gate clide:// deep links: paranoid allowlist + confirmation prompt (T-56, D-90)
A clide:// link is an untrusted external vector (any webpage can fire one), so it no longer translates to a command in parseArgv. It routes the raw URL to a new builtin.deeplink handler that is doubly defensive: a default-deny allowlist (kDeepLinkSafeActions — only the read-only 'open' verb; run/git/write/passthrough rejected) AND a mandatory 'an external link wants to: … allow?' confirmation before anything runs. Records the security boundary as D-90. The earlier silent editor.open passthrough is replaced; open still works, now behind the prompt. Tests cover the allowlist (the boundary) + the gating. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -7,6 +7,7 @@ import 'package:clide/builtin/claude/claude.dart';
|
||||
import 'package:clide/builtin/claude_control/claude_control.dart';
|
||||
import 'package:clide/builtin/cli_install/cli_install.dart';
|
||||
import 'package:clide/builtin/decisions/decisions.dart';
|
||||
import 'package:clide/builtin/deeplink/deeplink.dart';
|
||||
import 'package:clide/builtin/default_layout/default_layout.dart';
|
||||
import 'package:clide/builtin/diff/diff.dart';
|
||||
import 'package:clide/builtin/editor/editor.dart';
|
||||
@@ -371,6 +372,7 @@ Future<void> main() async {
|
||||
..register(GitExtension())
|
||||
..register(PqlExtension())
|
||||
..register(ProblemsExtension())
|
||||
..register(DeepLinkExtension())
|
||||
// Workspace
|
||||
..register(ClaudeExtension())
|
||||
..register(TerminalExtension())
|
||||
|
||||
Reference in New Issue
Block a user