Directory trust can now be decided strictly from saved state when the host serves your files.
What's wrong with this entry?
Building the permission context is now asynchronous, and when the newer storage layout is in use and workspace files are served by the host it computes a strict-persisted-trust value that feeds both the deny rules and the list of additional working directories.
- Requires storage version 5 and
hostFiles.serving("workspace")returning"host". - In every other configuration the options object is empty and trust is decided exactly as before.
strictPersistedTrust
Strings lifted out of the shipped bundle, so the claim above can be checked against them.