Skip to main content

rightkit_control/
lib.rs

1//! rightkit-control: drive a real desktop app like a human, in the background.
2//!
3//! macOS: input is posted to the target pid with `CGEventPostToPid` (never the
4//! global HID tap), so the frontmost app and the user's cursor are untouched.
5//! State is read through the Accessibility API and window captures.
6//!
7//! Control-plane guarantees (CodeRight EFF-001 / PTY-002):
8//! - [`admission::EffectGate`]: every effectful request is validated, approved
9//!   by a host [`admission::AdmissionHook`], executed, and settled; a denial
10//!   happens before any side effect.
11//! - [`lease::InputLease`]: input carries `(epoch, sequence)`; stale epochs are
12//!   fenced, duplicates are deduplicated, unacknowledged input must be
13//!   explicitly reconciled. [`lease::ControlSession`] composes both.
14//! - [`events::ControlEvent`]: content-free lifecycle events for the journal.
15//!
16//! The raw `mac` primitives are ungated building blocks; host-facing surfaces
17//! (`webdriver::Server`, the `tauri-plugin` server) route through the gate.
18pub mod admission;
19#[cfg(feature = "tauri-plugin")]
20pub mod embedded;
21pub mod events;
22pub mod json;
23pub mod keys;
24pub mod lease;
25#[cfg(target_os = "macos")]
26pub mod mac;
27pub mod webdriver;