Skip to content

fix: harden plugin directory recovery - #15

Merged
CoderLambert merged 3 commits into
mainfrom
fix/plugin-dir-fallback-hardening
Sep 17, 2026
Merged

CoderLambert merged 3 commits into
mainfrom
fix/plugin-dir-fallback-hardening

Conversation

@CoderLambert

Copy link
Copy Markdown
Owner

Summary

  • correct the Omarchy compatibility floor to 4.0.3, where third-party manifests are already sanitized
  • derive the plugin root by stripping the complete manifest menu entry-point path instead of assuming QOpen.qml lives at the plugin root
  • reject non-file:// entry-point URLs before constructing a local backend path
  • retain the dirname fallback for compatibility if a host ever hides entryPoints too
  • add focused source-level regression coverage for the hardened recovery contract

Why

PR #14 fixed catalog loading after __sourceDir was stripped, but the first fallback assumed the menu entry point always lived directly in the plugin root. A future move such as ui/QOpen.qml would therefore resolve backendPath under ui/bin/qopen.

Omarchy v4.0.3 already contains publicPluginManifest() sanitization and the scoped PluginRegistryApi, so the previous 4.0.4+ compatibility note was also one release too high.

Verification

CI should run the existing backend/unit suite and QML syntax compilation. The previous source-level assertions remain compatible, and the new tests specifically guard full entry-point stripping and local-file URL validation.

@CoderLambert
CoderLambert merged commit 8d28ead into main Sep 17, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant