Add update and revocation handling for installed official plugins #181
Labels
No labels
abandoned
active
audit
blocked
data-safety
difficulty:easy
difficulty:hard
difficulty:high
difficulty:medium
docs
done
duplicate
notebook-v0
open
priority:high
ready
release-critical
safe-mode
spec
spec-backlog
subsystem:api
subsystem:backlog
subsystem:bases
subsystem:ci
subsystem:command
subsystem:configuration
subsystem:consolidate
subsystem:dependencies
subsystem:desktop-electron
subsystem:diffmerge
subsystem:docker
subsystem:docs
subsystem:fuzzy
subsystem:graph
subsystem:hotkeys
subsystem:lapis
subsystem:maint
subsystem:maintenance
subsystem:markdown
subsystem:markdown-lint
subsystem:md018
subsystem:notebook
subsystem:notifications
subsystem:opfs
subsystem:package
subsystem:plugin-markdown
subsystem:plugin-tasks
subsystem:plugins
subsystem:registry
subsystem:release
subsystem:renovate
subsystem:restore
subsystem:scripts
subsystem:search
subsystem:settings
subsystem:spec
subsystem:tasks
subsystem:testing
subsystem:ui
subsystem:web
subsystem:workspace
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
lapis-notes/lapis#181
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Installed official plugins need verified update and revocation handling before Full Registry V1 is complete.
Goal
Add compatible update listing, verified update install, revocation handling, and UI explanations for installed official plugins.
Scope
Non-goals
Acceptance Criteria
Implementation Notes
revoked.jsonparsing/fetching in the registry client and cache it beside catalog metadata.PluginDistributionManager.refreshCatalog()apply revocation policy to installed official records without trusting plugin manifests.Suggested Files or Specs To Inspect
Validation Commands
pnpm --filter @lapis-notes/api check:allpnpm --filter @lapis-notes/workspace check:allpnpm test:smokeRelated Issues
Follow-up Tasks
Implementation Summary
Added signed revoked.json fetching and caching, applied revocation policy to installed official plugin records, expanded update listing for compatible, incompatible, and revoked states, preserved enabled state during verified updates, surfaced revoked/update states in Plugins settings, and validated checks plus smoke.