-
Notifications
You must be signed in to change notification settings - Fork 180
Home
Local plugin docs for the Electron desktop app. Plugins are installed from a directory, disabled until you grant their declared permissions, and never receive GitHub tokens, AI keys, or Electron APIs.
插件系统仅在 Electron 桌面端可用。从本地目录安装,默认禁用,启用前必须确认 Manifest 权限。宿主不会把 GitHub Token、AI Key 或 Electron API 交给插件。
- Plugin usage — install, enable, permissions, where plugin actions appear, community registry readout
- Plugin development — Manifest, Worker API, page bridge, modal actions, limits, examples
Shipped with PR #357 (V1–V1.3) and PR #420 (V1.4: modal actions opensPage with repository context, page clipboard/download output). The community plugin registry (#389 / #394) is informational only — Settings compares installed plugins against it and flags updates, permission changes, and revoked or blocked versions; nothing is downloaded or disabled automatically. Official examples live in examples/plugins/.
随 PR #357(V1–V1.3)与 PR #420(V1.4:弹窗动作 opensPage 与仓库上下文、页面剪贴板 / 下载输出)合入。社区插件注册表(#389 / #394)只是信息展示:设置页会把已安装插件与注册表比对,提示更新、权限变化和撤销 / 拉黑状态,不会自动下载或停用任何插件。官方示例见 examples/plugins/。
| Kind / 类型 | Runtime / 运行时 | Trust / 信任级别 |
|---|---|---|
Worker plugin (main) |
Isolated worker_threads.Worker
|
Trusted local Node.js. Lifecycle, crash, and timeout isolation only — not a security sandbox. |
Page plugin (contributes.pages) |
Sandboxed iframe (sandbox="allow-scripts allow-same-origin", origin plugin-page://<id>) + plugin-page: protocol |
Untrusted page content. No Node, no Electron, no tokens. Data goes through a validated Host bridge. |
A plugin may ship both. The page isolation does not reduce Worker privileges.
带 main 的 Worker 插件是受信任的本地 Node.js 代码:Worker 只隔离生命周期、崩溃和超时,不是安全沙箱。页面插件在受限 iframe 中运行。两者可以同时存在;页面隔离不会降低 Worker 权限。