Capabilities and restrictions
Declare only the capabilities your plugin uses. The sandbox client and host both enforce grants, which are confirmed together with the code hash.
| Capability | Available services |
|---|---|
| storage | Plugin-private JSON get/set/delete |
| settings | Manifest-defined preference get/set |
| ui | Dialogs, panels, overlays, composer and right-click menu items, sandbox views, a settings page, theme snapshots, notices |
| patcher | Checked transforms at the named hooks, including the badges drawn next to names |
| messages | Validated embeds in the current channel, or text typed into the message box, right after a user action in the plugin |
| styling | Validated, disposable selector rules |
| inspection | Sanitized element events, optionally intercepting inspected clicks |
| shortcuts | Host keyboard shortcut registrations |
| images | PNGs from any public HTTPS address, loaded without asking the user |
| clipboard | Text writes right after a user action in the plugin |
| attachments | Posted-file context actions and bounded metadata lookup |
| external_links | Public HTTPS links, after an attachment action or a user action in the plugin |
| badges | Badges next to names, from community role lists; the host looks up members’ roles |
| navigation | The open community and channel, and changes to them |
| guild_data | Name, icon, roles (with permissions) and channels of communities opened this session |
| decorations | Content below messages and next to names; sees on-screen message, author and member ids |
| message_content | The text of messages on screen, in decorations and right-click targets |
| network | HTTPS requests to the hosts listed in the manifest, without asking the user |
| activity | Whether Fluxer is focused, shown and idle; never input or timestamps |
| voice | Whether the user is in a voice call, and the ids of its channel and community |
navigation, guild_data, decorations, message_content, network, activity and voice need FluxPlugs 0.5.0-beta.1 or later; older runtimes refuse manifests that list them, as they do any capability they don’t know.
Check a grant
Section titled “Check a grant”if (api.capabilities.has("storage")) { const previous = await api.storage.get<string>("last-view"); api.logger.debug("Stored view available", { available: previous !== undefined, });}A capability check does not replace error handling: the current context, input, resource limits, and instance lifetime can still make an operation fail.
Unavailable privileges
Section titled “Unavailable privileges”The network capability reaches only the hosts listed in the manifest’s network.hosts. The hosts are confirmed together with the code hash, so changing them needs a new confirmation. The main process makes each request: HTTPS only, public IPv4 addresses, no cookies, bounded bodies and a 10-second deadline. See network requests.
The images capability is the exception to watch: the main process fetches any public HTTPS URL the plugin names, without a user action, so the URL itself can carry data to a server. Treat images as a network capability when you review a plugin.
The badges and guild_data capabilities give a plugin the role lists of communities the user opens, including each role’s permissions, which Fluxer’s own UI doesn’t show to everyone. FluxPlugs fetches them, and the roles of people on screen, with the user’s account. Plugins never receive credentials, members’ roles, presence or profiles.
The decorations capability shows a plugin the ids of messages, authors and members on screen without any user action, and message_content adds the text of those messages. A plugin that combines them with images could send that data out through an image URL, so treat the combination like a network capability. With network, such a plugin can send the text and ids of messages on screen to its listed hosts; the enable prompt warns about this.
The activity and voice capabilities tell a plugin when the user is at Fluxer and which voice channel they are in, without any user action. Plugins get flags and ids only, never input, timestamps, names or audio. With network, the enable prompt warns that the plugin can send this to its listed hosts. See activity and voice.
A user action means a trusted click, key press or submit in the plugin’s own UI: a dialog submit, an overlay action button, a registered shortcut, an attachment action, a right-click menu item, a decoration button, or a click while the plugin inspects the page. It opens a 1.5-second window that the first gated call uses up. Synthetic events don’t count.
Plugins have no Node/Electron APIs, filesystem, parent DOM, top navigation, popups, or remote scripts. Direct fetch/connect from the frame is blocked. The network, image, attachment lookup and browser navigation services each have narrower rules.
Core owns credentials and transport. Handles belong to a plugin instance and cannot be transferred. New privileged operations require a bounded core extension; see extending the SDK.
