Skip to content

feat(plugin)!: add validated v1 manifests - #84

Open
wumingzhinu wants to merge 1 commit into
OpenListTeam:mainfrom
wumingzhinu:feat/plugin-manifest
Open

wumingzhinu wants to merge 1 commit into
OpenListTeam:mainfrom
wumingzhinu:feat/plugin-manifest

Conversation

@wumingzhinu

Copy link
Copy Markdown
Contributor

Summary / 摘要

  • 新增严格的插件 manifest v1:apiVersion、ID、版本、显示名、描述、capabilities、settingsSchema 和仅存储的 opaque entry。
  • 完整 manifest 限制为 65,535 UTF-8 bytes,并限制深度、节点数、数组/对象大小、字符串长度和危险属性,适配 MySQL TEXT。
  • 为 map/key/SQL 插件记录增加可选 manifest 字段;D1、MySQL、Durable Object 旧库执行幂等列迁移。
  • 修复 MySQL 新库 DDL:字符串主键/唯一列使用 VARCHAR(255),不再生成非法的 TEXT PRIMARY KEY/UNIQUE。
  • 插件 install/update/toggle/delete/batch 使用隔离写时复制和延迟缓存发布;失败不会泄漏未持久化候选。DB_FORMAT=key 因缺少多键原子写而明确返回 409。
  • manifest_url 仅允许匹配显式 PLUGIN_MANIFEST_ORIGIN,禁止重定向/凭据,限制 5 秒和 65,535 bytes,并取消被拒绝的响应体。
  • 公开插件 API 仅返回元数据和安全的 manifest 摘要,不再公开 script/style、entry、settingsSchema、配置值或 hooks。
  • 本 PR 只存储和验证 manifest;entry 与 capabilities 不会下载、导入、执行或授予权限。

Breaking changes / 兼容性变化

  • GET /api/public/plugins 不再返回旧插件行中的 script_content、style_content、entry_url、config_schema、config_values、target_hooks 和完整 manifest。

  • DB_FORMAT=key 暂不支持插件写操作,返回 ATOMIC_PLUGIN_PERSISTENCE_UNSUPPORTED;请使用默认 map 或 sql。

  • manifest_url 安装现在要求配置 PLUGIN_MANIFEST_ORIGIN,且远程 manifest 必须符合严格 v1 schema。

  • This PR has breaking changes.
    / 此 PR 包含破坏性变更。

  • This PR changes public API, config, storage format, or migration behavior.
    / 此 PR 修改了公开 API、配置、存储格式或迁移行为。

  • This PR requires corresponding changes in related repositories.
    / 此 PR 需要关联仓库同步修改。

Related repository PRs / 关联仓库 PR:

  • OpenList: none
  • OpenList-Docs: follow-up required before the v4.4 release

Testing / 测试

Checklist / 检查清单

  • I have read CONTRIBUTING.
    / 我已阅读贡献指南。
  • I confirm this contribution follows the repository license, contribution policy, and code of conduct.
    / 我确认本次贡献符合仓库许可证、贡献规范和行为准则。
  • I have formatted the changed code with Prettier where applicable.
    / 我已按适用情况格式化变更代码。
  • I have requested review from relevant maintainers or code owners where applicable.
    / 我已在适用情况下请求相关维护者审查。

AI Disclosure / AI 使用声明

  • This PR includes AI-assisted content.
    / 此 PR 包含 AI 辅助内容。

Tools used / 使用工具:

  • Other: OpenCode

Usage scope / 使用范围:

  • Code generation / 代码生成

  • Tests / 测试

  • Review assistance / 审查辅助

  • I have reviewed and validated all AI-assisted content included in this PR.
    / 我已审核并验证此 PR 中的所有 AI 辅助内容。

  • I have ensured that all AI-assisted commits include Co-Authored-By attribution.
    / 我已确保所有 AI 辅助提交都包含 Co-Authored-By 归属信息。

  • I can reproduce all AI-assisted content included in this PR without any AI tools.
    / 我可以在没有 AI 工具的情况下重现此 PR 的内容。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant