Shellaro Download

Permissions

An extension gets exactly the permissions it declares in manifest.json and the user approved in the review dialog. The Extension Host checks them on every call; a call without its permission is rejected with an error naming the permission, and logged.

PermissionRiskAllowsAPI
sessions.readLowNames, hosts, users, groups, environments of saved sessions and which one is active. Never passwords, keys or key paths.sessions.list, sessions.getActive, sessions.onDidChangeActive
context.readLowShellaro Context of the active terminal: hostname, shell user, root, OS, directory, Git branch, Kubernetes context and namespace, tools.context.get, context.onDidChange
ui.commandsLowCommands in the command palette (declared in contributes.commands).commands.registerCommand
ui.sidebarLowA sidebar view drawn by Shellaro (declared in contributes.views).views.*
storageLowUp to 1 MB of the extension's own data on this computer.storage.*
runbooks.readLowThe user's runbooks and installed Command Packs.runbooks.list
runbooks.runMediumOpens a runbook for the active terminal; each step still waits for the user and Command Safety.runbooks.start
sftp.readMediumLists folders and reads text files over the active session's SFTP.sftp.list, sftp.readText
local.clusterMediumCreate, start, stop and delete Shellaro's local Kubernetes cluster (k3s in Docker on this computer) and its session. Creating and deleting always ask you, naming the extension.localCluster.*
networkMediumhttps requests to the hosts in network.hosts, made by Shellaro.network.fetch
terminal.executeHighRuns a command in a visible terminal (active, new tab or split), as if typed. Command Safety checks it first.terminal.execute
remote.execHighRuns commands on connected servers without showing them in a terminal. Command Safety checks every command, and the user allows each server once ("Always allow on <server>" or "Allow once").remote.exec
sftp.writeHighWrites files over SFTP.sftp.writeText

Messages, pickers, input boxes, confirmations and the document viewer need no permission; they always show the extension's name.

Rules that hold for every extension