mirror of
https://github.com/penpot/penpot.git
synced 2026-10-10 13:11:41 -04:00
A plugin with "scope": "global" keeps running across the dashboard and files and can find and open the user's projects and files. Any manifest could ask for this without the user being told. Add the allow:global permission. The plugin registry adds it to every manifest with global scope, so the install dialog lists it, and a plugin that becomes global in a later version shows the permissions update dialog again. The permission is valid in the shared schema, which the backend checks when saving, and in the runtime manifest schema. The built-in MCP plugin declares it too. Document the scope property and the new permission for plugin developers.