Files
openchamber/packages/web/server/lib/opencode/npm-registry.js
T
Quat3rnionandBohdan Triapitsyn 2b47d899c6 feat: plugin settings (#1375)
* feat(settings): add opencode plugins page

Manage opencode `plugin` array entries (npm, scoped npm, versioned,
local paths) and auto-loaded plugin files in `~/.config/opencode/plugins/`
and `<project>/.opencode/plugins/`. Mirrors MCP CRUD pattern.

- Server: `plugins.js` data layer + `plugin-routes.js` REST routes
- UI: PluginsSidebar / PluginsPage / AddPluginDialog
- Store: usePluginsStore (cache TTL, in-flight dedup, narrow selectors)
- i18n: 41 keys across 7 locales

Whitelist /api/config/plugins in JSON body-parser so POST/PATCH bodies
parse; opencode plugin specs runtime-resolve OPENCODE_CONFIG dir so
parallel test files do not cross-pollute module-frozen consts.

* feat(settings/plugins): hook npm registry for update + invalid-version detection

Plugins page now consults registry.npmjs.org with a 1h server cache. Sidebar
rows show an update badge with the latest version, group headers show how
many updates are available, the kebab adds an "Update to latest" action
that reuses the existing PATCH+restart flow, and the editor surfaces a
banner for update-available / missing-version / missing-package / malformed
/ missing-path / unreadable-path / offline-registry states. A refresh
button in the sidebar header forces a cache bypass.

- Server: `npm-registry.js` (cache + in-flight dedup + 5s timeout, 404
  cached, network failures NOT cached) + `plugin-spec.js` (parser + exact
  semver detection) + `GET /api/config/plugins/registry?specs=...&refresh=`
- Routes accept up to 100 specs/request, dedup by npm package name before
  fetching, classify each result by kind, never propagate network failure
  as 500.
- Client: `registryInfo` slice + `loadRegistryInfo` (fire-and-forget after
  loadPlugins, refreshes on mutations) + `updateToLatest(id)`.
- UI: `RegistryBadge` per-row + `RegistryBanner` per-entry editor, both
  use theme tokens (text-only color, no new bg/border tokens) and the
  shared Icon sprite. Per-spec subscriptions only.
- i18n: 24 new keys (incl. split singular/plural for "N update(s)
  available" because the runtime does not parse ICU plural format).

* fix(settings/plugins): keep registry badge visible for long specs

Sidebar entry row used `inline-flex` with `truncate` only on the spec
text. With long npm specs the badge could be pushed past the row edge
and clipped by the parent overflow. Switch to `flex` with spec
`flex-1 min-w-0 truncate` and add `shrink-0` to the badge wrapper so
the update indicator stays anchored to the right of the row.

* fix(settings/plugins): use code-box icon to distinguish from MCP

Plugins nav entry used 'plug' which is visually too close to MCP's
'plug-2' icon. Swap to 'code-box' for clearer differentiation in the
Settings nav list.

* Update packages/ui/src/components/sections/plugins/PluginsPage.tsx

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Signed-off-by: Quat3rnion <81202811+Quat3rnion@users.noreply.github.com>

* Update packages/ui/src/stores/usePluginsStore.ts

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Signed-off-by: Quat3rnion <81202811+Quat3rnion@users.noreply.github.com>

* fix(settings/plugins): validate registry directory + surface save errors

- registry endpoint: return 400 on invalid directory query (was silently falling back to homedir, breaking relative path specs)
- save failure toast: prefer result.message over generic 'Reload failed'

* fix(settings/plugins): address review follow-ups

---------

Signed-off-by: Quat3rnion <81202811+Quat3rnion@users.noreply.github.com>
Co-authored-by: Bohdan Triapitsyn <artmore@protonmail.com>
2026-05-25 19:20:04 +03:00

