- api: PATCH /admin/plugins/:id/mode (Site Admin) switches
disabled/optional/required; new PluginPondController exposes
GET /ponds/:id/plugins (effective list: required + optional-enabled,
pond read access — the SPA loads it per pond), GET .../plugins/settings
and PUT .../plugins/:pluginId (Pond Admin) to toggle optional plugins.
Toggling a non-optional plugin is refused (plugin_not_optional).
Install/uninstall/mode/toggle are audit-logged.
- web: PluginManager in the admin area lists installed plugins with their
declared permissions surfaced prominently (security.md), an upload
control that shows validation errors, a mode switch with an impact
hint, and a link to the sandbox preview. PondPluginSettings adds a
per-pond optional-plugin toggle section to pond settings.
- shared: PondPluginSetting, mode/toggle input schemas, plugin_not_optional
error code + de/en messages, plugins i18n (admin/mode/pond).
- tests: api db test covers mode switching, per-pond activation, the
required-everywhere and disabled-nowhere propagation, and the
not-optional guard; e2e plugin-admin pack drives the admin list,
permission display, mode switch, and pond toggle end to end.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1