Teleport review
The review and consent before a teleport: what to send per site, from the app or from the Keyvault, and the choice remembered for next time.
The review and consent before a teleport: what to send per site, from the app or from the Keyvault, and the choice remembered for next time.
These APIs are part of the Cua Spaces app export for building Spaces UIs. They are source-available under FSL-1.1-MIT and ship for Swift only (import CuaSpacesFFI); the Rust tab shows the cua-spaces-ffi crate they come from. The open source SDK packages for Python, TypeScript and Kotlin do not include them.
AppReviewView is the review sheet. AppReviewToggle and AppReviewChoice change what is sent, per site or per part; app_review_remember keeps the choice for the next teleport of the same app to the same Space, and AppVaultSource offers the items the Keyvault already holds, which need no Keychain prompt.
AppReviewView record#Returned by app_picker_review.
| Field | Type | Default | Description |
|---|---|---|---|
title | String | "Teleport Slack to Aurora". | |
items | Vec<AppConsentItem> | The consent lines. | |
steps | Vec<AppPlanStepView> | Plan steps. | |
needs_acknowledgement / needsAcknowledgement | bool | The secrets checkbox shows. | |
acknowledged | bool | Checked. | |
offers_save_to_keyvault / offersSaveToKeyvault | bool | The "Save to Keyvault" checkbox shows (a sensitive plan only: there is nothing to keep sealed otherwise). | |
save_to_keyvault / saveToKeyvault | bool | Checked. | |
needs_relay_plaintext_acknowledgement / needsRelayPlaintextAcknowledgement | bool | The relay-plaintext warning's checkbox shows (S1): this Space predates end-to-end sealing, and the Cua relay could read this secret in transit. | |
acknowledged_relay_plaintext / acknowledgedRelayPlaintext | bool | Checked. | |
can_confirm / canConfirm | bool | "Teleport" is enabled. | |
leaves_text / leavesText | Option<String> | "12 MB leaves this Mac" (none when nothing leaves). | |
warnings | Vec<String> | Caveats. | |
toggles | Vec<AppReviewToggle> | Lines the user can turn off (files, folders, state, secrets), each with whether it is sent. The cookie store is the site list below. | |
offers_domains / offersDomains | bool | The plan sends a browser's cookies, so the sites can be chosen. | |
needs_domains / needsDomains | bool | The sites have not been read yet (the shell asks the Keyvault for them, which may ask for Touch ID). | |
domains | Vec<AppReviewDomain> | The sites with counts, filtered by the search. | |
domain_summary / domainSummary | String | "3 of 12 sites". | |
domain_query / domainQuery | String | The sites search text. | |
selected_domains / selectedDomains | Vec<String> | The sites chosen (what is remembered for next time). | |
source | AppSendSource | Where it sends from. | |
offers_vault / offersVault | bool | The app has saved Keyvault items to send instead of reading the live app. | |
vault | AppVaultSource | The saved items. | |
vault_label / vaultLabel | String | "Send from the Keyvault (212 items, saved 2 days ago)". | |
live_label / liveLabel | String | "Read Chrome now (macOS asks for Keychain access)". | |
offers_passwords / offersPasswords | bool | "Also send saved passwords" shows (there are some to send). | |
include_passwords / includePasswords | bool | Ticked. | |
passwords_label / passwordsLabel | String | "Also send 14 saved passwords". | |
source_note / sourceNote | String | What the Keychain will do for this source, in a line. |
AppSendSource enum#.live
.vault| Variant | Description |
|---|---|
Live | Read the live app now (a browser's cookies are decrypted, so macOS asks for Keychain access). |
Vault | Send the items saved in the Keyvault for this app. Nothing is read from the host. |
AppVaultSource record#| Field | Type | Default | Description |
|---|---|---|---|
available | bool | The app has saved items that can be sent (passwords never are). | |
items | u32 | How many. | |
saved | String | "saved 2 days ago". | |
selected | Vec<String> | The items chosen to send (ids). | |
password_ids / passwordIds | Vec<String> | The app's saved passwords (ids), sent only when ticked. |
AppRememberedChoice record#Returned by app_review_remember.
