概览
dsh-plugin-workbench
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
- **Long files are windowed.** The preview lays out the first 2 000 lines and says so; markdown over that length falls back to the source view, because the markdown renderer has no windowing of its own. - **The editor is a textarea.** No syntax highlighting while editing, no autosave, no conflict detection: a save overwrites whatever is on disk. - **mkdir/rename/delete bypass the fs seam.** `ctx.fs` has no equivalent (it exposes read, write, and edit only), so those three go through `node:fs` and this plugin's own guard is the only gate — unlike `write`, which additionally passes the harness's per-call write policy. - **A session keeps the sandbox mode it was spawned under.** Lowering the mode later does not retroactively confine a running shell — close it and open a new one. - **No remote runtimes.** Spawning goes straight to node-pty instead of `ctx.subprocess.spawnTerminal`, because that seam's handle exposes no `resize()` (rows/cols are fixed at spawn). Terminals therefore only work where the host process runs. - **Reconnecting does not restore the old shells.** They are gone with the socket; you get a fresh one, and scrollback from before the drop is lost. - **Refreshing is polling, not watching.** The listing and any open preview re-check every five seconds while visible, and immediately when the tab regains focus; there is no filesystem watch, so a change can take up to five seconds to show. Searching pauses the listing poll. - **HTML previews are sandboxed and, by default, inert.** Scripts are blocked unless you opt in per file, and even then run walled off in an opaque origin. Because the frame has no base URL and no same-origin access, a page's relative or external resources — its own linked CSS/JS/images — may not load: it is a structure-and-inline-styles preview, not a live site. Use **View source** for the markup. - **Link interception is a content heuristic.** File-link buttons are recognized by their title/text being path-shaped (there is no stable hook on them), so a dsh change to how links render could make some links fall back to the host opener until the heuristic is updated. - **No Range requests.** `bytes` sends whole files, so large media cannot be seeked; it is meant for images and small downloads. - **Only UTF-8 text is displayable.** Other encodings are detected and refused rather than transcoded; there is no encoding picker.
