Skip to main content

rightkit_control/
lib.rs

1//! rightkit-control: drive a real desktop app like a human, in the background.
2//!
3//! macOS: embedded targets receive main-thread AppKit `NSEvent`s through the
4//! WKWebView responder, including hidden, non-key windows. Non-embedded targets
5//! use per-pid `CGEventPostToPid` (never the global HID tap); inactive-window
6//! first-mouse handling can discard their press. Neither path activates apps
7//! or moves the user's cursor.
8//! State is read through the Accessibility API and window captures.
9//!
10//! Control-plane guarantees (CodeRight EFF-001 / PTY-002):
11//! - [`admission::EffectGate`]: every effectful request is validated, approved
12//!   by a host [`admission::AdmissionHook`], executed, and settled; a denial
13//!   happens before any side effect.
14//! - [`lease::InputLease`]: input carries `(epoch, sequence)`; stale epochs are
15//!   fenced, duplicates are deduplicated, unacknowledged input must be
16//!   explicitly reconciled. [`lease::ControlSession`] composes both.
17//! - [`events::ControlEvent`]: content-free lifecycle events for the journal.
18//!
19//! - [`lease_store`]: optional durable lease state (store trait plus an
20//!   atomic file store), execution identity and `Running | Exited | Unknown`.
21//!
22//! Every effectful entry point routes through the gate: `webdriver::Server`,
23//! the `tauri-plugin` server, `mac::Gated` and the `rightkit-control` CLI
24//! ([`cli`]). The raw macOS primitives are reachable only through the
25//! explicitly named `mac::unsafe_ungated` opt-in.
26pub mod admission;
27pub mod cli;
28#[cfg(feature = "tauri-plugin")]
29pub mod embedded;
30pub mod events;
31pub mod json;
32pub mod keys;
33pub mod lease;
34pub mod lease_store;
35#[cfg(target_os = "macos")]
36pub mod mac;
37pub mod webdriver;