fix: app-launch macros on Windows + bump to 1.1.1 #10

Merged
jknapp merged 1 commits from fix/app-launch-windows into main 2026-07-18 05:59:36 +00:00
3 changed files with 16 additions and 8 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
# Configuration and constants for MacroPad Server # Configuration and constants for MacroPad Server
VERSION = "1.1.0" VERSION = "1.1.1"
DEFAULT_PORT = 40000 DEFAULT_PORT = 40000
SETTINGS_FILE = "settings.json" SETTINGS_FILE = "settings.json"
+12 -4
View File
@@ -416,13 +416,21 @@ class MacroManager:
elif cmd_type == "app": elif cmd_type == "app":
# Launch application. # Launch application.
# SECURITY: shell=True was removed to kill shell-metacharacter # SECURITY: never use shell=True — that would allow shell-metacharacter
# injection (no ; && | $() chaining). We tokenize the command # injection (; && | $() chaining, redirection). Both branches below run
# and exec the program directly without a shell. # without a shell, so the command can only launch a program with args.
command = cmd.get("command", "") command = cmd.get("command", "")
if command: if command:
try: try:
args = shlex.split(command, posix=(os.name != "nt")) if os.name == "nt":
# Windows: pass the string so CreateProcess parses it
# (correctly handling quoted paths like "C:\Program
# Files\app.exe"). shell=False means no cmd.exe, so no
# metacharacter chaining.
subprocess.Popen(command)
else:
# POSIX: split into an argv list; no shell involved.
args = shlex.split(command)
if args: if args:
subprocess.Popen(args) subprocess.Popen(args)
except Exception as e: except Exception as e:
+1 -1
View File
@@ -1 +1 @@
1.1.0 1.1.1