fix: honor catalog release packages instead of repository root - #93
Closed
loopx-agent wants to merge 2 commits into
Closed
loopx-agent wants to merge 2 commits into
loopx-agent wants to merge 2 commits into
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Owner
|
Thanks @loopx-agent — this is a real bug, and your diagnosis is spot on. We've fixed it and shipped it. The fix is released in v1.4.14 and is live on npm, following the same approach you outlined:
Release notes: https://github.com/dshplugin/dsh-plugin-hub/releases/tag/v1.4.14 — with credit to you for both the report and the reference implementation. Install it with: dsh plugin --profile web add dsh-pluginThanks again for the detailed write-up and for taking the time to prepare the reference fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The live catalog's LoopX entry already supplies a prebuilt GitHub release
.tgzinigc. With no npm package, the install button sendsowner/repoinstead, and the server falls back to repository HEAD. This selects the monorepo root and fails withentry file missing index.jseven though the catalog's displayed command names a complete package.Preserve npm priority, then select a same-repository release target from the existing authoritative catalog command, before the legacy Git fallback. A shared, pure installer parser accepts only a fixed HTTPS
github.com/<owner>/<repo>/releases/download/<tag>/<asset>.tgztarget; it never executes command text. Cross-repository catalog redirects, foreign hosts, credentials, moving latest URLs, query/fragment data, extra CLI arguments and shell code are rejected.The HTTP installer preserves the release URL, uses the existing GitHub security setting and proxy path, and probes HTTP rather than a Git clone. Release packages bypass the unrelated repository-HEAD preflight; the existing post-install entry validation remains active. Repository identity is preserved for installed-state readback, deduplication, pinned updates and package-name removal. No new setting or UI control is added. Tracked server/Client artifacts and the new helper declarations are included; rebuilding changes CSS module identifiers without changing styles.
Validation:
npm run checkpassed: client/server/test type checks, 107 tests passed, 2 platform tests skipped, server and Client builds. Run withGIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_NOSYSTEM=1; an initial proxy test was affected by local Git URL rewriting and passed with that configuration isolated.@latest, then uninstalled with readback. No npm publication or model call was needed. A browser-mounted Hub interaction was not exercised.Related repair: loopx-project/loopx#5589 and the repeated distribution incidents linked there. This PR requires upstream review and a Hub release before existing installations adopt the behavior; it does not claim deployment.
Remote CI is currently
action_requiredon the fork pull request (no jobs executed). An upstream maintainer must authorize the workflow before remote CI evidence is available; local checks above are kept separate from that gate.