Skip to content

Add standalone Canvas Designer provider to Wizard plugin - #38

Merged
nicolehaugen merged 5 commits into
mainfrom
nicolehaugen-canvas-designer-provider-layer
Sep 30, 2026
Merged

nicolehaugen merged 5 commits into
mainfrom
nicolehaugen-canvas-designer-provider-layer

Conversation

@nicolehaugen

Copy link
Copy Markdown
Contributor

Summary

  • Add the standalone speckit-canvas-designer extension within the installed Wizard plugin. Its canvas opens only with a validated handoff ID from the child session's session.workspacePath, and serves a token-gated shell.
  • Cover handoff validation, session artifact boundaries, and shell rendering/HTTP access with targeted tests.
  • Bump only the Wizard plugin to 0.3.0 in its manifest, marketplace entry, and README.

This middle layer deliberately excludes bootstrap.mjs, checkout extension copying, and all Wizard launch UI/handler changes. Extension discovery is provided by the installed Wizard plugin's extensions/ declaration. Native stack metadata is unchanged.

Validation

  • node --test plugins/spec-kit-copilot-wizard/extensions/speckit-canvas-designer/test/provider.test.mjs (4 passing)
  • git diff --cached --check

Copilot AI balanced review requested due to automatic review settings September 30, 2026 01:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The handoff file check has a symlink race that can bypass the intended session-artifact boundary.

Review effort: Balanced
Findings: 1 High severity · 3 Low severity

Open (4)
What changed in this PR

Adds a standalone Canvas Designer shell to the Wizard plugin with validated handoff loading and token-gated loopback access.

Changes:

  • Adds handoff validation and Designer lifecycle/server logic.
  • Adds targeted provider and security tests.
  • Bumps Wizard plugin metadata to 0.3.0.
File Description
README.md Documents the Designer canvas and version.
plugins/​spec-kit-copilot-wizard/​plugin.json Bumps the plugin version.
.github/​plugin/​marketplace.json Bumps the marketplace entry version.
.../​extension.mjs Registers and manages Designer instances.
.../​handoff.mjs Validates and reads session handoffs.
.../​server.mjs Serves the token-gated shell.
.../​test/​provider.test.mjs Tests validation, boundaries, and HTTP access.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread plugins/spec-kit-copilot-wizard/extensions/speckit-canvas-designer/handoff.mjs Outdated
Comment thread .github/plugin/marketplace.json
Comment thread README.md Outdated
Comment thread plugins/spec-kit-copilot-wizard/plugin.json
@nicolehaugen
nicolehaugen added this pull request to stack #39 September 30, 2026 01:45
Copilot AI balanced review requested due to automatic review settings September 30, 2026 01:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Opening a FIFO handoff can block indefinitely before file-type validation.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (4)

Comment thread plugins/spec-kit-copilot-wizard/extensions/speckit-canvas-designer/handoff.mjs Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 02:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A malformed HTTP request can terminate the Designer extension through an uncaught URL parsing exception.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Copilot AI balanced review requested due to automatic review settings September 30, 2026 02:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The scoped provider implementation is consistent, securely bounded, well tested, and its release metadata is synchronized.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Base automatically changed from nicolehaugen-wizard-canvas-generation-dialog to main September 30, 2026 14:48
nicolehaugen and others added 5 commits September 30, 2026 09:48
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@nicolehaugen
nicolehaugen force-pushed the nicolehaugen-canvas-designer-provider-layer branch from a81fb96 to 7e080df Compare September 30, 2026 14:48
@nicolehaugen
nicolehaugen merged commit a13234f into main Sep 30, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants