feat(coding-agent): accept GitHub/git URLs in plugin install

Extends `omp plugin install` to accept git sources alongside npm specs and
marketplace refs. Bun's installer already understands git URLs; the blocker
was `PluginManager.install`'s strict npm-name validator and the assumption
that the actual package name could be derived from the spec.

- `git-url.ts`: `parseGitUrl` now recognizes npm-style namespaced shorthand
  (`github:user/repo`, `gitlab:`, `bitbucket:`, `codeberg:`, `sourcehut:` /
  `srht:`), with optional `#ref` and `.git` suffix. Exposes `isGitSpec` as
  `parseGitUrl(s) !== null`. Existing protocol-URL and `git:` shorthand paths
  are untouched.
- `manager.ts`: `install()` branches on `isGitSpec`. Git specs go through a
  separate `validateGitSpec` (shell-metachar rejection only — `/`, `:`, `@`,
  `#`, `+` are legal) and the real package name is discovered by snapshotting
  `plugins/package.json` deps before `bun install` and diffing afterwards.
  Falls back to value-match on force-reinstall where the key already exists.
- Help text in `plugin-cli` documents the new sources and adds a github:
  example.

Smoke tested end-to-end on Windows with both forms against the test repo:
  PluginManager.install('github:oldschoola/omp-insights')
  PluginManager.install('https://github.com/oldschoola/omp-insights')
both resolve `@oldschoola/omp-insights@1.2.3` and write a correct lock entry.
Shell-injection probe (`github:foo/bar; rm -rf /`) is rejected.
This commit is contained in:
oldschoola
2026-05-29 21:57:00 -07:00
committed by can1357
parent 4ab0360f65
commit 22e564a85d
6 changed files with 431 additions and 10 deletions
@@ -0,0 +1,123 @@
/**
* Install-from-git tests for `PluginManager.install`.
*
* Strategy: spy on the six `@oh-my-pi/pi-utils` plugin-path getters so the
* manager points at a temp directory tree, then spy on `Bun.spawn` so we can
* simulate `bun install <git-spec>`'s side effects (writing the dep into
* `plugins/package.json` under its real name, and dropping a matching
* `node_modules/<name>/package.json`). This exercises the real
* `PluginManager.install` end-to-end without hitting the network.
*
* `vi.spyOn` + `vi.restoreAllMocks()` is the same pattern used by
* `test/tools/report-tool-issue.test.ts` (which spies on
* `piUtils.getInstallId`), so we know namespace spying on `pi-utils` exports
* propagates through to consumers of the barrel re-exports. The
* `vi.spyOn(Bun, "spawn")` mock follows `test/git-process-config.test.ts`.
*/
import { afterEach, beforeEach, describe, expect, test, vi } from "bun:test";
import * as fs from "node:fs/promises";
import * as os from "node:os";
import * as path from "node:path";
import { PluginManager } from "@oh-my-pi/pi-coding-agent/extensibility/plugins/manager";
import * as piUtils from "@oh-my-pi/pi-utils";
import type { Subprocess } from "bun";
function emptyStream(): ReadableStream<Uint8Array> {
const body = new Response("").body;
if (!body) {
throw new Error("Failed to create empty response stream");
}
return body;
}
describe("PluginManager.install with git sources", () => {
let tmpRoot: string;
let pluginsDir: string;
let pluginsNodeModules: string;
let pluginsPkgJson: string;
beforeEach(async () => {
tmpRoot = await fs.mkdtemp(path.join(os.tmpdir(), "omp-plugin-git-"));
pluginsDir = path.join(tmpRoot, "plugins");
pluginsNodeModules = path.join(pluginsDir, "node_modules");
pluginsPkgJson = path.join(pluginsDir, "package.json");
await fs.mkdir(pluginsNodeModules, { recursive: true });
vi.spyOn(piUtils, "getPluginsDir").mockReturnValue(pluginsDir);
vi.spyOn(piUtils, "getPluginsNodeModules").mockReturnValue(pluginsNodeModules);
vi.spyOn(piUtils, "getPluginsPackageJson").mockReturnValue(pluginsPkgJson);
vi.spyOn(piUtils, "getPluginsLockfile").mockReturnValue(path.join(tmpRoot, "omp-plugins.lock.json"));
vi.spyOn(piUtils, "getProjectDir").mockReturnValue(tmpRoot);
vi.spyOn(piUtils, "getProjectPluginOverridesPath").mockReturnValue(path.join(tmpRoot, "plugin-overrides.json"));
});
afterEach(async () => {
vi.restoreAllMocks();
await fs.rm(tmpRoot, { recursive: true, force: true });
});
test("installs from github: shorthand and resolves real package name from deps diff", async () => {
// Seed the plugins manifest so install()'s `depsBefore` snapshot is empty
// rather than triggering #ensurePackageJson's bootstrap path.
await Bun.write(
pluginsPkgJson,
JSON.stringify({ name: "omp-plugins", private: true, dependencies: {} }, null, 2),
);
vi.spyOn(Bun, "spawn").mockImplementation(((cmd: string[]) => {
// Verify the manager forwards the spec verbatim to bun install.
expect(cmd[0]).toBe("bun");
expect(cmd[1]).toBe("install");
expect(cmd[2]).toBe("github:foo/bar");
// Simulate the on-disk side effects bun install produces for a git
// source: a new dep keyed by the package's own `name` field, plus
// the corresponding entry under node_modules.
const prepare = (async () => {
await Bun.write(
pluginsPkgJson,
JSON.stringify(
{
name: "omp-plugins",
private: true,
dependencies: { "real-name": "github:foo/bar" },
},
null,
2,
),
);
const installedDir = path.join(pluginsNodeModules, "real-name");
await fs.mkdir(installedDir, { recursive: true });
await Bun.write(
path.join(installedDir, "package.json"),
JSON.stringify({ name: "real-name", version: "0.1.0" }, null, 2),
);
})();
return {
pid: 1,
stdout: emptyStream(),
stderr: emptyStream(),
exited: prepare.then(() => 0),
} as Subprocess;
}) as typeof Bun.spawn);
const mgr = new PluginManager(tmpRoot);
const result = await mgr.install("github:foo/bar");
expect(result.name).toBe("real-name");
expect(result.version).toBe("0.1.0");
expect(result.enabled).toBe(true);
expect(result.path).toBe(path.join(pluginsNodeModules, "real-name"));
});
test("rejects git specs containing shell metacharacters", async () => {
const mgr = new PluginManager(tmpRoot);
await expect(mgr.install("github:foo/bar; rm -rf /")).rejects.toThrow(/Invalid characters in plugin source/);
});
test("still rejects invalid npm names with the original error", async () => {
const mgr = new PluginManager(tmpRoot);
await expect(mgr.install("Invalid Name With Spaces")).rejects.toThrow(/Invalid (package name|characters)/);
});
});