Permissions¶
A plugin's manifest asks; the user grants; the capability gate enforces. A plugin's ctx simply
has no attribute for a capability it was not given, so a mistake shows up the first time you run
the plugin rather than silently in a user's installation.
| Capability | Grants | Narrowed by |
|---|---|---|
files |
Read and write inside one folder | show, episode, or a path the user picks |
network |
HTTP requests | A host list in the manifest, held to at the gate |
llm.local |
Calls to Ollama on this machine | A model name, or a capability such as summarise |
llm.remote |
Calls to an external provider on the user's key | A monthly ceiling in euros |
transcription |
The built-in transcription service | — |
audio |
Decode, filter and mix the show's audio | — |
native |
Widgets in the UI process | Bundled plugins only |
What this is, and is not¶
Running a plugin in its own process stops it hanging the window, confines a crash, and lets the user kill it. Permissions make what a plugin reaches visible and revocable.
It is not a security sandbox. A determined plugin still runs with your user account. Treating the gate as a guardrail rather than a jail is the honest description. Podlibre shows where a plugin came from, so trust stays the user's decision, and asks again when a plugin that has been running reaches for something new.
Asking well¶
Ask for the least that works, and narrow it. network = ["api.castopod.org"] tells a user what
you will do; network = ["*"] tells them nothing. A publisher that names its host can be held to
it by the gate, and the user can see at a glance that it is not phoning somewhere else.