7 Commits
Author SHA1 Message Date
Jinpy b1b99eccfb feat(desktop): deliver font settings to plugin sandboxes 2026-09-19 19:13:30 +08:00
t8y2 193e9e898d fix(dev-host): close debug pages without a confirmation modal
Closing a workbench page popped a centered confirm dialog that locked
the entire shell (busy gate) until answered. Developers who clicked the
tab's close button and immediately went for the connection list found
every button dead and reported the page as impossible to reopen. Debug
pages are stateless and rebuild on reopen, so the close now happens
immediately; destructive actions (delete connection, disconnect,
backend rebuild) keep their confirmations.
2026-09-16 16:26:58 +08:00
t8y2 2c4f2091a6 fix(dev-host): reload manifest.json instead of failing the identity check
The dev host read manifest.json once at startup and froze that copy in
the Sidecar, while the backend watcher happily rebuilt the binary on any
source edit. Editing the manifest while the host ran — a routine version
bump during a release, for example — then made every restart compare the
fresh binary against the stale in-memory manifest and fail with "Sidecar
identity or protocol does not match manifest" until the whole dev host
was restarted.

Two layers of fixing: the project root now watches manifest.json and hot
swaps the in-memory copy (plus secret-key collection), and the sidecar
handshake re-reads the manifest from disk before declaring a mismatch, so
the check can no longer race the watcher. A genuinely disagreeing
manifest still fails the handshake.
2026-09-16 15:10:06 +08:00
t8y2 048b9ed291 feat(plugins): add host.copy bridge for plugin clipboard writes
Plugin workbenches run in a sandbox="allow-scripts" iframe with an opaque
origin, so every scripted clipboard path (async Clipboard API, offscreen
textarea + execCommand) is denied there — plugins could not copy share
links to the system clipboard. The bridge now exposes host.copy: the
workbench host reuses copyToClipboard (Tauri clipboard-manager on desktop,
Web Clipboard with a legacy fallback on web hosts), and the sandbox iframe
additionally gets allow="clipboard-write" so engines that honor the
delegation can write directly.

The dev host matches production: its debug page answers host.copy in the
top-level document and its plugin iframes carry the same allow attribute.
No new plugin permission is required, so old hosts keep installing new
plugins and old plugins simply never call the method.
2026-09-16 14:29:47 +08:00
t8y2 f1cc68a4ba fix(plugin): prevent theme flash in embedded workbenches 2026-09-14 14:43:02 +08:00
t8y2 e8e1ece80d feat(plugins): display manifest icons in dev host 2026-09-14 00:44:02 +08:00
t8y2 b5072f1a3e feat(plugin): add plugin framework workflow 2026-09-13 10:39:17 +08:00