Root cause of #1013 (macOS: "Microphone access denied" but OmniVoice never appears in Privacy & Security → Microphone to enable it): Tauri's macOS bundle config defaults `hardenedRuntime` to true, and Hardened Runtime blocks camera/microphone hardware access unless the matching entitlement is present — regardless of Info.plist's NSMicrophoneUsageDescription (that only supplies the *prompt text*, it isn't itself the grant) and regardless of wry's own WKUIDelegate already granting the request at the WebKit/JS layer (WryWebViewUIDelegate::request_media_capture_permission unconditionally calls WKPermissionDecision::Grant — confirmed by reading wry 0.55.1's source; that part was never the problem). With Hardened Runtime on and zero entitlements, TCC never registers a request at all, which is exactly the reported symptom: nothing to enable because the OS never saw a legitimately-entitled process ask. This also explains the workaround in #1013 and its comments (launching the raw binary from Terminal works, but as Terminal's identity, not the app's) — Terminal is a properly entitled, hardened-runtime process; the ad-hoc/unentitled app binary isn't. Adds src-tauri/entitlements.plist (com.apple.security.device.audio-input, plus com.apple.security.device.camera matching the forward-looking NSCameraUsageDescription already in Info.plist) and wires it in via tauri.conf.json's bundle.macOS.entitlements. Also corrects the stale "nothing to do here" module comment in lib.rs that documented the incomplete assumption this bug falsified. Verified: built a debug .app (`tauri build --debug --bundles app`) and diffed `codesign -dv --entitlements -` before/after this change — the entitlements dictionary goes from absent to containing exactly the two keys added here, alongside the runtime (Hardened Runtime) flag that was already on. `cargo test` — 60 passed, 0 failed.
29 lines
1.3 KiB
Plaintext
29 lines
1.3 KiB
Plaintext
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
|
<plist version="1.0">
|
|
<dict>
|
|
<!--
|
|
Tauri's macOS bundle defaults `hardenedRuntime` to true. Hardened
|
|
Runtime blocks camera/microphone hardware access unless the matching
|
|
entitlement is present here — regardless of Info.plist's
|
|
NSMicrophoneUsageDescription and regardless of wry's own WKUIDelegate
|
|
already granting the request at the WebKit/JS layer
|
|
(WryWebViewUIDelegate::request_media_capture_permission unconditionally
|
|
calls WKPermissionDecision::Grant). Without this entitlement, TCC
|
|
never even registers a request for the app — nothing shows up in
|
|
System Settings → Privacy & Security → Microphone to enable, because
|
|
the OS never saw a legitimately-entitled process ask.
|
|
-->
|
|
<key>com.apple.security.device.audio-input</key>
|
|
<true/>
|
|
|
|
<!--
|
|
Matches Info.plist's forward-looking NSCameraUsageDescription — no
|
|
current feature uses the camera, but ship the entitlement now so a
|
|
future getUserMedia({video: true}) call doesn't hit this same bug.
|
|
-->
|
|
<key>com.apple.security.device.camera</key>
|
|
<true/>
|
|
</dict>
|
|
</plist>
|