LuaLS / LuaLS/vscode-lua

Addon manager plugin support

オープン
#112 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

addon manager enhancement
主要言語
TypeScript
スター
215
フォーク
62
PR マージ指標
30日以内にマージされた PR はありません

説明

Explain the feature

The Lua Language Server supports plugins that allow users to write custom Lua scripts that the language server will then run to output a modified file. As of right now, the addon manager will download the plugin.lua file, but it will not tell the server to use it. There should be some easy (and safe) way for users to enable a plugin that they have installed.

Are there any potential drawbacks from adding the feature?

There are some serious security concerns with downloading a script off the internet and running it automatically on the user's computer. While the addons being installed should be reviewed and trusted before being merged into LLS-addons, there is always the chance of something slipping through.

We could ask the user to review the code themselves before approving the request to enable it - but at the end of the day, the safest option will always be to not run code created by other users.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、addon manager がダウンロードした plugin.lua ファイルをどのように処理するかを追跡し、runtime.plugin 設定に関する LuaLS のドキュメントを確認します。インストール済みのプラグインを有効にするための承認要件と安全性要件を明確にし、そのうえで、レビューされていないコードを自動的に実行せずに完了を検証する方法を定義します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
lua, typescript, vscode
領域
security, tooling
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。