Skip to main content

ADR 0013: Narrow Host↔UI IPC Bridge


Context​

If the React webview receives ambient filesystem, shell, or arbitrary HTTP for career data, the outbound boundary and plugin sandbox become theater. Tauri enables tight command allowlists; we must commit to deny-by-default.

Alternatives considered:

OptionProsCons
Allowlisted commands + event subscriptionEnforces architecture lawsEvery feature needs a command
Expose Node/fs to rendererFamiliar to web appsPrivacy defect
Full REST localhost server unboundedEasy debuggingLarge attack surface

Decision​

Use a narrow, deny-by-default IPC bridge between UI and host.

  • UI invokes explicit commands: preferences, agent control, queue approve/reject, send-under-policy, follow-ups, plugin enablement, sanitized logs.
  • UI subscribes to batched domain events / model health for badge and toasts.
  • No generic eval, raw fs, or unbounded fetch from the renderer for career payloads.
  • Prefer Tauri command/event primitives aligned with this allowlist.

Consequences​

Positive​

  • Renderer stays presentation-focused.
  • Egress and storage remain host-side and reviewable.
  • Matches testing strategy for bridge deny-by-default.

Negative / tradeoffs​

  • New UI flows need host command work — intentional.
  • Developers must not “just fetch from the client” for boards.

Follow-ups​

  • Document command catalog beside implementation.
  • Contract tests attempt forbidden bridge operations and expect failure.