Every plugin declares who it is — and Postulo stops throwing that away #97
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Postulo/postulo#97
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
The last line is #94's subject; this issue is the other five, plus the reason the last one
does not work today either.
What a plugin is actually required to declare
plugins/base.py, in full:SourcePluginConnectedPluginnamenamelabelversionversionA capture source is "anything with these four names" --
name,version,can_handle,parse. So a source cannot say what it is called in words, what it does, who wrote it, orwhere its code lives, and the built-in ones do not:
Most of it is already read, and then thrown away
installing.PackageInfopulls this out of a wheel before anything is installed:and the confirmation screen shows all four. Then
Installed(...)is built withname,version,origin,source,sha256,installed_at,installed_by,entry_points,disabledanddependencies-- and none of those four. They are read, displayed once,and dropped. After the install completes there is nowhere to look up who wrote a plugin or
what it claims to do.
And the source link is read from a header modern packaging no longer emits
Home-pagecomes from setuptools' oldurl=. A project using[project.urls]-- which isthe current standard -- emits
Project-URLinstead, and Postulo reads none of it. Checkedagainst what is actually installed here rather than from memory:
This already bites Postulo's own reference plugin.
postulo-helloworldis built withhatchling and declares:
which becomes
Project-URL: Homepage, ...in the wheel. Postulo asks forHome-page, getsnothing, and would show no source link for the plugin this project publishes as the example
to copy.
The author fallback has the same shape of problem:
Authoris a bare name;Author-emailisFirst Last <address>-- exactly the formasked for above. Trying
Authorfirst prefers the less informative of the two whenever apackage sets both.
Which layer owns which field
This is the design decision, and getting it wrong means the same fact stored twice. One
distribution can ship several plugins --
postulo-helloworldregisters both a source and anotifier from one wheel -- so some of these are per plugin and some are per package:
ConnectedPlugin.labelalready is thisAuthor-email, already standard, already the right formatProject-URL, first of Source / Repository / HomepageInstalled.sha256, already recorded, over the exact bytesSo the protocol gains
labelfor sources anddescriptionfor both, and the packagingmetadata answers the rest. Nothing new is invented where a standard field exists.
Two things worth deciding
1. The
postulo-prefix is already the convention, and it is a distribution name.postulo-helloworld,postulo-apprise,postulo-paperless. The plugin identifiers insideare short and unprefixed --
helloworld,schema.org,page-metadata-- which is right,because they are already scoped by the entry-point group.
Renaming the built-in sources would be a data migration, not a rename.
base.pysaysnameis "recorded against every capture this source produced", andJobPostingDatakeepsa
sourcefield, so every capture anybody has ever made carries the stringschema.orgorpage-metadata. Changing them orphans that history unless the old values are migrated. Ifthe prefix matters more than the history, say so and the migration comes with it -- but it
should be a decision rather than a side effect of tidying names.
2. An author's email address is a personal address, on a page.
Author-emailis publicin the wheel and on PyPI, so showing it to an administrator is no disclosure. #96 puts a
plugin list in front of every person on the instance, and an address rendered there is an
address harvested there. Suggest: the name for everyone, the address for administrators.
Scope
SourcePlugingainslabel; both protocols gaindescription. Both optional at first,with a sensible fallback, so no existing plugin stops loading -- a hard requirement would
break every plugin already written against the current contract.
Installedkeeps the summary, licence, author and source link it already reads.Project-URL(Source, then Repository, then Homepage) beforeHome-page;Author-emailbeforeAuthor.licence, and this repository as the source.
what it can from the installed
dist-inforather than showing blanks for ever.docs/PLUGINS.mdand the reference plugin updated --postulo-helloworlddeclaresauthors = [{ name = "Tiago Agueda" }]with no address, so it would not itself satisfy theformat this issue is about.
Project-URLyields a source link; one with both prefersAuthor-email; a plugin missing the new optional fields still loads.Classification
Enhancement, interface, documentation. Sits under #94, which uses this to say where a plugin
came from, and feeds #96, which shows it to the person.