Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
apps/desktop/src-tauri/capabilities/default.json: most-fixed (1 issue). Treat as high-risk during review.
2 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Command Injection / Privilege Escalation: Child process spawning with inherited environment variables and global permission bypass allowed arbitrary command execution and privilege escalation.
Auth Bypass: Project directories were opened without re-authorization, allowing unauthorized filesystem access.
Privilege Escalation: Widening capability scope to all windows and adding window creation permissions could let a compromised webview gain elevated control.