workspace: confirm the IDE extension calls the new serve routes from its host process, not a webview
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 35/100
- issue の種類
- バグ
- 明瞭さ
- 説明が足りない
- 活発さ
- 活発
- 技術スタック
- typescript
調査の方向性
Start with the route guard and route definitions in packages/opencode/src/server/server.ts, then inspect where the IDE extension's Refresh, Sync, and Publish actions issue their requests. Confirm whether calls originate in the extension host or a webview; done means host-origin requests succeed without 403, or webview calls are routed through the host without weakening the refusal.
索引モデルが issue の本文から書いたものです。
説明
Found during the v0.12.4 release review. Needs confirmation against the IDE extension; not verifiable from this repo.
v0.12.4 adds serve routes for the extension: POST /altimate/workspace/refresh, POST /altimate/workspace/sync, GET /altimate/skill/publishable and POST /altimate/skill/publish. All four go through workspaceRouteRefusal (packages/opencode/src/server/server.ts), which refuses any request a browser labels cross-site (Sec-Fetch-Site), any request with an Origin when OPENCODE_SERVER_PASSWORD is unset, and any other origin when it is set. Native clients (the extension host process, curl) send neither header and are allowed.
If the extension calls these routes from a webview fetch (a Chromium context that sends Origin / Sec-Fetch-Site) rather than from the extension host, every call is refused with 403 and the panel's Refresh / Sync / Publish actions do not work.
To do: confirm where the extension issues these requests. If from a webview, route them through the extension host (preferred — keeps the browser-origin refusal intact), rather than loosening the gate.
- 主要言語
- TypeScript
- スター
- 805
- フォーク
- 122
- 平均マージ
- 2日 10時間
- マージ済み PR(30日)
- 63
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
AltimateAI/altimate-code のほかの issue
-
test: MCP tests fail when the developer's ~/.claude.json has MCP servers (HOME is not sandboxed)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
AltimateAI/altimate-code#1386 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
AltimateAI/altimate-code#1384 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
AltimateAI/altimate-code#1323 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
AltimateAI/altimate-code#1288 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
AltimateAI/altimate-code#1285 ·
メンテナーはふだん 1 日以内に返信
AltimateAI/altimate-code の issue をすべて見る
似ている issue
-
awaiting-response bug needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
wildcard/caro#1562 · コメント 1 件 ·
メンテナーはふだん 3 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
supadata-ai/mcp#27 ·
-
content
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cosimochellini/one-piece-zero-spoiler#516 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
capricorn86/happy-dom#2485 ·
メンテナーはふだん 2 日以内に返信
-
lane: fast
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
unicef/adt-studio#946 ·
メンテナーはふだん 2 日以内に返信