Explain blocked browser-profile access; hide Chrome for Testing - #16
Merged
Merged
Conversation
Playwright and Puppeteer install an automation-only Chrome build that registers as an https handler, so it showed up next to real Google Chrome in rules, the picker, and Settings → Browsers. It has no profile support, and picking it by mistake looked like the Profile dropdown was broken. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019Y9gVVaoGd4dCz42XkXkpP
On recent macOS, reading another browser's Local State or profiles.ini is refused with EPERM unless Junction has Full Disk Access. There is no permission prompt for it, and the profile readers failed quietly to an empty list, so the rule editor's Profile dropdown and Settings → Browsers simply showed no profiles. BrowserDiscovery.isProfileAccessBlocked tells a denied read (EPERM) apart from a missing file (ENOENT). AppState refreshes it with the browser list, and a shared notice with an "Open System Settings…" button and a "Check Again" button now appears in Settings → Browsers, in the rule editor in place of the Profile picker, and on the onboarding default-browser step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019Y9gVVaoGd4dCz42XkXkpP
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
First launch, Privacy, and the profile action now say that listing browser profiles needs Full Disk Access, what Junction reads with it, and what still works without it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019Y9gVVaoGd4dCz42XkXkpP
This was referenced Sep 27, 2026
jnahian
added this pull request to stack #19
September 27, 2026 05:53
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The rule editor showed no Profile dropdown for Google Chrome, and Settings → Browsers listed no profiles for any browser. Chrome's
Local Stateparsed fine from Terminal, but a normal app (tested with a throwaway signed bundle launched viaopen) getsOperation not permittedreading it, Firefox'sprofiles.ini, or Edge'sLocal State. There is no prompt, and nothing is logged. Only Full Disk Access unblocks it, and the profile readers silently turned the denial into "no profiles".What
BrowserDiscovery.isProfileAccessBlockedopens each installed Chromium/Firefox profile file and reports a block only onEPERM. A missing file (ENOENT, never launched) doesn't count.FileHandle's Cocoa error code turned out to be unreliable here (513, not 257), hence plainopen(2).AppState.profileAccessBlockedrefreshes with the browser list.FullDiskAccessNotice("Open System Settings…" deep link + "Check Again") appears in Settings → Browsers, in the rule editor in place of the Profile picker, and on the onboarding default-browser step.com.google.chrome.for.testing, installed by Playwright/Puppeteer) from browser discovery. It sat next to real Chrome and has no profile support.Unreleased, plus a troubleshooting entry on the docs site.Not changed (follow-up)
Dispatcherchecks that a Firefox profile exists by readingprofiles.ini. With access blocked, every Firefox profile rule degrades to the fallback with the reason "profile no longer exists". Trusting the rule instead risks Firefox's profile manager eating the link, so this needs a decision.Testing
swift buildandswift testpass.cd web && npm testpasses.Local State→ blocked, readable context → not blocked, missing file → not blocked.🤖 Generated with Claude Code
https://claude.ai/code/session_019Y9gVVaoGd4dCz42XkXkpP