Repository navigation
feat(plugin)!: add validated v1 manifests - #84
Open
wumingzhinu wants to merge 2 commits into
Open
wumingzhinu wants to merge 2 commits into
wumingzhinu wants to merge 2 commits into
Conversation
This comment has been minimized.
This comment has been minimized.
pikachuren
reviewed
Oct 9, 2026
pikachuren
left a comment
Collaborator
There was a problem hiding this comment.
🙏 感谢 @wumingzhinu 提交!
🤖 AI 自动审核声明:本评审报告由 AI 自动生成,当前使用 GLM 模型进行分析。
🔄 增量评审:上次评审 → 当前 head(a4a49cf)
上次评审后新增 1 个提交,为 merge origin/main(并移除 cloud-functions 构建产物),无功能性新改动。
新增改动的问题:
无新增问题。
旧问题解决情况:
- ❌ 公开插件 API 破坏无替代端点(P0)→ 未解决。当前 head 的
GET /api/public/plugins(public.ts:531-540)仍返回toPublicPlugin收窄后的对象,全仓依旧没有任何端点能取到插件代码,已启用插件仍会失效。 - ❌
reloadDb绕过 1s TTL 缓存与 inflight 去重(P1)→ 未解决,未鉴权 GET 每次仍触发一次后端读。 - ❌ D1 batch 分批保护移除(P1,未确证)→ 未恢复分片。
- ❌ 旧式 install 对已有 manifest 的插件
delete newPlugin.manifest导致重装丢 manifest(P2)→ 未处理。
🎯 结论:🔄 Request Changes — 旧 P0(公开 API 破坏)在增量提交中未触碰,仍需提供替代端点或保留旧字段后再合并。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary / 摘要
apiVersion、ID、版本、显示名、描述、capabilities、settingsSchema 和仅存储的 opaque entry。TEXT。manifest字段;D1、MySQL、Durable Object 旧库执行幂等列迁移。VARCHAR(255),不再生成非法的TEXT PRIMARY KEY/UNIQUE。DB_FORMAT=key因缺少多键原子写而明确返回 409。manifest_url仅允许匹配显式PLUGIN_MANIFEST_ORIGIN,禁止重定向/凭据,限制 5 秒和 65,535 bytes,并取消被拒绝的响应体。entry与capabilities不会下载、导入、执行或授予权限。Breaking changes / 兼容性变化
GET /api/public/plugins不再返回旧插件行中的script_content、style_content、entry_url、config_schema、config_values、target_hooks和完整 manifest。DB_FORMAT=key暂不支持插件写操作,返回ATOMIC_PLUGIN_PERSISTENCE_UNSUPPORTED;请使用默认map或sql。manifest_url安装现在要求配置PLUGIN_MANIFEST_ORIGIN,且远程 manifest 必须符合严格 v1 schema。This PR has breaking changes.
/ 此 PR 包含破坏性变更。
This PR changes public API, config, storage format, or migration behavior.
/ 此 PR 修改了公开 API、配置、存储格式或迁移行为。
This PR requires corresponding changes in related repositories.
/ 此 PR 需要关联仓库同步修改。
Related repository PRs / 关联仓库 PR:
Testing / 测试
mainfailures addressed by PR test(auth): isolate default credential cases #77, fix(seed): preserve CAS cloud metadata #78, and fix(storage): validate KV proxy health response #79.src/backend/internal/model/db_cipher.test.ts:187-188remain, fixed by PR test(db): type cipher producers #80.FRONTEND_DIST="$PWD/dist" node scripts/build-edge.mjsgit diff --checkChecklist / 检查清单
/ 我已阅读贡献指南。
/ 我确认本次贡献符合仓库许可证、贡献规范和行为准则。
/ 我已按适用情况格式化变更代码。
/ 我已在适用情况下请求相关维护者审查。
AI Disclosure / AI 使用声明
/ 此 PR 包含 AI 辅助内容。
Tools used / 使用工具:
Usage scope / 使用范围:
Code generation / 代码生成
Tests / 测试
Review assistance / 审查辅助
I have reviewed and validated all AI-assisted content included in this PR.
/ 我已审核并验证此 PR 中的所有 AI 辅助内容。
I have ensured that all AI-assisted commits include
Co-Authored-Byattribution./ 我已确保所有 AI 辅助提交都包含
Co-Authored-By归属信息。I can reproduce all AI-assisted content included in this PR without any AI tools.
/ 我可以在没有 AI 工具的情况下重现此 PR 的内容。