Skip to content

Record plugin hook sandbox limitations in marketplace docs #1345

Description

@greatest0fallt1me

Summary

executeHook in src/services/pluginRegistry.ts is explicitly a stub that performs no code execution, yet the install route reports sandboxed: true and README does not mention plugins at all.

Why this matters

Plugin authors may believe their before_charge hooks run and enforce business rules when nothing executes.

Scope

Add a marketplace plugins section to README (or docs/) describing the manifest schema, lifecycle endpoints, that hooks are currently no-ops, and the intended sandbox design.

Relevant code in CalloraOrg/Callora-Backend:

  • README.md
  • src/services/pluginRegistry.ts
  • src/routes/marketplace/plugins.ts

Priority

Low

Acceptance criteria

  • Manifest fields are documented from pluginManifestSchema
  • The no-op nature of hooks is explicit
  • Endpoints and required auth are listed
  • The sandboxed flag meaning is clarified

Validation

Review against npm test -- src/routes/marketplace/plugins.test.ts.

Non-goals

  • Typo-only, formatting-only, or cosmetic changes.
  • Unrelated refactors, dependency upgrades, or broad rewrites.
  • Removing safeguards or weakening validation to make tests pass.

Contributor application

Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.

PR requirements

Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.

Quality review

A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveStellar Wave Program issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions