Implements the security core of the plugin system: code-plugin surfaces
run in opaque-origin iframes (sandbox="allow-scripts", never
allow-same-origin) with a capability-filtered RPC bridge.
- api: serve a per-plugin sandbox frame document at
/plugins/:id/:version/frame with a CSP that pins every load to the
plugin's own asset path (built from APP_BASE_URL, not the request Host,
so a Host-rewriting proxy cannot break it) and forbids network access
(connect-src 'none'). Plugin assets get Access-Control-Allow-Origin: *
so the null-origin frame can load its own module bundle.
- web: sandbox-host creates the frame, wires the SDK host bridge over a
source-filtered postMessage transport, drives render under a 5 s
deadline (hung/failed plugin -> placeholder, never a frozen page), and
tears down on unmount. PluginFrame/PluginPreviewPage surface it; the
built-in ui.resize handler clamps plugin-requested heights.
- plugin-sdk: host bridge reports gate violations via onViolation and
registers a gated handler for every v1 method, so an undeclared
capability is rejected with capability_not_permitted (not
unknown_method).
- tests: SDK gate unit test; web sandbox unit tests (opaque origin,
source filtering, timeout); and the e2e security pack with a permanent
malicious fixture plugin proving no escape (DOM/cookies/storage/fetch/
undeclared capability all blocked) plus well-behaved and hung cases.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1