mirror of
https://github.com/penpot/penpot.git
synced 2026-09-14 06:40:00 -04:00
* 🐛 Fix deep-harden of host plugin context on load ses.harden(context) in loadPlugin deep-freezes every host-owned object and function reachable through the context. The host keeps needing to modify those across page navigation (listener wrappers, proxies), so a later property augmentation (e.g. assigning toString) throws 'TypeError: Cannot assign to read only property toString' and kills the MCP session (penpot/penpot#11001). Pass the host context through untouched; sandbox isolation stays at the compartment boundary (hardened sandbox-owned globals + ses.safeReturn). Regression test: load-plugin-context.spec.ts (no ses mock). AI-assisted-by: muse-spark-1.3 Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> * 🐛 Add real SES bootstrap to host-context regression test The previous load-plugin-context.spec.ts had no SES bootstrap, so it failed on the original code with 'ReferenceError: harden is not defined' instead of the intended freeze assertion, and passed on the fixed code merely by avoiding ses.harden. Now the spec bootstraps real SES (repairIntrinsics + hardenIntrinsics), adds a control test proving real ses.harden deep-freezes host-owned functions (Object.isFrozen === true, later toString assignment throws TypeError - the #11001 crash signature), and keeps the regression test asserting loadPlugin leaves host functions unfrozen and patchable. AI-assisted-by: muse-spark-1.3 Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> * 🐛 Add production-order hardening contrast evidence Proves the initialization-ordering hazard behind #11001 (cf. #8636): in production, index.ts runs repairIntrinsics only at module load while hardenIntrinsics runs later in createSandbox. The original loadPlugin called ses.harden(context) between those steps, freezing the shared Function.prototype with plain data properties so later override taming is skipped and any subsequent fn.toString assignment throws TypeError. Kept in a separate spec file so the full SES bootstrap in load-plugin-context.spec.ts cannot mask the ordering effect. AI-assisted-by: muse-spark-1.3 Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> * 🐛 Apply approved lint fix and CHANGELOG entry Restores the two approved deliverables missing from the previous push: the prefer-rest-params fix in load-plugin-harden-order.spec.ts (replacing the deprecated arguments usage) and the plugins-runtime CHANGELOG entry for the host-context harden fix (#11001). AI-assisted-by: muse-spark-1.3 Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> * 🐛 Remove deep-hardening of host plugin context on load Signed-off-by: makesomethingshit <junsoo1172@gmail.com> Co-authored-by: multica-agent <github@multica.ai> Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> * 🐛 Align CHANGELOG and context comment with reviewed evidence AI-assisted-by: multica-agent Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> Co-authored-by: multica-agent <github@multica.ai> * 🔥 Remove SES semantic tests from plugin regression coverage Drop the tests that only verify SES library semantics rather than Penpot application behavior: - Delete load-plugin-harden-order.spec.ts (pure SES initialization-order evidence, never calls loadPlugin). - Remove the ses.harden control test and its SES bootstrap setup from load-plugin-context.spec.ts. - Remove the #8636 hardening-order contrast test and the now-unused ses import from load-plugin-real-path.spec.ts. Keep the application-level regression coverage: the real loadPlugin initialization path, permission enforcement, host-context isolation and safeReturn protection. No production code changes. Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> AI-assisted-by: Omen Alpha --------- Signed-off-by: Junsoo Choi <junsoo1172@gmail.com> Signed-off-by: makesomethingshit <junsoo1172@gmail.com> Co-authored-by: multica-agent <github@multica.ai> Co-authored-by: Andrey Antukh <niwi@niwi.nz>
Plugins runtime
The plugins-runtime is responsible for generating the API and loading Penpot's plugins.