Files
fusion/plugins/fusion-plugin-quality
gsxdsm 06d03d4e1f FN-8103: enforce PostgreSQL-only production data access
Require production paths to use PostgreSQL-aware stores and prevent new unrestricted database access.

- Add a checked allowlist that bans production getDatabase() calls by default.
- Route Quality plugin persistence through an async PostgreSQL-aware store and add Drizzle ORM.
- Document backend-safe plugin storage patterns and cover guarded access behavior.

Files changed:
 docs/PLUGIN_AUTHORING.md                           |  20 +++
 package.json                                       |   6 +-
 .../src/__tests__/agent-logs-backend-mode.test.ts  |   7 +
 packages/core/src/store.ts                         |   7 +-
 packages/core/src/task-store/remaining-ops-5.ts    |   8 +-
 plugins/fusion-plugin-quality/package.json         |   1 +
 .../src/__tests__/async-quality-store.pg.test.ts   |  36 +++++
 .../src/__tests__/cancel-and-plans.test.ts         |   8 +-
 .../src/__tests__/experimental-gate.test.ts        |   1 +
 .../src/routes/create-routes.ts                    |  50 +++----
 .../src/runner/command-runner.ts                   |  17 ++-
 .../src/store/async-quality-store.ts               |  34 +++++
 pnpm-lock.yaml                                     |   3 +
 scripts/__tests__/check-no-getdatabase.test.mjs    |  90 ++++++++++++
 scripts/check-no-getdatabase.mjs                   | 159 +++++++++++++++++++++
 scripts/lib/getdatabase-allowlist.json             |  18 +++
 16 files changed, 422 insertions(+), 43 deletions(-)

Fusion-Task-Id: FN-8103
Fusion-Task-Lineage: ff17bcb2-5341-4c6c-a5c4-993580539676
Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
2026-07-16 10:13:49 -07:00
..

fusion-plugin-quality

First-party Fusion plugin that makes task QA easy and visual.

Surfaces

  • Quality hub (left sidebar): project-wide test run history and plans
  • Task QA tab: action-first task quality work
    • Task-scoped preview / test server (worktree cwd)
    • Allowlisted targeted tests + report viewer
    • Screenshots / visual evidence (task artifacts)
    • Suggested test cases (advisory checklist)
    • PR checks, browser verification handoff

Design principles

  • Orchestrates existing verification (testCommand, gate, verify-fast) — does not replace the merge gate
  • Composes Dev Server process patterns and the artifact registry
  • Composes fusion-plugin-agent-browser for browser verification (soft dependency)
  • Never uses port 4040; never free-form shell as the default path
  • Advisory results only — does not change merge eligibility

Settings

See plugin settingsSchema in src/settings.ts.