Repository navigation
fix(darwin): honour Permissions for media capture requests - #6144
Conversation
Recover the implementation and tests from closed PR #6050 after its temporary base branch was deleted. Port the permission docs to the current M-Press tree and refresh the translation audit records. Co-authored-by: stefan <stefan@znipp.ch>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: wailsapp/wails/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. WalkthroughmacOS 12 and later now apply per-window ChangesmacOS media permission handling
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant WebContent
participant WebviewWindowDelegate
participant resolveMediaCapturePermission
participant TCC
WebContent->>WebviewWindowDelegate: Request camera or microphone
WebviewWindowDelegate->>resolveMediaCapturePermission: Resolve permission for window
resolveMediaCapturePermission-->>WebviewWindowDelegate: Prompt, grant, or deny
WebviewWindowDelegate-->>WebContent: Return WebKit decision
WebContent->>TCC: Request device access
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The reviewed changes align macOS camera and microphone policy with the documented WebKit and TCC behavior. No concrete merge-blocking issue is established; native macOS CI should still validate the change. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change is limited to macOS camera and microphone permissions. Explicit allow settings remove a consent prompt for eligible content within the configured window, while system device consent remains required. Native macOS validation is still outstanding. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 54.55% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the camera gate, Comment |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It introduces Darwin-only Objective-C/WebKit delegate behavior that needs macOS CI compilation/runtime verification to confidently approve.
Review effort: Lite
Findings: None
What changed in this PR
This PR restores and completes the macOS (Darwin) implementation of Wails v3 WebviewWindowOptions.Permissions for media capture, ensuring camera/microphone getUserMedia requests on macOS 12+ are decided according to the configured policy (instead of always falling back to WebKit’s default prompt behavior). It also updates the permissions documentation (including translations) and records the fix in the unreleased changelog.
Changes:
- Implement
WKUIDelegatemedia-capture permission handling on macOS 12+ and route decisions through the existing WailsPermissionsmap. - Add focused Darwin unit tests covering decision mapping and unknown-window behavior.
- Update the permissions documentation (and translations) plus translation-audit exceptions and the v3 UNRELEASED changelog entry.
| File | Description |
|---|---|
| v3/UNRELEASED_CHANGELOG.md | Adds a changelog entry documenting the macOS 12+ Permissions fix for camera/microphone capture. |
| v3/pkg/application/webview_window_darwin.m | Implements the WKUIDelegate media-capture permission request method and forwards decisions to Go. |
| v3/pkg/application/permissions_darwin.go | Adds Darwin decision logic mapping Permissions → WKPermissionDecision (prompt/grant/deny). |
| v3/pkg/application/permissions_darwin_test.go | Adds Darwin-only unit tests to pin decision constants and verify strictest-wins/lookup behavior. |
| docs/mpress/translation/audit-exceptions.json | Refreshes translation audit exceptions for updated platform headings. |
| docs/mpress/content/features/windows/permissions.md | Updates canonical docs to reflect macOS 12+ support for camera/microphone Permissions and the TCC layer. |
| docs/mpress/content/de/features/windows/permissions.md | German translation update for the revised macOS permissions section. |
| docs/mpress/content/fr/features/windows/permissions.md | French translation update for the revised macOS permissions section. |
| docs/mpress/content/id/features/windows/permissions.md | Indonesian translation update for the revised macOS permissions section. |
| docs/mpress/content/ja/features/windows/permissions.md | Japanese translation update for the revised macOS permissions section. |
| docs/mpress/content/ko/features/windows/permissions.md | Korean translation update for the revised macOS permissions section. |
| docs/mpress/content/pt/features/windows/permissions.md | Portuguese translation update for the revised macOS permissions section. |
| docs/mpress/content/ru/features/windows/permissions.md | Russian translation update for the revised macOS permissions section. |
| docs/mpress/content/zh-cn/features/windows/permissions.md | Simplified Chinese translation update for the revised macOS permissions section. |
| docs/mpress/content/zh-tw/features/windows/permissions.md | Traditional Chinese translation update for the revised macOS permissions section. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Tested this on macOS 26.6.2 (arm64) in our app. We were carrying a vendor patch that added this same delegate, and I swapped it out for this PR with |
This recovers the implementation that was unintentionally stranded when #6050's temporary base branch was deleted after the documentation migration merged.
The original PR contained real Darwin code and tests, not just documentation:
WKUIDelegatemedia-capture permission handling for macOS 12+Permissionsmapping for camera and microphone requestsThe original implementation and tests were authored by Stefan (@fan711); this recovery preserves him as co-author. See the original PR: #6050.
Checks
go test ./pkg/application -skip '^TestX11GlobalShortcutEndToEnd$'go test -race ./pkg/application -skip '^TestX11GlobalShortcutEndToEnd$'bash docs/mpress/scripts/build.shThe X11 integration test is excluded because this environment does not deliver its synthesized key callback. Native macOS compilation and runtime validation still need to run in macOS CI.
Closes #6067.
Summary by CodeRabbit
New Features
Documentation
Bug Fixes