Skip to content

Permissions

HarborClient uses a trusted-extension model similar to VS Code or Obsidian. Permissions are shown at install time and enforced in the main process on every privileged hc.* call.

PermissionGrants
uiAll hc.ui.register* methods, hc.themes.register, hc.imports.registerHandler, registerImportHandler, hc.ui.showToast, and hc.commands.register
storagePlugin-scoped persistent key-value storage via hc.storage
databasePlugin-scoped private SQLite database via hc.database (one file per plugin under userData)
filesystem:pickOpen and save dialogs; read and write only user-selected paths
filesystem:readRead from allowlisted paths (plugin directory plus granted paths)
filesystem:writeWrite to allowlisted paths
httpHook into or send HTTP from main via hc.http
networkOutbound HTTP from the renderer via hc.host.sendHttpRequest (gated by Settings → General)
ipcRegister custom IPC handlers via hc.ipc.handle
serverLocal HTTP echo server via hc.server (express listener in the Electron main process)

Filesystem access never uses raw Node fs in plugin code. Use hc.fs.* helpers only; the host checks permissions and path allowlists on each call.

Paths the user selects through hc.fs.pickFile, hc.fs.pickDirectory, or hc.fs.saveFile are added to the allowlist automatically and persist across app restarts. The host restores those grants when the plugin loads again; plugins do not need to re-prompt every session for the same file.

Declare required permissions in Manifest under permissions.