingOrigin = (details as { requestingOrigin?: string } | undefined)?.requestingOrigin || webContents.getURL()
|
|
callback(isAllowedRendererOrigin(requestingOrigin, getAllowedOrigins()))
|
|
})
|
|
}
|
|
|
|
export async function requestMicrophoneAccess(): Promise<boolean> {
|
|
if (!isMac) {
|
|
return true
|
|
}
|
|
|
|
const status = systemPreferences.getMediaAccessStatus("microphone")
|
|
if (status === "granted") {
|
|
return true
|
|
}
|
|
|
|
return systemPreferences.askForMediaAccess("microphone")
|
|
}
|