pluginsdk/plugin/wasmguest/caps/coreservices.go
Alex Dunmow 6dd745bc34 Let a plugin grant and revoke file access
WO-FL-009. The files family reaches the CMS File access grant store: a plugin
grants one file to a member or an address, lists what a file has handed out,
and revokes what it gave. The response carries the signed unlock link, so a
seller can deliver a file to somebody with no account. Nothing on the wire
names the calling plugin: the host stamps plugin:<name> on what this family
writes and refuses a revoke of anything else. ADR 0008.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 10:47:13 +08:00

55 lines
2.8 KiB
Go

package caps
import (
"git.dev.alexdunmow.com/block/pluginsdk/plugin"
)
// NewCoreServices assembles the guest-side CoreServices value plugins receive
// in their Load/HTTP/Job hooks: every capability interface is a stub that
// marshals to a "<family>.<method>" host call over the injected transport.
//
// The transport is injected (not a package global) so the marshaling logic is
// natively testable with a fake CallFunc; the wasm shim (package wasmguest,
// wasip1) passes its host_call-backed CallHost. A nil call yields stubs that
// fail every capability with a clear "no host transport" error — the shape
// used by DESCRIBE probes, which never reach a live host.
//
// Members intentionally left zero because they do NOT cross as capability
// calls (all documented in core/docs/wasm-abi.md §"Capability calls"):
//
// - Pool → the db.* driver messages (db.proto)
// - Interceptors → host-side connect options; RBAC from the manifest
// - MediaPath / AppURL → delivered in LoadRequest.host_config at load
// - CoreServiceBindings → static manifest.core_service_bindings; host mounts
func NewCoreServices(call CallFunc) plugin.CoreServices {
settings := &settingsStub{base: base{family: "settings", call: call}}
ai := &aiStub{base: base{family: "ai", call: call}}
return plugin.CoreServices{
Content: &contentStub{base{family: "content", call: call}},
ContentAuthor: &authorStub{base{family: "content", call: call}},
Settings: settings,
SettingsUpdater: settings,
Gating: &gatingStub{base{family: "gating", call: call}},
Crypto: &cryptoStub{base{family: "crypto", call: call}},
Menus: &menusStub{base{family: "menus", call: call}},
Datasources: &datasourcesStub{base{family: "datasources", call: call}},
DataTables: &datatablesStub{base{family: "datatables", call: call}},
PublicUsers: &usersStub{base{family: "users", call: call}},
Subscriptions: &subscriptionsStub{base{family: "subscriptions", call: call}},
Media: &mediaStub{base{family: "media", call: call}},
ToolRegistry: ai,
AITextCall: ai.textCall,
EmailSender: &emailStub{base{family: "email", call: call}},
Bridge: &bridgeStub{base: base{family: "bridge", call: call}},
ReviewSubmitter: &reviewsStub{base{family: "reviews", call: call}},
BadgeRefresher: &badgesStub{base{family: "badges", call: call}},
FileGrants: &filesStub{base{family: "files", call: call}},
JobRunner: &jobsStub{base{family: "jobs", call: call}},
EmbeddingService: &embeddingsStub{base{family: "embeddings", call: call}},
RAGService: NewRAGStub(call),
Provisioner: &provisionerStub{base{family: "provisioner", call: call}},
OutboundHTTP: &httpStub{base{family: "http", call: call}},
}
}