Files
NetMesh/infrastructure/services/adapters/pluginSyncObjectStorage.ts
zhaolei 3c72efcb7f
Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
[Init] Initial commit - NetMesh terminal manager
2026-09-13 18:24:01 +08:00

139 lines
5.0 KiB
TypeScript

/**
* EncryptedObjectStorage implementation that drives a plugin sync Provider
* through the host extension Provider service. Plugins only ever see already
* encrypted object bytes — never the master key or plaintext vault.
*/
import type {
EncryptedObjectAccount,
EncryptedObjectDeleteResult,
EncryptedObjectReadResult,
EncryptedObjectStorage,
EncryptedObjectStorageCapabilities,
EncryptedObjectWriteResult,
} from '../../../domain/encryptedObjectStorage';
import type { PluginSyncCredentialRef as DurablePluginSyncCredentialRef } from '../../../domain/sync';
/**
* SyncConnectPayload.credential — includes one-shot leases for live connect.
* Durable reconnect persistence only keeps secret/credential refs (see domain).
*/
export type PluginSyncCredentialRef =
| DurablePluginSyncCredentialRef
| { kind: 'secret-lease'; id: string; key?: string; operationId?: string; expiresAt?: number };
export type { DurablePluginSyncCredentialRef };
export interface PluginSyncProviderHost {
connectSync(
params: {
providerId: string;
configuration?: unknown;
credential?: PluginSyncCredentialRef;
deadlineMs?: number;
},
options?: { signal?: AbortSignal },
): Promise<{ account: EncryptedObjectAccount }>;
disconnectSync(
params: { providerId: string; deadlineMs?: number },
options?: { signal?: AbortSignal },
): Promise<null>;
getSyncAccount(
params: { providerId: string; deadlineMs?: number },
options?: { signal?: AbortSignal },
): Promise<{ account: EncryptedObjectAccount | null }>;
getSyncCapabilities(
params: { providerId: string; deadlineMs?: number },
options?: { signal?: AbortSignal },
): Promise<EncryptedObjectStorageCapabilities>;
readSyncObject(
params: { providerId: string; key: string; preferStream?: boolean; deadlineMs?: number },
options?: { signal?: AbortSignal },
): Promise<{
found: boolean;
key: string;
bytes: Uint8Array | null;
revision?: string;
contentType?: string;
}>;
writeSyncObject(
params: {
providerId: string;
key: string;
bytes: Uint8Array;
expectedRevision?: string | null;
preferStream?: boolean;
deadlineMs?: number;
},
options?: { signal?: AbortSignal },
): Promise<{ created: boolean; revision?: string }>;
deleteSyncObject(
params: { providerId: string; key: string; expectedRevision?: string; deadlineMs?: number },
options?: { signal?: AbortSignal },
): Promise<{ deleted: boolean }>;
}
export function createPluginSyncObjectStorage(options: {
providerId: string;
host: PluginSyncProviderHost;
configuration?: unknown;
/** Canonical SyncConnectPayload.credential for host-owned secret refs. */
credential?: PluginSyncCredentialRef;
deadlineMs?: number;
}): EncryptedObjectStorage {
const { providerId, host, configuration, credential, deadlineMs } = options;
return {
providerId,
async connect(connectConfiguration, connectOptions): Promise<{ account: EncryptedObjectAccount }> {
// Only treat undefined as "use stored / default". Explicit null is a
// valid JSON configuration for schemas with type: "null".
const resolvedConfiguration = connectConfiguration !== undefined
? connectConfiguration
: (configuration !== undefined ? configuration : {});
return host.connectSync({
providerId,
configuration: resolvedConfiguration,
...(credential ? { credential } : {}),
deadlineMs,
}, { signal: connectOptions?.signal });
},
async disconnect(disconnectOptions): Promise<void> {
await host.disconnectSync({ providerId, deadlineMs }, { signal: disconnectOptions?.signal });
},
async getAccount(accountOptions): Promise<EncryptedObjectAccount | null> {
const result = await host.getSyncAccount({ providerId, deadlineMs }, { signal: accountOptions?.signal });
return result.account ?? null;
},
async getCapabilities(capOptions): Promise<EncryptedObjectStorageCapabilities> {
return host.getSyncCapabilities({ providerId, deadlineMs }, { signal: capOptions?.signal });
},
async readObject(key, readOptions): Promise<EncryptedObjectReadResult> {
return host.readSyncObject({
providerId,
key,
preferStream: readOptions?.preferStream,
deadlineMs,
}, { signal: readOptions?.signal });
},
async writeObject(key, bytes, writeOptions): Promise<EncryptedObjectWriteResult> {
return host.writeSyncObject({
providerId,
key,
bytes,
expectedRevision: writeOptions?.expectedRevision,
preferStream: writeOptions?.preferStream,
deadlineMs,
}, { signal: writeOptions?.signal });
},
async deleteObject(key, deleteOptions): Promise<EncryptedObjectDeleteResult> {
return host.deleteSyncObject({
providerId,
key,
expectedRevision: deleteOptions?.expectedRevision,
deadlineMs,
}, { signal: deleteOptions?.signal });
},
};
}