Expand description
Content-plugin install / uninstall / list commands.
Install is gated by a native confirmation dialog (mirroring set_hooks):
the user must explicitly approve installing a plugin, with its provenance
shown. A content pluginβs pack is merged into the active profile and the
exact additions are recorded in the registry (merge-and-track), so
uninstall removes precisely what was added. The registry persists to
plugins.json; the merged content persists in the profile as usual.
StructsΒ§
- Dialog
Busy πGuard - Install
Outcome - Result of an install, surfaced to the renderer.
hints_added/routines_addedare the content merge effect (zero for a detector).
EnumsΒ§
- Prepared π
- A validated plugin awaiting consent + apply. Holds enough to show the confirmation dialog and then apply the right install path.
ConstantsΒ§
- DIALOG_
MAX_ πCAPABILITIES_ SHOWN - Most capabilities shown in full in the dialog before truncating, so a long (or padded) import list canβt push the safety text off-screen.
- KEY_
FINGERPRINT_ πCHARS - Number of leading characters of the base64 signing key shown as a short visual fingerprint in the dialog, so a returning user can recognise a familiar author and spot a substituted one.
- MAIN_
WINDOW_ πLABEL - Plugin IPC is restricted to the main settings window, like content packs.
- MAX_
MANIFEST_ πBYTES - Hard cap on a plugin manifest weβll read+parse. A content plugin embeds its pack, so this matches the content-pack cap.
- PLUGIN_
DIALOG_ πALLOW - PLUGIN_
DIALOG_ πCANCEL
FunctionsΒ§
- apply_
detector_ πinstall - Persist a validated detectorβs module to disk and register it (granted
capabilities + detect config travel in the record). Split out so itβs
unit-testable without a
WebviewWindow/dialog. The module bytes are written first; only on success is the registry updated and persisted, so a failed write leaves no dangling record. - apply_
export_ πinstall - Register a validated export adapter (declarative β no module, no content
merge). The export config travels in the record for the delivery path.
Split out so itβs unit-testable without a
WebviewWindow/dialog. - apply_
install π - Merge a validated content plugin into the active profile, record the
additions in the registry, and persist both. Split out so itβs
unit-testable without a
WebviewWindow/dialog. Mirrors the content-packapply_packwrite sequence (merge into a clone, rebuild the derived caches, store, upsert the active profile, persist). - apply_
uninstall π - Remove
addedcontent from the active profile and persist. The registry entry is dropped by the caller; this only touches settings. Split out for unit testing. ReturnsMergeSummaryrepurposed as removal counts. - confirm_
install π - ensure_
main_ πwindow - format_
install_ πsummary - install_
plugin - Install a plugin from
path: read (size-capped), validate (parse, schema, signature, and β for detectors β decode + sandbox link check), confirm via a native dialog, then apply. Content plugins merge their pack into the active profile; detector plugins persist their module and register their granted capabilities. Returns a summary of the effect. - list_
plugins - List installed plugins for the Settings UI.
- read_
manifest_ πtext - Read a plugin manifest file with the size cap, mapping I/O errors to user-facing strings. Pure (filesystem only), so the read + error-mapping is testable without a Tauri window.
- sanitize_
for_ πdialog - Same control-character / bidi sanitisation as the hooks dialog, so a hostile manifest canβt spoof or scramble the consent prompt.
- uninstall_
by_ πid - Drop the registry record for
idand remove its tracked content from the active profile, persisting both. Errors ifidisnβt installed. Split from the command wrapper so itβs testable against a realScheduler. - uninstall_
plugin - Uninstall the plugin
id: remove exactly the content it added from the active profile and drop its registry record. No-op-safe if the user already deleted some of that content by hand. Returns what was removed.