Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.
Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.
Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).
moecables · · focus · HN ↗
- Ghostty (fine, it's my terminal)
- Alfred (fine, I use it for searching everywhere)
Then I have a few turned off:
- Spotify (why does it need full disk access) ??
- Gemini (nope, don't need it to know everything about my computer)
coderbants · · focus · HN ↗
Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.
Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).
ashishb · · focus · HN ↗
Indeed, I run all dev tools including coding agents inside sandbox now
<a href="https://github.com/ashishb/amazing-sandbox" rel="nofollow">https://github.com/ashishb/amazing-sandbox
jackjeff · · focus · HN ↗
If you open a project using a devcontainer it prompts you to build one. As long as you install all the tools you need in it, it just works.
Orbstack is much nicer than Docker to host the containers.