{"record":{"id":"ff6fe64df0e12475","repo":"tauri-apps/tauri","slug":"missing-command-scope-for-key-key","errorCode":null,"errorMessage":"missing command scope for key {key}","messagePattern":"missing command scope for key (.+?)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tauri/src/ipc/authority.rs","lineNumber":785,"sourceCode":"        self.global_scope_cache.set(scope.clone());\n        Ok(scope)\n      }\n    }\n  }\n\n  fn get_command_scope_typed<R: Runtime, T: ScopeObject>(\n    &self,\n    app: &AppHandle<R>,\n    key: &ScopeKey,\n  ) -> crate::Result<ScopeValue<T>> {\n    let cache = self.command_cache.get(key).unwrap();\n    match cache.try_get::<ScopeValue<T>>() {\n      Some(cached) => Ok((*cached).clone()),\n      None => {\n        let resolved_scope = self\n          .command_scope\n          .get(key)\n          .unwrap_or_else(|| panic!(\"missing command scope for key {key}\"));\n\n        let mut allow = Vec::new();\n        let mut deny = Vec::new();\n\n        for allowed in &resolved_scope.allow {\n          allow\n            .push(Arc::new(T::deserialize(app, allowed.clone()).map_err(\n              |e| crate::Error::CannotDeserializeScope(Box::new(e)),\n            )?));\n        }\n        for denied in &resolved_scope.deny {\n          deny\n            .push(Arc::new(T::deserialize(app, denied.clone()).map_err(\n              |e| crate::Error::CannotDeserializeScope(Box::new(e)),\n            )?));\n        }\n\n        let value = ScopeValue {","sourceCodeStart":767,"sourceCodeEnd":803,"githubUrl":"https://github.com/tauri-apps/tauri/blob/460ec35447493200d64290dd7f015d5a91d0fd58/crates/tauri/src/ipc/authority.rs#L767-L803","documentation":"get_command_scope_typed resolves a command's allow/deny scope from a per-command cache keyed by command name. If the key is absent from `self.command_scope`, the library panics because typed scope lookups assume the command was registered with a resolved scope during capability parsing; a missing entry is an internal invariant violation.","triggerScenarios":"Requesting a typed scope via `get_command_scope_typed::<T>(key)` for a command key that was never inserted into the ACL/command_scope map — e.g. querying a scope for a command not referenced by any capability, or a typo'd/mismatched command key.","commonSituations":"Plugin authors resolving custom scoped types at runtime for commands whose capabilities weren't generated (missing in capabilities JSON), key naming drift between build-time ACL generation and runtime lookup, or calling the lookup before ACLs are resolved.","solutions":["Verify the command key matches exactly (case and path) the command declared in your capabilities file and regenerated ACLs.","Regenerate the ACL/permissions so the command scope is embedded (rebuild after adding the command to capabilities).","Use the non-panicking cache path: check `cache.try_get::<ScopeValue<T>>()` / query the scope map (`command_scope.get(key)`) and handle None instead of the panicking typed getter.","Ensure capabilities are loaded before any typed scope resolution (lookups happen after manager initialization)."],"exampleFix":"// before\nlet scope: Vec<ScopeValue<MyScope>> = acl\n  .get_command_scope_typed::<MyScope>(\"my_plugin:allow-read\")\n  .unwrap(); // panics if key missing\n// after\nlet scope = acl.command_scope.get(\"my_plugin:allow-read\")\n  .map(|resolved| resolved.clone().try_into_scope::<MyScope>())\n  .unwrap_or_default(); // or return a proper error","handlingStrategy":"fallback","validationCode":"// check the scope exists before the typed, panicking lookup\nlet exists = acl.command_scope.contains_key(\"my_plugin:allow-read\");\nif !exists { return Err(anyhow!(\"no scope registered for command\")); }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep command keys in capabilities in sync with runtime lookups (same exact string)","Regenerate ACLs after adding commands or permissions","Prefer the non-panicking command_scope.get()/try_get path in library code","Load capabilities/ACLs before any typed scope resolution"],"tags":["rust","tauri","ipc","acl","panic"],"backgroundTag":"record-not-found","analyzedSha":"460ec35447493200d64290dd7f015d5a91d0fd58","analyzedAt":"2026-09-18T23:55:51.277Z","contentChangedAt":"2026-09-18T23:55:51.277Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}