Require production paths to use PostgreSQL-aware stores and prevent new unrestricted database access. - Add a checked allowlist that bans production getDatabase() calls by default. - Route Quality plugin persistence through an async PostgreSQL-aware store and add Drizzle ORM. - Document backend-safe plugin storage patterns and cover guarded access behavior. Files changed: docs/PLUGIN_AUTHORING.md | 20 +++ package.json | 6 +- .../src/__tests__/agent-logs-backend-mode.test.ts | 7 + packages/core/src/store.ts | 7 +- packages/core/src/task-store/remaining-ops-5.ts | 8 +- plugins/fusion-plugin-quality/package.json | 1 + .../src/__tests__/async-quality-store.pg.test.ts | 36 +++++ .../src/__tests__/cancel-and-plans.test.ts | 8 +- .../src/__tests__/experimental-gate.test.ts | 1 + .../src/routes/create-routes.ts | 50 +++---- .../src/runner/command-runner.ts | 17 ++- .../src/store/async-quality-store.ts | 34 +++++ pnpm-lock.yaml | 3 + scripts/__tests__/check-no-getdatabase.test.mjs | 90 ++++++++++++ scripts/check-no-getdatabase.mjs | 159 +++++++++++++++++++++ scripts/lib/getdatabase-allowlist.json | 18 +++ 16 files changed, 422 insertions(+), 43 deletions(-) Fusion-Task-Id: FN-8103 Fusion-Task-Lineage: ff17bcb2-5341-4c6c-a5c4-993580539676 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
19 lines
632 B
JSON
19 lines
632 B
JSON
{
|
|
"entries": [
|
|
{
|
|
"file": "packages/core/src/store.ts",
|
|
"line": 2604,
|
|
"snippet": "await this.getDatabase().runPluginSchemaInits(",
|
|
"reason": "FN-8104: Backend-guarded SQLite plugin-schema fallback; remove with the coordinated SQLite/U15 retirement.",
|
|
"allowlistedAt": "2026-07-16"
|
|
},
|
|
{
|
|
"file": "packages/engine/src/self-healing.ts",
|
|
"line": 5358,
|
|
"snippet": "const db = this.store.getDatabase();",
|
|
"reason": "FN-8104: Backend-guarded SQLite self-healing fallback; remove with the coordinated SQLite/U15 retirement.",
|
|
"allowlistedAt": "2026-07-16"
|
|
}
|
|
]
|
|
}
|