Run plugins in a QuickJS sandbox in the browser

Adds packages/plugin-sandbox: QuickJS-ng compiled to wasm, running in a
dedicated worker, with a runtime shell inside it that loads a plugin bundle
and answers the same InternalEventPayload events the Node runtime answers.
Plugins are unmodified.

Wires the browser host's template function, authentication, cURL import and
template render commands to it, and relaxes TemplateCallback's Send bound on
wasm32 so the engine's renderer can call back out to a plugin.
This commit is contained in:
Gregory Schier
2026-08-18 15:22:49 -07:00
parent 115615d994
commit f8d6dfbdaa
37 changed files with 3251 additions and 138 deletions
+18 -3
View File
@@ -31,10 +31,25 @@ export function boot(): Promise<void>;
* settings, the cookie jar. Nothing here touches a socket. What comes back is what the tab
* posts to the Yaak server.
*
* Refuses, with a message the user can act on, when the request needs something this host
* doesn't have: an authentication plugin, or a template function.
* `plugins` is the template function bridge — a JavaScript function taking a name and its
* JSON arguments and resolving to the rendered string. Passing nothing is allowed and makes
* every template function a refusal naming it.
*
* Authentication is *not* applied here even though it is part of preparing a send. It is
* applied to the rendered request by the caller, because the plugin that applies it wants to
* see the request as it will be sent, and the caller is the side that knows that.
*/
export function prepare_http_send(payload: any): Promise<any>;
export function prepare_http_send(payload: any, plugins: any): Promise<any>;
/**
* Render one template string against an environment chain.
*
* What `cmd_render_template` does on the desktop, for the same callers: the value previews
* under an editor, and anywhere the app shows what a template will become. `ignore_error`
* picks the same behaviour it picks there — a preview shows an empty string where a send
* would refuse, because a half-typed template is not yet a mistake.
*/
export function render_template(payload: any, plugins: any): Promise<any>;
/**
* Run one command as `label` (the calling tab's identity, which stands in for