Skip to content

feat(desktop): enable meeting microphone access (MEET-8) - #371

Merged
eliotlim merged 2 commits into
feat/meet-3-local-whisperfrom
feat/meet-8-desktop-mic
Oct 4, 2026
Merged

eliotlim merged 2 commits into
feat/meet-3-local-whisperfrom
feat/meet-8-desktop-mic

Conversation

@eliotlim

@eliotlim eliotlim commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Problem

The desktop app (Tauri/WKWebView) had no microphone entitlement, no usage description, and no documented permission path — meeting recording (MEET-5 / #369) was web-only. Board: MEET-8.

Solution

com.apple.security.device.audio-input entitlement; new src-tauri/Info.plist with an honest NSMicrophoneUsageDescription (merged via Tauri 2's bare-Info.plist convention — verified against the locked tauri-codegen/bundler source); module docs recording Wry 0.55.1's media-capture delegate behavior (retained, comment-only Rust change); IPC transport test proving two 360 KB chunks (webm+mp4) round-trip byte-for-byte through desktop base64 IPC within the server's exact cap formula. Stacked on #369 — merge after it. No deps, no signing config touched.

Key files: packages/app/src-tauri/{entitlements.plist,Info.plist,src/main.rs}, packages/app/src/data/microphoneTransport.test.ts, packages/app/README.md.

Before / After

Behavior Before After
getUserMedia in desktop app fails (no entitlement/usage string; hardened app would crash on prompt) OS TCC prompt → recording works (signed build) — manual steps in README
Audio chunk over desktop IPC untested byte-for-byte round-trip test vs the server cap formula
Denied permission n/a MEET-5's graceful copy (existing automated tests)

No visual change (native plumbing).

Test procedure

pnpm verify green; cargo check --locked green; pnpm --filter @book.dev/app test. Live: README §Manual microphone verification (build, launch, record >45s two chunks, reload persistence, TCC deny/recover).

Operational notes

Owner acceptance required on a SIGNED build (signing key unavailable to agents, config untouched): run the README manual steps; step 2's OS prompt implicitly proves the Info.plist merged (hardened runtime hard-crashes without the purpose string — or plutil -p .../Contents/Info.plist | grep Microphone). Security containment verified in review: nav guard keeps webview first-party; artifact iframes have opaque origins + empty permissions policy. Follow-up filed (MEET-11): gate loopback origins to dev builds — a release-build co-resident-attacker hardening, not a blocker.


Verify: green (full suite + both e2e). Reviews cleared: security (Sasha), code (Quinn) — zero fix rounds.

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
app.book.pub Ready Ready Preview Oct 4, 2026 2:09pm UTC

Request Review

@eliotlim
eliotlim changed the base branch from main to feat/meet-3-local-whisper October 4, 2026 14:09
@eliotlim
eliotlim merged commit 26ccf46 into feat/meet-3-local-whisper Oct 4, 2026
11 of 12 checks passed

This branch was successfully deployed

1 active deployment
Preview — 759cc8f0 Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant