Plugin API v0 #59
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#59
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #37.
What Relay does
Plugin API v0 — internal in 0.8.9, public in 0.8.12.
getUsers(),getCurrentUser(),registerTextView()/unregisterTextView(), plus workspaceevents
system3-relay:api-ready,:v0:users,:v0:current-user, typed in ashipped
relay-plugin-api.d.ts.What we do today
Nothing. No API surface for other plugins at all.
What changes
api.tsplus a published.d.ts.getUsers()reads awareness,getCurrentUser()reads the session — both already exist internally. Viewregistration is the larger half and overlaps with what Kanban multiplayer needs.
Why it belongs after comments, not before
Relay built comments on their API. We can build ours first and extract the
API from what it needed, which yields a smaller and more honest surface than
designing one speculatively.
What must not leak
The API runs inside the trust boundary.
docs/security-model.mdalready recordsthat secret ids are global to the app and any installed plugin can read our keys
— that is Obsidian's design and no storage choice changes it. This API must not
make it easier: no key material, no passphrase, no document ids paired with
paths (that pairing is the one thing that would undo the HMAC).
Risk
risk:noneto sync; a real surface-area decision for the security model.Verification
docs/security-model.mdis updated to describe what the API exposes, and theclaim is checked against the code as that document is written to be.
Moved to the Vikunja board as NEC-36: https://projectron.nerchure.com/tasks/36