Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -158,8 +158,12 @@ enum SelectionGrabber {
|
||||
}
|
||||
guard pb.changeCount != before else { return nil }
|
||||
let text = pb.string(forType: .string)
|
||||
// Restore what the user had copied.
|
||||
// Restore what the user had copied — except secrets: password managers mark them
|
||||
// concealed/transient and clear them on their own; putting them back would defeat that.
|
||||
pb.clearContents()
|
||||
let secretTypes: Set<String> = ["org.nspasteboard.ConcealedType", "org.nspasteboard.TransientType",
|
||||
"org.nspasteboard.AutoGeneratedType", "com.agilebits.onepassword"]
|
||||
if saved.contains(where: { $0.keys.contains { secretTypes.contains($0.rawValue) } }) { return text }
|
||||
let items = saved.map { dict -> NSPasteboardItem in
|
||||
let it = NSPasteboardItem()
|
||||
for (t, v) in dict { it.setData(v, forType: t) }
|
||||
|
||||
Reference in New Issue
Block a user