4.0 KiB
ADDED Requirements
Requirement: Plugin manifests declare remote access methods
Game management plugin manifests SHALL declare remote access methods before platform exposes FTP, rsync, or run-mediated remote server operations for server instances created from that plugin.
Scenario: Manifest declares supported methods
- WHEN a plugin manifest lists
ftp,rsync, orrununder remote access methods - THEN platform registry and marketplace responses MUST preserve those methods without exposing host paths, remote credentials, direct sockets, or provider secrets
Scenario: Unsafe remote access declaration is rejected
- WHEN a plugin manifest includes raw credentials, host paths, direct run socket details, or unknown remote access methods
- THEN plugin workspace validation and platform registration MUST reject the manifest before it becomes installable
Requirement: Remote run operations are capability gated
Remote run operations SHALL be represented as explicit run capabilities and SHALL require both the run endpoint and the installed game plugin to declare the requested capability.
Scenario: Declared remote run job is queued
- WHEN a plugin declares a remote run capability and the selected run endpoint reports the same capability
- THEN platform MAY queue a bounded job for that server instance using logical target keys and scoped input or artifact refs
Scenario: Undeclared remote run job is denied
- WHEN a caller requests remote database, RCON, log transfer, or remote file work for a server instance whose plugin did not declare the requested capability
- THEN platform MUST reject or deny the request before creating a job
Requirement: Remote access bridge is platform mediated
Plugin pages SHALL request remote access through a platform-mediated bridge action and MUST NOT connect directly to FTP, rsync, run, MySQL, SQLite, log storage, or RCON endpoints.
Scenario: Bridge queues declared remote access
- WHEN a plugin page has
server.remote.accesspermission and requestsremote.access.requestfor a declared capability - THEN platform MUST authorize the action and queue the corresponding bounded run job
Scenario: Bridge denies undeclared remote access
- WHEN a plugin page requests
remote.access.requestfor a capability not declared by the plugin - THEN platform MUST return a safe denial and MUST NOT expose run credentials, host paths, database DSNs, RCON passwords, or remote storage endpoints
Requirement: Run handles bounded remote jobs
Run SHALL report supported remote capabilities and complete remote job assignments with bounded progress and safe result references while keeping control, job, logs, and artifact channels separate.
Scenario: Run accepts remote database and RCON assignments
- WHEN run receives declared remote MySQL, SQLite, RCON, log transfer, or remote file assignments
- THEN run MUST validate bounded job metadata and return terminal results without embedding raw credentials, host paths, query result bodies, log bodies, or RCON output in the job result payload
Scenario: Run rejects unsafe remote job payload
- WHEN a remote job assignment includes an absolute path, parent traversal, raw secret, direct socket, or oversized inline content
- THEN run MUST reject the assignment with a bounded failure result
Requirement: MC and SCUM plugins share the remote access model
First-party Minecraft and SCUM plugin manifests SHALL validate against the same remote access schema and declare only the capabilities each game needs.
Scenario: Minecraft plugin validates
- WHEN the Minecraft example plugin declares run-managed files, logs, and RCON access
- THEN plugin workspace manifest validation MUST pass
Scenario: SCUM plugin validates
- WHEN the SCUM example plugin declares FTP/rsync/run file access, run lifecycle, SQLite/MySQL database read compatibility, log transfer, and RCON access
- THEN plugin workspace manifest validation MUST pass