| Field | Type | Default | Description |
|---|---|---|---|
key | String | <app>|<space>. | |
domains | Vec<String> | The sites (registrable domains) that were sent. |
AppPlanStepView record#| Field | Type | Default | Description |
|---|---|---|---|
kind | String | install, files, state, launch. | |
summary | String | One line. |
AppInstallCuaPrompt record#| Field | Type | Default | Description |
|---|---|---|---|
installed | bool | Cua is installed but not running. | |
title | String | Title. | |
message | String | One line. | |
action_label / actionLabel | String | Button. | |
url | String | Button target: always one of the constants, never from the error. |
AppConsentItem record#| Field | Type | Default | Description |
|---|---|---|---|
kind | AppConsentKind | Kind. | |
key | String | Stable key. | |
label | String | Label. | |
detail | String | Detail. | |
bytes | u64 | Bytes that leave. | |
sensitive | bool | Credentials, cookies, tokens. |
AppReviewChoice record#| Field | Type | Default | Description |
|---|---|---|---|
source | AppSendSource | Where to send from. | |
domains | Vec<KvDomainCount> | The browser's sites with counts (none until read, or for an app that is not a browser). | |
selected_domains / selectedDomains | Vec<String> | The sites chosen. | |
query | String | The sites list's search text. | |
excluded | Vec<String> | Consent items (keys) turned off. | |
vault | AppVaultSource | The saved items. | |
loaded | bool | The sites were asked for (a failure counts: the review then sends what the plan lists). | |
include_passwords / includePasswords | bool | The saved passwords are ticked to send (off unless the user ticks them; never remembered). |
AppReviewDomain record#| Field | Type | Default | Description |
|---|---|---|---|
domain | String | The site (github.com). | |
counts | String | "12 cookies, 2 storage values". | |
count | u32 | Items the site holds. | |
signin | bool | It looks like it keeps a sign-in. | |
identity_provider / identityProvider | bool | An identity provider: its session unlocks other apps. | |
selected | bool | Chosen to send. | |
selectable | bool | Can be chosen: it holds something that can be sent. A site whose cookies are all unreadable is greyed out. | |
unavailable | u32 | Cookies that cannot be read, shown greyed with unavailable_note. | |
unavailable_note / unavailableNote | String | "3 cookies cannot be sent: Chrome protects them with ...", or empty. |
AppReviewToggle record#| Field | Type | Default | Description |
|---|---|---|---|
key | String | The consent item's key. | |
label | String | Label. | |
detail | String | Detail. | |
bytes | u64 | Bytes that leave. | |
sensitive | bool | A secret. | |
selected | bool | Sent (not turned off). |
AppConsentKind enum#.install
.file
.folder
.state
.secret| Variant | Description |
|---|---|
Install | An install into the Space. |
File | A file that leaves this machine. |
Folder | A folder that leaves this machine. |
State | App state that leaves this machine. |
Secret | A secret that leaves this machine. |
app_review_remember#choices with the sites just sent remembered for key.
func appReviewRemember(choices: [AppRememberedChoice], key: String, domains: [String]) -> [AppRememberedChoice]| Parameter | Type | Default |
|---|---|---|
choices | Vec<AppRememberedChoice> | required |
key | String | required |
domains | Vec<String> | required |
Returns Vec<AppRememberedChoice>
app_review_remember_key#The key a review's site choice is remembered under (<app>|<space>).
func appReviewRememberKey(app: String, space: String) -> String| Parameter | Type | Default |
|---|---|---|
app | String | required |
space | String | required |
Returns String
app_review_remembered#What was picked last time for key (an app and a Space), if anything.
func appReviewRemembered(choices: [AppRememberedChoice], key: String) -> [String]?| Parameter | Type | Default |
|---|---|---|
choices | Vec<AppRememberedChoice> | required |
key | String | required |
Returns Option<Vec<String>>