Summary
executeHook in src/services/pluginRegistry.ts is explicitly a stub that performs no code execution, yet the install route reports sandboxed: true and README does not mention plugins at all.
Why this matters
Plugin authors may believe their before_charge hooks run and enforce business rules when nothing executes.
Scope
Add a marketplace plugins section to README (or docs/) describing the manifest schema, lifecycle endpoints, that hooks are currently no-ops, and the intended sandbox design.
Relevant code in CalloraOrg/Callora-Backend:
README.md
src/services/pluginRegistry.ts
src/routes/marketplace/plugins.ts
Priority
Low
Acceptance criteria
- Manifest fields are documented from pluginManifestSchema
- The no-op nature of hooks is explicit
- Endpoints and required auth are listed
- The sandboxed flag meaning is clarified
Validation
Review against npm test -- src/routes/marketplace/plugins.test.ts.
Non-goals
- Typo-only, formatting-only, or cosmetic changes.
- Unrelated refactors, dependency upgrades, or broad rewrites.
- Removing safeguards or weakening validation to make tests pass.
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.
Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code
Summary
executeHook in src/services/pluginRegistry.ts is explicitly a stub that performs no code execution, yet the install route reports
sandboxed: trueand README does not mention plugins at all.Why this matters
Plugin authors may believe their before_charge hooks run and enforce business rules when nothing executes.
Scope
Add a marketplace plugins section to README (or docs/) describing the manifest schema, lifecycle endpoints, that hooks are currently no-ops, and the intended sandbox design.
Relevant code in CalloraOrg/Callora-Backend:
README.mdsrc/services/pluginRegistry.tssrc/routes/marketplace/plugins.tsPriority
Low
Acceptance criteria
Validation
Review against
npm test -- src/routes/marketplace/plugins.test.ts.Non-goals
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include
Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code