Add plugin platform with modular backend and frontend registry.

Split graph/import/meta into Django apps, add API v1 with OpenAPI and pytest, and introduce plugin registry with the tags reference plugin on both FE and BE.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-06-25 09:35:51 +03:00
co-authored by Cursor
parent b694a596b8
commit cafc7335ad
77 changed files with 1801 additions and 490 deletions
+50
View File
@@ -0,0 +1,50 @@
# External Plugins Policy
## Supported distribution (Phase D)
### Backend (Python)
- Package name: `social-graph-plugin-<id>`
- Entry point group: `social_graph.plugins`
- Manifest fields: `id`, `version`, `min_core_version`, `permissions[]`
Example `pyproject.toml`:
```toml
[project.entry-points."social_graph.plugins"]
tags = "social_graph_plugin_tags.plugin:TagsPlugin"
```
Install: `pip install social-graph-plugin-tags`
Enable: `ENABLED_PLUGINS=tags` in backend environment.
### Frontend (npm)
- Package name: `@social-graph/plugin-<id>`
- Default export: `PluginDefinition` (same shape as `registerPlugin()`)
Build-time inclusion only (trusted packages). Runtime CDN loading is **not supported** for security reasons.
Enable: `VITE_ENABLED_PLUGINS=tags,my-plugin`
## Trust model
| Source | Trust level | Loading |
|--------|-------------|---------|
| Monorepo `frontend/src/plugins/*` | Full | Build-time |
| npm / pip packages from allowlist | Trusted | Build-time / deploy-time |
| Arbitrary URL / user upload | Untrusted | **Blocked** |
## Version compatibility
Plugins declare `minCoreVersion`. Core version is `1.0.0` (`CORE_VERSION` in frontend, `SPECTACULAR_SETTINGS.VERSION` in backend).
Breaking API changes require a new `/api/v2/` namespace.
## Security checklist for external authors
- Request minimal `permissions`
- Do not access `localStorage` outside plugin namespace
- Do not inject scripts into core DOM outside registered extension points
- Use plugin-scoped Dexie tables only via `upgradeDexie`