Repository navigation
Conversation
Some operations an app already exposes as an App Intent. Driving its interface to reach them is slower and more fragile than asking for the operation, and an intent runs without the window being usable or frontmost. macOS has no unentitled API that invokes an App Intent directly: the private LinkServices executor rejects any client that is not a validated bundle. The one supported route is Shortcuts, whose workflow action identifier for an App Intent is exactly `<bundle id>.<intent name>`. So the first call for an intent generates a one-action workflow, signs it with `shortcuts sign` and opens it for a one-time Add Shortcut; later calls run it. `shortcuts list` is the record of what is installed, so there is no separate binding table to drift from it. The limits sit at the narrowest point: only an app's own intents run (built-in `is.workflow.` actions are refused), the identifier must be dotted with non-empty segments of letters, digits, `_` and `-` so `/`, `..`, spaces and newlines never reach a filename, and installation needs the user's own click. Child stdin is `/dev/null`: `shortcuts` reads stdin when it is left attached, which would consume the runtime's own pipe. A 120s deadline terminates an intent that sits waiting, since reading to EOF only returns when the child exits.
Contributor
Author
|
@iFurySt checking in: this runs an app's App Intent by identity, a direct path for actions that have no stable UI. It conflicts with main now; I'll rebase if you're interested, otherwise feel free to say no and I'll close it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A macOS
run_intenttool that runs one of an app's App Intents by<bundle id>.<intent name>, instead of driving its interface.Why
Some operations an app already exposes as an intent. Clicking through the interface to reach them is slower and more fragile β and an intent runs without the window being usable or frontmost.
How, and why it looks like this
macOS has no unentitled API that invokes an App Intent directly; the private LinkServices executor rejects any client that is not a validated bundle. The one supported route is Shortcuts, and an App Intent's workflow action identifier is exactly
<bundle id>.<intent name>β the two fields the caller already has.So the first call for a given intent generates a one-action workflow, signs it with
shortcuts signand opens it for a one-time Add Shortcut by the user. Later calls run it viashortcuts run.shortcuts listis the record of what is installed, so there is no separate binding table to drift from it.The one-time approval is inherent to the platform, not a design choice I can remove.
Please review the safety boundary closely
This tool widens what the runtime can do, so the limits sit at the narrowest point:
is.workflow.Shortcuts actions are refused outright β notablyrunshellscript._and-, so/,.., spaces and newlines never reach a filename. Covered by a test that walks a list of hostile inputs./dev/nullβshortcutsreads stdin when left attached, which would consume the runtime's own pipe.docs/SECURITY.mdrecords these constraints.Honest caveat
Of the changes I am upstreaming from my fork, this is the most speculative one for a general audience β a capability expansion with a manual handshake, and an extra tool beyond the official nine. If you would rather it be opt-in, or not land at all, that is a reasonable call.
It also adds a tool on top of #73; if both land, the count assertion becomes 11 rather than 10 β happy to rebase whichever merges second.
Verification
swift buildcleanAppIntentExecutionTestsβ 3 tests covering identifier joining, built-in refusal, and path-character rejectionmake check-docspassesThe install-and-run path needs a real desktop with Shortcuts and is not covered by an automated test.