Repository navigation
feat(web-shell): share HTML artifacts through managed hosting #10024
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
f1a6fc4
03f9870
fa917a2
34173f1
3063685
b16bdcd
bba81a3
73381f8
1f6c187
e34a6cf
a0035e3
09747eb
4ab71b5
f4eab1b
74e1489
7330ba5
b2f4c82
de76d60
7d2f844
8f3ccb8
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3897,7 +3897,7 @@ const SETTINGS_SCHEMA = { | |
| requiresRestart: true, | ||
| default: '', | ||
| description: | ||
| 'Command that uploads the artifact, run with execFile (no shell). {file} = local HTML path, {key} = remote object key. e.g. "aws s3 cp {file} s3://bucket/{key} --content-type text/html".', | ||
| 'Command run with execFile (no shell). Template mode uses {file} and {key}; command-output mode uses {dir} for the temporary static site directory.', | ||
| showInDialog: false, | ||
| }, | ||
| urlTemplate: { | ||
|
|
@@ -3910,6 +3910,16 @@ const SETTINGS_SCHEMA = { | |
| 'Shareable URL template; {key} is substituted. e.g. "https://bucket.example.com/{key}".', | ||
| showInDialog: false, | ||
| }, | ||
| urlFromCommandOutput: { | ||
| type: 'boolean', | ||
| label: 'URL From Command Output', | ||
| category: 'Experimental', | ||
| requiresRestart: true, | ||
| default: false, | ||
| description: | ||
| 'Deploy the temporary site directory through uploadCommand and read its public HTTPS URL from stdout. The command must include {dir}; stdout may be a URL or JSON containing url, ssl_url, deploy_url, deploy_ssl_url, or deployUrl.', | ||
| showInDialog: false, | ||
| }, | ||
| keyPrefix: { | ||
| type: 'string', | ||
| label: 'Key Prefix', | ||
|
|
@@ -3922,6 +3932,143 @@ const SETTINGS_SCHEMA = { | |
| }, | ||
| }, | ||
| }, | ||
| share: { | ||
| type: 'object', | ||
| label: 'Artifact Sharing', | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Needs a maintainer's decision — not settled here. Restricting artifact publish-target state from workspace scope requires choosing where daemon-managed share state is persisted: enforce a workspace-scope restriction, or move the state to user-scope/daemon-owned storage. Which direction do you want? The thread stays open until answered. 中文说明需要维护者决策——此处不做决定。限制 artifact 发布目标状态不得来自工作区作用域,需要先选择守护进程托管的共享状态持久化到哪里:强制工作区作用域限制,还是把状态移到用户作用域/守护进程自有存储。请选择方向?线程保持开放直至有答复。
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Needs a maintainer's decision — not settled here. Restricting artifact publish-target state from workspace scope requires choosing where daemon-managed share state is persisted: enforce a workspace-scope restriction, or move the state to user-scope/daemon-owned storage. Which direction do you want? The thread stays open until answered. 中文说明需要维护者决策——此处不做决定。限制 artifact 发布目标状态不得来自工作区作用域,需要先选择守护进程托管的共享状态持久化到哪里:强制工作区作用域限制,还是把状态移到用户作用域/守护进程自有存储。请选择方向?线程保持开放直至有答复。
Comment on lines
+3935
to
+3937
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Deferred — superseded by the re-post of this finding at later heads (round-6 thread 3876242254, round-7 3879310211, round-8 3882827665); the current status is recorded there. The maintainer's round-6 summary additionally defers this class (workspace-scope publish-target trust) to the policy owner as a follow-up. This round was scoped to the rejected verification gate only. 中文说明延后——该发现已在更晚的 head 上重新发布(第 6 轮线程 3876242254、第 7 轮 3879310211、第 8 轮 3882827665),当前状态记录于相应线程。维护者的第 6 轮总结还把该类问题(工作区作用域的发布目标信任)交给策略负责人作为后续跟进。本轮只处理被拒的验证门禁。
Comment on lines
+3935
to
+3937
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Deferred by maintainer decision (round-6 summary comment): workspace-scope publish-target trust is a policy decision for the scope-policy owner, tracked as a follow-up. Re-posted at round 8 (3882827665) with the connectVercel pendingName entrance. This round was scoped to the rejected verification gate only. 中文说明按维护者决定延后(第 6 轮总结评论):工作区作用域的发布目标信任是作用域策略负责人的策略决定,作为后续跟进。已在第 8 轮(3882827665)连同 connectVercel pendingName 入口重新发布。本轮只处理被拒的验证门禁。
Comment on lines
+3935
to
+3937