158 lines
4.0 KiB
JavaScript

import fs from 'fs';
import path from 'path';
import { fileURLToPath } from 'url';
export const NPM_CACHE_TTL_MS = 3_600_000;
export const NPM_FETCH_TIMEOUT_MS = 5_000;
export const NPM_REGISTRY_BASE = 'https://registry.npmjs.org';
/**
* @typedef {Object} NpmPackagePayload
* @property {true} ok
* @property {string|null} latest
* @property {string[]} versions
* @property {Record<string, string>} distTags
*
* @typedef {Object} NpmLookupError
* @property {false} ok
* @property {number|'network'} status
* @property {string} error
*
* @typedef {NpmPackagePayload | NpmLookupError} NpmLookupResult
* @typedef {{ forceRefresh?: boolean }} NpmInfoOptions
* @typedef {{ fetchedAt: number, payload: NpmLookupResult }} CacheEntry
*/
/** @type {Map<string, CacheEntry>} */
const _cache = new Map();
/** @type {Map<string, Promise<NpmLookupResult>>} */
const _inFlight = new Map();
/** @type {string | null} */
let _userAgent = null;
function _getPackageJsonPath() {
const __dirname = path.dirname(fileURLToPath(import.meta.url));
return path.resolve(__dirname, '..', '..', '..', '..', '..', 'package.json');
}
function _getUserAgent() {
if (_userAgent) return _userAgent;
try {
const pkg = JSON.parse(fs.readFileSync(_getPackageJsonPath(), 'utf8'));
_userAgent = `openchamber-server/${typeof pkg.version === 'string' ? pkg.version : '0.0.0'}`;
} catch {
_userAgent = 'openchamber-server/dev';
}
return _userAgent;
}
function encodeName(name) {
return encodeURIComponent(name).replace(/^%40/, '@');
}
function parseDistTags(value) {
if (!value || typeof value !== 'object' || Array.isArray(value)) {
return {};
}
return Object.fromEntries(
Object.entries(value)
.filter((entry) => typeof entry[1] === 'string'),
);
}
function parseVersions(value) {
if (!value || typeof value !== 'object' || Array.isArray(value)) {
return [];
}
return Object.keys(value);
}
function cacheResult(name, payload) {
if (payload.ok || payload.status === 404) {
_cache.set(name, { fetchedAt: Date.now(), payload });
}
}
/**
* Fetch package metadata directly from the npm registry.
*
* @param {string} name npm package name
* @returns {Promise<NpmLookupResult>}
*/
export async function lookupNpmPackage(name) {
try {
const response = await fetch(`${NPM_REGISTRY_BASE}/${encodeName(name)}`, {
headers: {
'User-Agent': _getUserAgent(),
Accept: 'application/json',
},
signal: AbortSignal.timeout(NPM_FETCH_TIMEOUT_MS),
});
if (response.ok) {
const data = await response.json();
const distTags = parseDistTags(data?.['dist-tags']);
return {
ok: true,
latest: distTags.latest ?? null,
versions: parseVersions(data?.versions),
distTags,
};
}
if (response.status === 404) {
return { ok: false, status: 404, error: 'Package not found' };
}
return { ok: false, status: response.status, error: `Registry returned ${response.status}` };
} catch (error) {
return { ok: false, status: 'network', error: String(error?.message ?? error) };
}
}
/**
* Fetch package metadata with TTL cache and in-flight request deduplication.
*
* @param {string} name npm package name
* @param {NpmInfoOptions} [options]
* @returns {Promise<NpmLookupResult>}
*/
export async function getNpmInfo(name, options = {}) {
const { forceRefresh = false } = options;
const cached = _cache.get(name);
if (cached && !forceRefresh && Date.now() - cached.fetchedAt < NPM_CACHE_TTL_MS) {
return cached.payload;
}
const existing = _inFlight.get(name);
if (existing && !forceRefresh) {
return existing;
}
const lookup = (async () => {
const result = await lookupNpmPackage(name);
cacheResult(name, result);
return result;
})();
_inFlight.set(name, lookup);
try {
return await lookup;
} finally {
if (_inFlight.get(name) === lookup) {
_inFlight.delete(name);
}
}
}
export function clearCache() {
_cache.clear();
_inFlight.clear();
}