> For the complete documentation index, see [llms.txt](https://seanime.gitbook.io/seanime-extensions/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://seanime.gitbook.io/seanime-extensions/plugins/apis/system/permissions.md).

# Permissions

The System APIs give you access to a set of methods for file operations, downloading and more.

{% hint style="warning" %}
Difficulty: Moderate

* Some knowledge of the filesystem, platform differences is required
  {% endhint %}

You can check out the type definition file to see the exhaustive list of methods available and use Go's documentation to learn how to use them.

{% hint style="info" %}
The examples may use hardcoded paths but this is not recommended. Seanime is a cross-platform app, keep that in mind.
{% endhint %}

{% hint style="warning" %}
As of Seanime `v3.8.0`, if the user enables Extension Secure Mode, sensitive system actions such as file reads, writes, directory inspection, and command execution can prompt for confirmation.

If the user rejects a prompt, the call throws. If the prompt cannot be shown, such as during app startup before a UI client is available, the call fails immediately.
{% endhint %}

## Permissions

{% hint style="warning" %}
`system` permission is required.
{% endhint %}

<pre class="language-json" data-title="my-plugin.json"><code class="lang-json">{
    //...
    "plugin": {
        "permissions": {
<strong>            "scopes": ["system"]
</strong>        }
    }
}
</code></pre>

### Allow lists

By default, all commands you may try to execute and all directories and files you may try to read to write to will be restricted. You need to explicitly declare which command and the arguments you want to execute and which directories/files you want to read or write to.

<pre class="language-json"><code class="lang-json">{
    //...
    "plugin": {
        "permissions": ["system", ...],
<strong>        "systemAllowList": {
</strong><strong>            "allowReadPaths": ["$TEMP/*"],
</strong><strong>            "allowWritePaths": ["$TEMP/*"],
</strong><strong>            "commandScopes": []
</strong><strong>        }
</strong>    }
}
</code></pre>

### Paths

* `/path/to/dir/` - Matches only the specific directory
* `/path/to/dir/*` - Matches all files in the directory, but not subdirectories
* `/path/to/dir/**` - Matches all files and directories recursively
* /`path/to/dir/**/*` - Same as above, matches all files and directories recursively

Here are pre-defined directory variables

* $TEMP - The temp directory
* $CACHE - The cache directory (LocalAppData on Windows)
* $HOME - The home directory (%USERPROFILE% on Windows)
* $CONFIG - The user config directory (AppData on Windows)
* $DOWNLOAD - The download directory
* $DOCUMENT - The document directory
* $DESKTOP - The desktop directory
* $SEANIME\_ANIME\_LIBRARY - Any of the user's anime library paths