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Deferred by maintainer decision (round-6 summary comment): workspace-scope publish-target trust is a policy decision for the scope-policy owner, tracked as a follow-up. Still open at the current head (8f3ccb8). This round was scoped to the rejected verification gate only, which no longer reproduces (see the round report). 中文说明按维护者决定延后(第 6 轮总结评论):工作区作用域的发布目标信任是作用域策略负责人的策略决定,作为后续跟进。在当前头(8f3ccb8ae6)仍开放。本轮只处理被拒的验证门禁,该失败已无法复现(见本轮报告)。 |
||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: {}, | ||
| description: | ||
| 'Daemon-managed targets used by the Web Shell artifact sharing flow.', | ||
| showInDialog: false, | ||
| properties: { | ||
| enabled: { | ||
| type: 'boolean', | ||
| label: 'Artifact Sharing', | ||
| category: 'Artifacts', | ||
| requiresRestart: false, | ||
| default: true, | ||
| description: | ||
| 'Show the Share action for workspace HTML artifacts and allow Web Shell publishing through configured hosting providers.', | ||
| showInDialog: true, | ||
| }, | ||
| publications: { | ||
| type: 'array', | ||
| label: 'Artifact Publication History', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: [], | ||
| description: | ||
| 'Latest public deployment metadata used to avoid redeploying unchanged artifacts.', | ||
| showInDialog: false, | ||
| items: { | ||
| type: 'object', | ||
| additionalProperties: false, | ||
| properties: { | ||
| provider: { | ||
| type: 'string', | ||
| enum: ['cloudflare', 'vercel', 'netlify'], | ||
| required: true, | ||
| }, | ||
| targetId: { type: 'string', required: true }, | ||
| artifactId: { type: 'string', required: true }, | ||
| contentHash: { type: 'string', required: true }, | ||
| publishedId: { type: 'string', required: true }, | ||
| url: { type: 'string', required: true }, | ||
| publishedAt: { type: 'string', required: true }, | ||
| }, | ||
| }, | ||
| }, | ||
| cloudflare: { | ||
| type: 'object', | ||
| label: 'Cloudflare Pages', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: {}, | ||
| showInDialog: false, | ||
| properties: { | ||
| accountId: { | ||
| type: 'string', | ||
| label: 'Cloudflare Account ID', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| projectName: { | ||
| type: 'string', | ||
| label: 'Cloudflare Pages Project', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| }, | ||
| }, | ||
| vercel: { | ||
| type: 'object', | ||
| label: 'Vercel', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: {}, | ||
| showInDialog: false, | ||
| properties: { | ||
| projectId: { | ||
| type: 'string', | ||
| label: 'Vercel Project ID', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| projectName: { | ||
| type: 'string', | ||
| label: 'Vercel Project', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| scope: { | ||
| type: 'string', | ||
| label: 'Vercel Scope', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| }, | ||
| }, | ||
| netlify: { | ||
| type: 'object', | ||
| label: 'Netlify', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: {}, | ||
| showInDialog: false, | ||
| properties: { | ||
| siteId: { | ||
| type: 'string', | ||
| label: 'Netlify Site ID', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| showInDialog: false, | ||
| }, | ||
| dedicatedSiteId: { | ||
| type: 'string', | ||
| label: 'Netlify Dedicated Site ID', | ||
| category: 'Experimental', | ||
| requiresRestart: false, | ||
| default: '', | ||
| description: | ||
| "Set by the sharing setup when it creates a Netlify site of its own. Publishing relaxes a site's password and SSO protection only when this matches the target site, so a project you had already linked yourself keeps its access settings.", | ||
| showInDialog: false, | ||
| }, | ||
| }, | ||
| }, | ||
| }, | ||
| }, | ||
| oss: { | ||
| type: 'object', | ||
| label: 'Artifact OSS', | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Needs a maintainer's decision — not settled here. Restricting artifact publish-target state from workspace scope requires choosing where daemon-managed share state is persisted: enforce a workspace-scope restriction, or move the state to user-scope/daemon-owned storage. Which direction do you want? The thread stays open until answered.
中文说明
需要维护者决策——此处不做决定。限制 artifact 发布目标状态不得来自工作区作用域,需要先选择守护进程托管的共享状态持久化到哪里:强制工作区作用域限制,还是把状态移到用户作用域/守护进程自有存储。请选择方向?线程保持开放直至有答复。