feat(plugins): add connection, authentication, and importer providers#2413
feat(plugins): add connection, authentication, and importer providers#2413ryan-wong-coder wants to merge 18 commits into
Conversation
|
Independent review of exact head No blocking findings remain. Reviewed areas:
Functional completeness assessment: this head provides the stable public and host integration seams required for the remaining PR 8–9 work without changing RPC method names, permission names/scopes/lifetimes, runtime identity, cancellation, or stream framing. Publisher verification remains correctly scoped to PR 9. Validation results are recorded in the PR body. The sole full-suite failure is the unchanged upstream SSH keyboard-interactive retry test; both the implementation and failing test are byte-identical to |
|
@codex review\n\nPlease review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fede51ea03
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
fede51e to
c3ef41e
Compare
|
@codex review |
|
Independent review of exact head Result: no additional actionable correctness, security, compatibility, accessibility, localization, or lifecycle findings. Reviewed areas:
Validation on this head:
The implementation is functionally complete for PR 7 scope and provides the required stable seams for PRs 8 and 9. |
|
Independent review of exact head Result: no actionable findings. This follow-up fixes the CI-only cancellation observed on Review conclusions:
The head remains functionally complete for PR 7. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ac89909aae
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
ac89909 to
55a6105
Compare
|
@codex review |
|
Independent review of exact head Result: no additional actionable correctness, security, compatibility, accessibility, localization, lifecycle, or downstream-delivery findings. Reviewed areas:
Validation:
This head remains functionally complete for PR 7 and preserves the required stable seams for PRs 8 and 9. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 55a6105352
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
55a6105 to
2a1478e
Compare
|
@codex review |
|
Independent review of exact head Result: no additional actionable correctness, security, compatibility, accessibility, localization, lifecycle, or downstream-delivery findings. Reviewed areas:
Validation on the rebased head:
This head is functionally complete for PR 7 scope and preserves the stable seams required for PRs 8 and 9. |
|
Maintainer rerun requested for the failed The sole CI failure is the existing intermittent Telnet assertion All PR-specific runtime, contract, lint, build, pack, and diff gates pass. This account cannot rerun the failed job because GitHub requires repository admin permission. No unrelated Telnet change or empty commit will be made to churn the reviewed SHA. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2a1478e8b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
2a1478e to
21e5fed
Compare
|
Independent exact-head review for No additional actionable findings. I re-reviewed both corrective paths beyond the reported cases:
The downstream audit found no changes to public RPC method names, permissions, scopes, lifetimes, runtime identity, cancellation, or stream framing. PR 8 retains its encrypted sync sidecar, namespaced storage, and stream seams; PR 9 retains the immutable identity and trust boundaries. Validation:
|
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 21e5fedb18
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
21e5fed to
7ed9b06
Compare
|
Independent follow-up review of exact head No additional correctness, security, compatibility, accessibility/localization, functional-completeness, or downstream PR 8-9 blockers were found. The auto-save fix keeps session-log ownership entirely on the host path: log configuration and host labels are forwarded only through the internal renderer/main/worker route, never through the public Provider payload. Each plugin terminal owns a token-bound worker-local stream; validated decoded output is appended before renderer delivery, while Provider finish and user close stop only the matching stream instance. Manual session logging remains on the existing main-process output-tap path, so the two modes do not duplicate output. Public Provider RPC names, permission names/scopes/lifetimes, runtime identity, cancellation, stream framing, and opaque plugin connection persistence are unchanged. PR 8 encrypted sync Providers and PR 9 distribution/trust can continue on the existing seams without contract changes. Validation: focused logging/bridge regressions 166/166; plugin runtime 393 passed with one intentional Electron skip; Electron smoke passed; contract 76/76; lint, contract drift, build, pack:dir, and diff check passed. Full |
|
@codex review |
|
Maintainer rerun requested for the failed The sole CI failure is the existing intermittent Telnet assertion All PR-specific logging/runtime, contract, lint, build, pack, and diff gates pass. This account cannot rerun the failed job because GitHub requires repository admin permission. No unrelated Telnet change or empty commit will be made to churn the reviewed SHA. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ed9b06940
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
7ed9b06 to
3b56a64
Compare
|
@codex review |
53b47ee to
b9fc1df
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b9fc1dfb7f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Maintainer follow-up and independent exact-head review for This addresses the five review gaps raised in #2413 (comment):
