Skip to main content

Crate rightkit_control

Crate rightkit_control 

Source
Expand description

rightkit-control: drive a real desktop app like a human, in the background.

macOS: embedded targets receive main-thread AppKit NSEvents through the WKWebView responder, including hidden, non-key windows. Non-embedded targets use per-pid CGEventPostToPid (never the global HID tap); inactive-window first-mouse handling can discard their press. Neither path activates apps or moves the user’s cursor. State is read through the Accessibility API and window captures.

Control-plane guarantees (CodeRight EFF-001 / PTY-002):

Every effectful entry point routes through the gate: webdriver::Server, the tauri-plugin server, mac::Gated and the rightkit-control CLI (cli). The raw macOS primitives are reachable only through the explicitly named mac::unsafe_ungated opt-in.

Modules§

admission
EFF-001 effect admission: every effectful control request traverses one authority, validate → (policy) → approval → execute → settle, and a denial is final before any side effect.
cli
rightkit-control command-line dispatch. Every effectful subcommand is admitted through one EffectGate (EFF-001); read-only subcommands (trusted, frontmost, windows, ax, find) are not effects.
events
Content-free lifecycle events for the caller’s journal.
json
Minimal JSON helpers for the WebDriver wire (flat string extraction only).
keys
US-layout virtual keycodes for named keys (typed text uses Unicode events).
lease
PTY-002 input lease: epoch fencing plus monotonic, acknowledged input sequence so a stale controller can never inject input.
lease_store
PTY-002 durable lease state: execution identity, Running | Exited | Unknown execution state, and a store that lets an InputLease survive a host restart or crash without its epoch going backwards or its unacknowledged input being silently forgotten.
webdriver
W3C-WebDriver-shaped session bridge over a native Backend.