Permissions
An extension gets exactly the permissions it declares in manifest.json and the user approved in the review dialog. The Extension Host checks them on every call; a call without its permission is rejected with an error naming the permission, and logged.
| Permission | Risk | Allows | API |
|---|---|---|---|
sessions.read | Low | Names, hosts, users, groups, environments of saved sessions and which one is active. Never passwords, keys or key paths. | sessions.list, sessions.getActive, sessions.onDidChangeActive |
context.read | Low | Shellaro Context of the active terminal: hostname, shell user, root, OS, directory, Git branch, Kubernetes context and namespace, tools. | context.get, context.onDidChange |
ui.commands | Low | Commands in the command palette (declared in contributes.commands). | commands.registerCommand |
ui.sidebar | Low | A sidebar view drawn by Shellaro (declared in contributes.views). | views.* |
storage | Low | Up to 1 MB of the extension's own data on this computer. | storage.* |
runbooks.read | Low | The user's runbooks and installed Command Packs. | runbooks.list |
runbooks.run | Medium | Opens a runbook for the active terminal; each step still waits for the user and Command Safety. | runbooks.start |
sftp.read | Medium | Lists folders and reads text files over the active session's SFTP. | sftp.list, sftp.readText |
local.cluster | Medium | Create, start, stop and delete Shellaro's local Kubernetes cluster (k3s in Docker on this computer) and its session. Creating and deleting always ask you, naming the extension. | localCluster.* |
network | Medium | https requests to the hosts in network.hosts, made by Shellaro. | network.fetch |
terminal.execute | High | Runs a command in a visible terminal (active, new tab or split), as if typed. Command Safety checks it first. | terminal.execute |
remote.exec | High | Runs commands on connected servers without showing them in a terminal. Command Safety checks every command, and the user allows each server once ("Always allow on <server>" or "Allow once"). | remote.exec |
sftp.write | High | Writes files over SFTP. | sftp.writeText |
Messages, pickers, input boxes, confirmations and the document viewer need no permission; they always show the extension's name.
Rules that hold for every extension
- No permission gives access to passwords, passphrases, private keys, key file paths, Credential Manager, API keys, tokens or Shellaro's settings. Shellaro performs the operation and returns plain data.
- Every command an extension sends to a server (
terminal.execute,remote.exec) goes through Command Safety with the origin "From the <name> extension" (background commands: "Background command from the <name> extension (not shown in the terminal)"). - Packages that request an unknown permission are refused; this version of Shellaro will not install them rather than ignore the request.
- An update that asks for more (new permissions or new network hosts) shows only what is new, and is not installed until approved. Until then the old version keeps running.
- Background-command consents are listed per extension in the Marketplace (Permissions tab) and can be revoked there; uninstalling removes them.
- Development extensions (Developer Mode) follow the same rules: their permissions are approved when the folder is loaded, and again when the manifest asks for more.