Independent review result: no additional actionable correctness, security, compatibility, accessibility/localization, functional-completeness, lifecycle, or downstream PR 8-9 blockers were found after the corrective changes. Downstream audit:
Validation on this head:
The PR description has been refreshed with the current Markdown and validation text. Remote CI is still being tracked separately: current completed failures are unrelated to this corrective commit ( |
|
Maintainer rerun requested for the failed jobs on exact head This account cannot rerun the failed jobs:
I will not create an empty commit or churn the reviewed SHA to retrigger CI. Current non-code CI failures:
The affected SFTP/transfer bridge files are byte-identical to current Please rerun the failed jobs when convenient. In the build workflow, macOS, Windows, and Linux arm64 have passed; only the pre-checkout Docker pull failure on Linux x64 remains red. |
|
@codex review |
|
Independent follow-up review of exact head Result: no additional actionable correctness, security, compatibility, accessibility/localization, functional-completeness, lifecycle, or downstream PR 8-9 blockers were found after the corrective change. This head fixes the current Codex P2 finding by mounting Regression coverage was added in Downstream audit:
Validation on this head:
Remote CI for this exact head is running. A single automated |
|
To use Codex here, create an environment for this repo. |
|
Maintainer rerun request for exact head The corrective change for the latest Codex finding is in place and the review thread is resolved. The only completed failing check is The failed assertions are outside this plugin PR's changed surface:
The affected files are byte-identical to current
Local validation for the plugin change passed: targeted popup/provider-tree regressions 13/13, I attempted to rerun the failed job with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f78ff1250c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Independent follow-up review of exact head Result: no additional actionable correctness, security, compatibility, accessibility/localization, functional-completeness, lifecycle, or downstream PR 8-9 blockers were found after the corrective change. This head fixes the current Codex P2 finding by requiring plugin connection attachments to wait for the host-owned Regression coverage now asserts that a plugin Provider returning Downstream audit:
Validation on this head:
Remote CI for this exact head is running. A single automated |
|
To use Codex here, create an environment for this repo. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 60368b0147
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Maintainer rerun/restart requested for exact head I attempted to rerun the failed test job with:
GitHub rejected it with: The failed
The affected SFTP/transfer files are byte-identical to current
The build run https://github.com/binaricat/Netcatty/actions/runs/30167643716 also appears stuck: Local PR-specific validation remains green on this exact head: targeted terminal attachment/startup regressions, plugin runtime, Electron plugin-runtime smoke, plugin contract, lint, contract drift, build, pack:dir, and diff check all passed. The full local suite only has unrelated upstream/environment failures in SFTP/SSH/transfer paths; the affected files are byte-identical to I will not modify unrelated SFTP/transfer code or create an empty commit just to churn the reviewed SHA. |
|
@codex review |
|
Independent follow-up review of exact head Result: no additional actionable correctness, security, compatibility, accessibility/localization, functional-completeness, lifecycle, or downstream PR 8-9 blockers were found after the corrective change. This head fixes the two latest Codex P2 findings from exact head
Downstream audit:
Validation on this head:
Remote CI for this exact head is running. A single automated |
|
To use Codex here, create an environment for this repo. |
|
Maintainer rerun request for exact head The two latest Codex findings are fixed, replied to, and resolved. The only completed failing check is The failed assertions are outside this plugin PR's changed surface:
The affected SFTP/transfer files are byte-identical to current
I attempted to rerun the failed job with:
GitHub rejected it with: Local validation for the plugin change passed: focused review/completeness regressions 81/81, Please rerun the failed |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 874fb255cc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Independent follow-up review of exact head Result: no additional actionable correctness, security, compatibility, accessibility/localization, functional-completeness, lifecycle, or downstream PR 8-9 blockers were found after the corrective change. This head fixes the three current Codex P2 findings from exact head
Downstream audit:
Validation on this head:
Remote CI for this exact head is starting/running. I will request Codex exactly once for this SHA unless the existing automation has already posted that request. |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Maintainer rerun/restart requested for exact head Codex completed the exact-head review with no major issues: #2413 (comment). All GraphQL review threads are resolved and there is no The completed
The affected SFTP/transfer files are byte-identical to current
I attempted to rerun the failed job with:
GitHub rejected it with: The build-package workflow https://github.com/binaricat/Netcatty/actions/runs/30169166863 has I will not modify unrelated SFTP/transfer code or create an empty commit just to churn the reviewed SHA. |
|
