8 Commits

Author SHA1 Message Date
Alex Dunmow
8418d2535b allowlist CMS registry browse/detail fetch() to orchestrator endpoints
The CMS registry browse tab and new Phase-5 detail view call the
orchestrator's public Connect endpoints (PluginRegistryService /
PluginReviewService) on a different origin. The CMS transport and generated
hooks only cover the CMS's own proto surface, so these are plain JSON POSTs
to the registry URL — same rationale routes/admin/plugins.tsx carried before
the BrowseRegistryTab extraction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 10:42:08 +08:00
Alex Dunmow
3476316e9c fix(frontend): match calcomblock REST allowlist by location-independent suffix
calcomblock was extracted from cms/backend/internal/plugins/calcomblock into a
standalone repo at plugins/calcomblock. The allowedPluginRESTFiles entries were
pinned to the old bundled path, so the standalone plugin's web/{settings,editor}.tsx
(which legitimately call the plugin's own HTTPHandler REST routes — no ConnectRPC
surface exists) tripped no-fetch-in-plugin. Switch to the suffix
plugins/calcomblock/web/... which matches both the standalone and legacy bundled
locations (pluginRESTFileAllowed uses HasSuffix).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 03:06:20 +08:00
Alex Dunmow
44d60b5f7b feat(frontend): allowlist /.well-known/skills/ fetches
The CMS skill-install card now reads the instance-derived skill name from
the public /.well-known/skills/index.json discovery index — a well-known
endpoint with no ConnectRPC surface, so it warns instead of failing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 15:21:21 +08:00
Alex Dunmow
bba5946bb1 allow site-agent streaming hook createClient (WO-SA-006)
SiteAgentService.SendMessage is a Connect server-streaming RPC consumed
with for-await; generated Connect Query hooks are unary-only (same
justification as use-restart-operation).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-03 03:05:25 +08:00
Alex Dunmow
7599fff971 feat: sanction /api/helpdesk/ as a known non-proto fetch prefix (WO-028)
Helpdesk attachment upload/download is multipart HTTP by design — ConnectRPC
has no multipart support — so the frontend fetch gets the same WARN-not-FAIL
treatment as /api/plugins/ and the other sanctioned REST endpoints.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 21:40:25 +08:00
Alex Dunmow
c3bb958f23 feat(frontend-check): flag raw <button> in JSX — use the shared <Button> component
New rules no-raw-button / no-raw-button-in-plugin ride inside Check 5's
walkers, same as the browser-confirm rules. Raw buttons bypass the
action=/entity= automation attributes (docs/BUTTON_AUTOMATION.md), so
MCP/Puppeteer can't target them.

Scope: .tsx/.jsx only (plain .ts builds DOM strings for non-React
surfaces), components/ui/ exempt (defines the primitives — same
carve-out as the button-automation check).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 15:15:46 +08:00
Alex Dunmow
fbe14f6c57 chore(frontend-check): document use-entity-search exception; allow helpdesk multipart fetches
use-entity-search reason expanded per 2026-06-10 work order Task 11
(Gate C: allowlist with documented reason). /api/support/ (CMS widget)
and /api/helpdesk/upload (orchestrator) are multipart FormData uploads
connect-query cannot express — WARN, not FAIL.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 14:52:35 +08:00
Alex Dunmow
cd88c808b0 initial: standalone check-safety module hoisted from CMS
Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.

This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
  blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
  install-safety-checker targets

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:04:02 +08:00