Files
browser/platform/validator/rules.md
T

1.6 KiB

Platform Validation Rules

  • API handlers must use named DTOs from platform/dto.
  • Platform services must not accept raw plugin-provided host paths.
  • AI provider secrets must be stored by reference and redacted from logs and plugin bridge responses.
  • Game management plugin installation must validate manifest identity, server type, required run capabilities, pages, permissions, and schema references.
  • Server instance creation must validate plugin installation state and run endpoint capability compatibility.
  • platform/validator/resources.go validates required IDs, enum values, AI key-reference shape, bounded progress summaries, artifact metadata, log stream cursors, and run capability compatibility.
  • platform/service.Core must call validators before repository writes and must reject server creation when the plugin is not installed, the run endpoint is disabled/offline, or required run capabilities are missing.
  • Job creation must require an idempotency key and return the existing job for duplicate (runEndpointId, idempotencyKey) pairs.

Client Manager lifecycle validation

Lifecycle validation rejects undeclared operations, stale attempt/deployment/key generations, cross-owner/server/profile/target/revision artifacts, unavailable endpoints, raw secrets, endpoint/socket values, traversal or absolute executable references, shell metacharacters, and unbounded timeouts. Registration additionally requires a current component-key HMAC, fresh nonce/timestamp, matching artifact and capabilities, and a monotonic heartbeat sequence. Safe DTOs are redacted before they cross the Platform boundary.