Skip to content

feat(plugins): create plugin sandbox with capability-based permissions (#824) - #1030

Merged
Nanle-code merged 2 commits into
Nanle-code:masterfrom
ogundeleoluwaferanmi35:feature/824-plugin-sandbox-capabilities
Sep 28, 2026
Merged

Nanle-code merged 2 commits into
Nanle-code:masterfrom
ogundeleoluwaferanmi35:feature/824-plugin-sandbox-capabilities

Conversation

@ogundeleoluwaferanmi35

Copy link
Copy Markdown

Summary

Resolves #824 by introducing a capability-based permission sandbox for the plugin system and CLI scaffolding.

Objectives & Changes Implemented

  1. Capability-Based Permissions Model (src/plugins/capabilitySandbox.ts):

    • Defined standardized capability scopes (CAPABILITY_SCOPES) and error codes (CAPABILITY_ERROR_CODES).
    • Implemented PluginCapabilityController managing dynamic capability tracking (grant, revoke, revokeAll, assertCapability).
    • Added automated cleanup of active store listeners and resources when capabilities are revoked.
    • Built createSandboxedDashboardApi with strict per-capability guards on getState, getConfig, subscribe, actions, notifications, storage, fetch, and openWindow.
    • Added bidirectional postMessage RPC bridge (handlePluginRpcMessage) supporting requests, responses, subscriptions, and broadcast of PLUGIN_CAPABILITY_REVOKED events.
    • Provided client helper SDK (createSandboxClient) with request matching, timeouts, and revocation listeners.
  2. Isolated Plugin Storage (src/plugins/pluginStorage.ts):

    • Partitioned storage per plugin under stellar-dashboard:plugin-data:<pluginId> to prevent cross-plugin data leakage or collision.
    • Integrated automatic purge of isolated plugin storage upon plugin uninstallation.
  3. Plugin Manager Integration (src/plugins/PluginManager.ts):

    • Integrated PluginCapabilityController lifecycle into PluginManager.
    • Added getCapabilityController, grantCapability, revokeCapability, and revokeAllCapabilities.
    • Injected sandboxed controller and API into iframe widget frames and module plugins.
    • Ensured proper controller disposal on uninstallation.
  4. UI Revocation Controls (src/components/dashboard/PluginRegistryView.tsx):

    • Displayed granted capability chips for each installed plugin with one-click revocation buttons (×).
    • Updated plugin cards with dynamic revocation handlers.
  5. CLI Scaffolding (scripts/create-plugin.mjs):

    • Added --capabilities / --permissions flag parsing.
    • Added validation against allowed scopes and input checking.
    • Updated scaffold templates to demonstrate capability-guarded calls and revocation listeners over postMessage.
  6. Documentation & Developer Guidance (docs/plugins/README.md):

    • Documented the capability-based security model, scopes matrix, RPC bridge protocol, error codes, and migration notes.

Acceptance Criteria Checklist

  • Clear handling for invalid input, unsupported environments, and failure paths.
  • Automated tests covering primary flow, boundary conditions, and failure cases:
    • src/plugins/__tests__/capabilitySandbox.test.ts (22 tests)
    • src/plugins/__tests__/pluginSandbox.test.tsx (5 tests)
    • src/plugins/__tests__/PluginManager.test.ts (3 tests)
    • tests/create-plugin.test.mjs (8 tests)
  • User-facing documentation updated in docs/plugins/README.md.
  • Free of merge conflicts with target branch (master).
  • Zero ESLint errors or warnings on touched files.

Nanle-code#824)

- Implement capability-based security model in capabilitySandbox.ts with dynamic grants and safe revocation&Nanle-code#10;- Add isolated per-plugin storage under pluginId namespace with automatic cleanup on uninstall&Nanle-code#10;- Add bidirectional postMessage RPC bridge in pluginSandbox.tsx and createSandboxClient SDK helper&Nanle-code#10;- Support capability chips and dynamic revocation controls in PluginRegistryView&Nanle-code#10;- Update scripts/create-plugin.mjs with capability flags, validation, and starter templates&Nanle-code#10;- Author comprehensive test suites covering primary flows, boundary conditions, and failure paths&Nanle-code#10;- Update docs/plugins/README.md with architecture, RPC protocols, error codes, and migration notes
@vercel

vercel Bot commented Sep 26, 2026

Copy link
Copy Markdown

@0dillon is attempting to deploy a commit to the nanle-code's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@ogundeleoluwaferanmi35 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Nanle-code
Nanle-code merged commit 33cf711 into Nanle-code:master Sep 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[2026 Platform] Create a plugin sandbox with capability-based permissions

3 participants