6 Commits

Author SHA1 Message Date
Alex Dunmow
d0adca8583 feat(2c): end the core/captcha carve-out — zero block/core in standalone plugins
Captcha is now the host-stamped X-Bn-Verified-Captcha trusted header
(pluginsdk v0.2.2), so no plugin has a legitimate core import left:
isForbiddenPluginImport flags ALL first-party prefixes unconditionally,
and a block/core require in a plugin go.mod fails as
no-block-core-require (always vestigial — imports are already
forbidden). Fleet-verified: no plugin imports or requires core.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 23:09:20 +08:00
Alex Dunmow
0749c22d30 feat(2c): forbid all first-party imports in standalone plugins; fix --plugin-dir-only scans
Import boundary now covers the whole first-party tree, not just block/cms:
block/core and block/orchestrator imports are violations too, with an
explicit carve-out for the packages that deliberately stayed core after
the pluginsdk extraction (core/captcha, core/backup — calcomblock uses
captcha today). The .templ import scan gets the same rule.

defaultScanTargetDir: --plugin-dir with no positional target used to
leave targetDir at cwd, so the checker scanned its own repo and
self-reported failures while never scanning the plugin. It now targets
the first plugin root, matching the positional form.

Verified green across cms + all 11 v0.2.1 fleet repos (bidmasters still
fails the version anchor as expected — it pins v0.2.0 on a detached
HEAD, unrelated to these changes).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:48:01 +08:00
Alex Dunmow
ff4de855cc refactor: complete check 2c retarget from block/core to block/pluginsdk
Standalone plugins now build against git.dev.alexdunmow.com/block/pluginsdk.
Check 2c requires a pluginsdk module require (rule missing-pluginsdk-require)
and enforces its version against the CMS anchor (rule pluginsdk-version-mismatch)
once the CMS migrates; a coexisting block/core require stays allowed
(calcomblock keeps core for captcha).

- check_sdkboundaries.go: degrade the 2c OK message gracefully when the
  pluginsdk version anchor is empty (transition period) — omit the version
  clause instead of printing "SDK version ".
- check_rbac.go: document pluginsdk in the definitions-only module comment.
- plugin_sdk_versions_test.go: retarget fixtures to pluginsdk; add cases for
  missing-pluginsdk-require, pluginsdk-version-mismatch, a forbidden core
  replace directive, and an allowed coexisting core require.
- lint_test.go: synthesized plugin repos now require pluginsdk (replace-
  directive case replaces pluginsdk).
- registry_test.go: add checks 30 and 31 to the canonical order (were added
  to the registry without updating this test).
- golden: regenerate — check count 32 -> 34 (checks 30/31 SKIP in fixtures).
- README.md: describe 2c as the pluginsdk boundary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 11:13:42 +08:00
Alex Dunmow
f968cb31d9 fix: skip gitignored .worktrees/ dirs in repo scans
Directory walkers pruned .git/vendor/node_modules but not .worktrees/, so a repo scan descended into nested git worktrees (e.g. an orchestrator worktree under cms/.worktrees/). Their Go/TS files surfaced as false positives in the standalone-plugin import check and noise in the any-usage warnings.

Add ".worktrees" to the skip set across the implicated and common walkers: proto RBAC proto-scan, standalone-plugin imports, frontend extras, go-lint, sqlc-uuid, presets.json, and plugin segmentation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 16:53:18 +08:00
Alex Dunmow
57bca429cc chore: follow CMS module rename in rule strings + test fixtures
CMS Go module renamed from git.dev.alexdunmow.com/block/ninja to
git.dev.alexdunmow.com/block/cms (along with the git remote rename
on gitea). All import paths, string-literal rules, test fixtures,
and doc references updated; (historical 'ninja-orchestrator' refs
preserved). go mod tidy regenerated checksums.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:55:47 +08:00
Alex Dunmow
cd88c808b0 initial: standalone check-safety module hoisted from CMS
Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.

This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
  blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
  install-safety-checker targets

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:04:02 +08:00