Thank you for addressing the five gaps from the previous maintainer review. I re-reviewed exact head The previous five findings are now addressed: connection control results are operation-specific, importer draft records are public, UI workflows have moved into application hooks, runtime diagnostics are propagated, and the plugin-platform documentation has been updated. My local merge-with-current-main validation also passed 403 plugin-runtime tests (1 intentional skip), 77 plugin-contract tests, 175 changed-area tests, lint, contract drift checking, and the production build. The PR is still not ready to merge, because two actionable findings remain: 1. Public importer key typing does not match runtime validationThe canonical schema requires exactly one of However, the handwritten generator override allows both properties at once because the opposite property remains optional in each branch: generator override, generated public type. A third-party importer can therefore compile successfully and then have the same record rejected at runtime by the schema's 2. Authentication overflow performs an external action inside a React state updaterWhen the authentication queue reaches its cap, the queue updater directly sends a cancellation response. State updaters must be pure and replay-safe. If React retries or replays that updater, the same challenge can send cancellation more than once; the second response then reaches a request that the main process has already consumed. Please decide the overflow result in the state update and send the cancellation exactly once outside the updater, with a regression for one outbound response. Separately, the current exact-head Merge verdict: do not merge this head yet. The direction remains sound and the previous review gaps are closed, but the public importer contract must be made self-consistent, the authentication cancellation path must be replay-safe, and the latest checks must pass. |
Summary
Security and functional completeness
resize,signal,reconnect, andcloseacknowledge with JSONnullplugin:<providerId>protocol with opaque provider-owned configurationpluginConnectionReadymarker emitted from Provider status polling, so banner/progress output cannot corrupt an in-progress handshakeconnected, including already-connected opens, until terminal closure, Provider error/closed status, abort, or disposaluser_version = 1with no migration chainReview follow-up
This head addresses the latest Codex review gaps on exact head
874fb255cce217fb1f21655de45d2f435908a596:This PR also addresses the prior Codex review gaps on exact head
60368b014776876ffdf623b8a7b819fcb5ff459b:resize; runtime dispatch validates the same shape and rejects the legacy single-callback form for connection ProvidersThis head also addresses the prior Codex review gap on exact head
f78ff1250c63c5d9bab3d63f8e05b6675dec259e:pluginConnectionReadymarker before transitioning a still-connecting Provider session toconnected, while preserving first-output connected behavior for built-in transportsThis head also addresses the prior Codex review gap on exact head
b9fc1dfb7f8ea6600b49f1c0de401d0e8a218b8b:PluginAuthenticationHostinside the popupI18nProvider, so plugin authentication Provider challenges sent to a copied new-window renderer have a listener/dialog path and no longer wait until cancellation or timeoutThis PR also addresses the latest maintainer review gaps on exact head
53b47eec51bf5aff547d7e4ae6763325c51c6d56:ConnectionStatusResultand flow to terminal exit diagnostics for asynchronous Provider errorsdocs/plugin-platform/*now describes the implemented PR 7 connection/authentication/importer behavior and the remaining PR 8/9 boundariesPrior corrective rounds also covered closed-session reuse, imported protocol validation, streaming UTF-8 output, public SecretLease shape, silent connected readiness, importer cancellation and completion bounds, zero-delay status polling, isolated plugin snapshots, hidden built-in credential stripping, explicit JSON null configuration, secure credential catalogs, auto-save logging, SDK overloads, readiness-gated startup commands, renderer cancellation, status monitoring, input chunking, and plugin-session command-history suppression.
Downstream audit
Validation
npm run test:plugin-runtime: 403 passed, 1 intentional Electron skipnpm run test:plugin-runtime:electron: passednpm run test:plugin-contract: 77/77 passednpm run lint -- --quiet: passednpm test: 7,368 total, 7,352 passed, 13 skipped, 3 unrelated upstream/environment failures:application/state/sftpTransferCenterStore.test.ts:orphan directory pause rolls back successful child pauses on hard failelectron/bridges/sshBridge.authRetryExit.test.cjs:failed keyboard-interactive retry still offers encrypted default key fallbackelectron/bridges/transferBridge.test.cjs:pause soft-drains concurrent ranges but resume waits before truncatingupstream/mainand outside this plugin PR's changed surfacenpm run check:plugin-contract: passednpm run build: passednpm run pack:dir: passedgit diff --check: passedf7b5f9b8529cb8ad66146fd8e48c202e068d6302: no major issuesf7b5f9b8529cb8ad66146fd8e48c202e068d6302:lint-and-testfailed only in two unchanged upstream/environment SFTP and transfer timing assertions (application/state/sftpTransferCenterStore.test.tsandelectron/bridges/transferBridge.test.cjs), while all four platform package builds passed; maintainer rerun of the failed test job is requested because this account cannot rerun it (Must have admin rights to Repository)Rebased/synced with
upstream/mainat5e5c98a6828e10092bec465c929ed268c6f20ba9;upstream/mainwas 0 commits ahead at the corrective push, and this branch was 18 commits ahead.Related to #2269.