Commit Graph
13 Commits
Author SHA1 Message Date
djdembeckandcan1357 5e45bee73f refactor: improve path handling with normalization refactor
- Refactor path normalization to combine expandPath and normalizeLocalScheme
- Add validation in utils.ts to reject local:// paths as filesystem paths
- Fix bash-skill-urls regex to handle hyphen-prefixed local:/ patterns
- Add tests for hyphen-prefixed and @local: patterns
2026-04-18 22:41:09 +02:00
djdembeckandcan1357 c7c3d4a82d fix: avoid matching local:/ in filesystem paths
- Add negative lookbehind to regex in bash-skill-urls to prevent matching local:/
  inside paths like /repo/local:/PLAN.md
- Normalize local scheme before expanding paths in path-utils
- Add test cases for both changes
2026-04-18 22:41:09 +02:00
djdembeckandcan1357 91998d326d fix: handle local:/ single-slash URL pattern
Expands the regex pattern to match local:/ (single-slash) URLs in addition to local:// (triple-slash), preventing potential Linux path leaks.

- Add regex patterns for single-quoted, double-quoted, and unquoted local:/ URLs
- Add test coverage for all three quote styles
2026-04-18 22:41:08 +02:00
djdembeckandcan1357 f353873b75 refactor: extract local:// URL normalization to shared utility
Extract duplicate normalizeLocalScheme regex pattern into a shared function in path-utils.ts. Updated interactive-mode.ts, approved-plan.ts, agent-session.ts, bash-skill-urls.ts, and plan-mode-guard.ts to use the shared utility. Also fixed error message formatting (removed extra backslashes).
2026-04-18 22:40:07 +02:00
djdembeckandcan1357 5da806671e fix: prevent local:// URI from creating local: directory on Linux
On Linux, Node's path.normalize() collapses the double slash in
local://PLAN.md to local:/PLAN.md, creating a directory called local:
in the project root instead of routing through the local:// protocol handler.

Defense-in-depth fixes across 5 layers:

1. resolveToCwd() now throws if a path starts with any internal URL
   scheme prefix (local:, agent:, skill:, etc.), preventing all 59
   call sites from treating URIs as relative filesystem paths.

2. resolvePlanPath() now matches on local: prefix (not just local://)
   and normalizes local:/ to local:// before resolution, catching
   all slash variants.

3. Bash URL expansion regex and early-exit checks now also match
   local:/ (single slash), and normalize before resolution.

4. Edit preview/diff functions now gracefully skip internal URL paths
   instead of crashing via the resolveToCwd guard.

5. All startsWith('local://') checks updated to startsWith('local:')
   with normalization in agent-session, interactive-mode, and
   approved-plan modules.

Also adds local: to .gitignore to prevent accidental commits of the
leaked directory.
2026-04-18 22:40:07 +02:00
Miroslav Drbalandcan1357 4e199f93f7 feat: add marketplace plugin system
Add Claude Code-compatible marketplace plugin infrastructure:

- Registry: types, ID helpers, atomic read/write for marketplaces.json
  and installed_plugins.json (Claude Code format with version: 2)
- Fetcher: classifySource (6 ordered rules), parseMarketplaceCatalog,
  fetchMarketplace (local sources; git/http stubs for Phase 2)
- Resolver + Cache: resolvePluginSource with pathIsWithin containment,
  cachePlugin, removeCachedPlugin, cleanOrphanedCache
- MarketplaceManager: orchestrates add/remove/update marketplaces,
  install/uninstall/enable plugins, clearPluginRootsCache on mutation
- CLI: omp plugin marketplace add|remove|update|list,
  omp plugin discover, classifyInstallTarget for name@marketplace
- Discovery: listClaudePluginRoots reads OMP registry alongside
  Claude's, OMP authoritative for duplicate plugin IDs
- Args: --plugin-dir repeatable flag (parsing only, runtime wiring TBD)
- Slash command: /reload-plugins clears fs + roots cache
- Test fixtures and 130 tests across 8 test files
2026-03-30 13:44:53 +02:00
can1357 e31f2ef6f0 refactor: simplified null checks using optional chaining across TypeScript and Rust modules
- Simplified null/empty checks across TypeScript codebase using optional chaining operator (?.) for improved readability.
- Replaced explicit null checks in validation logic with optional chaining in oauth-discovery, gemini-cli, claude, zai, and lsp modules.
- Updated error handling in Rust command invocation to use double question mark operator (??) for cmd_result.
- Consolidated null validation patterns across tools (bash-skill-urls, browser, gemini-image, resolve) and keybindings using optional chaining.
2026-03-26 14:09:14 +01:00
can1357 90f68431bf Fix local URL resolution for bash destinations 2026-02-23 01:51:54 +01:00
can1357 95ecf8ad1a refactor(coding-agent): simplified URL resolution and template formatting
- Removed try-catch wrapper around URL resolution in expandInternalUrls, allowing errors to propagate to caller.
- Simplified template formatting in subagent-user-prompt.md by collapsing context block to single line.
2026-02-22 18:44:50 +01:00
can1357 cd5c9655aa refactor: renamed notes protocol to local
- Renamed the `notes://` protocol to `local://` for better clarity.
- Updated all internal references, prompts, and tool documentation.
- Migrated plan storage paths to use the new `local://` scheme.
2026-02-22 18:05:22 +01:00
can1357 563d6a0ab9 feat(coding-agent): introduced notes:// protocol for session-scoped artifact storage
- Replaced plan:// protocol with notes:// for session-scoped artifact storage and plan finalization.
- Added title parameter to exit_plan_mode tool to enable plan file renaming during approval workflow.
- Implemented NotesProtocolHandler for notes:// URL scheme with path traversal protection and session fallback.
- Added renameApprovedPlanFile function to handle plan artifact finalization with validation and error handling.
- Updated system prompt documentation to reference notes:// protocol and internal URL schemes for artifact access.
2026-02-22 17:41:01 +01:00
can1357 8276390877 refactor(coding-agent): standardized XML tags and RFC 2119 keywords across prompts
- Standardized XML tag naming from snake_case to kebab-case across 50+ prompt files for consistency.
- Replaced imperative language with RFC 2119 keywords (MUST/SHOULD/MAY/MUST NOT) throughout system and tool prompts for clarity.
- Removed artifactsDir parameter from Python executor and simplified environment variable handling to use PI_SESSION_FILE only.
- Renamed read_path.md to read-path.md and updated memory guidance with hierarchy rules and conflict resolution workflow.
- Added noEscape option to bash URL expansion and extracted cwd parameter from leading cd commands for improved path handling.
- Exported NO_PAGER_ENV constant from bash-interactive module for centralized environment variable management.
2026-02-22 17:12:27 +01:00
can1357 ba1e3f8a07 fix(coding-agent): expanded internal url resolution and hardened memory protocol
Fixes #54
Fixes #74
2026-02-18 15:14:21 +01:00