Say only what is true in the __sourceDir comment

Bar widget instances are not handed sourceDir (ModuleSlot.injectProps sets only bar, moduleName and settings), and a plugin could reach its directory through Qt.resolvedUrl, so the comment's rationale was wrong on both counts. Two lines carry what the code cannot say.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
OmarchybotandClaude Opus 5.5 committed 2026-10-01 04:49:25 +02:00
1 parent 6df574cbb4
commit 146fe5d368
1 file changed
+2 -7
+2 -7
View File
@@ -317,13 +317,8 @@ ShellRoot {
if (!manifest) return null
if (manifest.__isFirstParty) return manifest
var copy = JSON.parse(JSON.stringify(manifest))
// __sourceDir is the plugin's own install directory, not a privilege
// signal: a third-party service/panel plugin needs it to locate its
// bundled scripts and assets (barWidgets already receive it via
// meta.sourceDir, but service/panel instances get only this manifest).
// Stripping it left those plugins with no way to find their own files,
// silently breaking every plugin that shells out to a bundled script.
// Only the true privilege markers below are withheld from third parties.
// Keep __sourceDir: third-party plugins find their bundled scripts through it.
// Only the host trust markers are withheld.
delete copy.__isFirstParty
delete copy.__hostCapabilities
return copy