Repository navigation
feat(dashboard): scoped path-token auth for plugin views and complete the views rename - #10415
Merged
Soulter merged 6 commits intoOct 6, 2026
Merged
Conversation
Finish the remaining Pages -> Views rename on the dashboard: - Fix the plugin card "Open View" button crash by pointing openPluginWebui at the renamed PluginView route - Rename PluginPagePage.vue to PluginViewPage.vue and update its internals (loadPluginView, pluginViewTitle, .plugin-view-* classes) - Rename openPluginWebui -> openPluginView and the open-webui emit to open-view; pluginPageTitle/Description -> pluginViewTitle/Description; isPluginPageRoute -> isPluginViewRoute - Rename i18n keys (pluginWebui -> pluginView, openWebui -> openView, pluginPageType -> pluginViewType, messages) across en/zh/ja/ru locales The postMessage bridge channel name (astrbot-plugin-page) is kept unchanged because it is part of the wire protocol shared with plugin_page_bridge.js.
Serve plugin view assets from
/api/v1/plugins/{id}/views/{page}/_t/{token}/... so the scoped token
travels in the URL path. Relative URLs inside the view then inherit the
token through normal path resolution, which removes the need for
server-side HTML/CSS/JS URL rewriting on this route.
- Add the _t routes with a require_plugin_view_token dependency
(v1 paths bypass the dashboard auth middleware)
- Extend the plugin page asset token to a session-length TTL (7 days,
aligned with the dashboard session) with a page_session purpose claim,
still scoped to a single plugin and page
- Serialize the view entry content_path as the _t URL, keeping the
asset_token query for plugins that parse location.search
- Keep the legacy /api/plugin/page/content/...?asset_token= form working
during the transition
- Rename the OpenAPI tag Plugin Pages -> Plugin Views, document the new
route, regenerate the frontend API client, and update the zh/en
plugin-pages docs
Contributor
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. This changes how unauthenticated requests obtain plugin-view access and extends scoped JWT validity from 60 seconds to seven days, so a leaked path token can expose the corresponding view assets for much longer. Because the TTL and trust boundary are policy decisions, an overly permissive choice affects every issued token immediately, and reverting will not invalidate tokens already issued.
…URL rewriting
The path-token view route makes the compatibility surface unnecessary:
- Drop /api/plugin/page/content/... (query asset_token form)
- Drop the redundant authenticated asset routes /plugins/page/assets,
/plugins/view/assets, and /plugins/{id}/(pages|views)/{page}/assets/...
which had no callers outside the generated client
- Remove the HTML/CSS/JS URL rewriting helpers; view assets are always
served raw and only HTML gets bridge SDK injection plus theme handling
- Slim PluginPageAuth down to the bridge SDK endpoint, the only
non-v1 path still authenticating scoped query tokens
- serialize_plugin_page no longer falls back to the legacy content path
- Update the plugin-pages docs (zh/en) and the OpenAPI spec, and
regenerate the frontend API client
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
astrbot-docs | 475fe63 | Commit Preview URL Branch Preview URL |
Oct 06 2026, 09:14 AM |
Remove the page-named plugin view API aliases now that the views rename
is complete and legacy compatibility is intentionally dropped:
- DELETE /api/v1/plugins/page(s) and /plugins/{plugin_id}/pages{,/{page_name}}
aliases; /plugins/view(s) and /plugins/{plugin_id}/views{,/{page_name}}
are the only entry config routes
- Remove the unused /api/v1/plugins/page-bridge-sdk.js route; the live
bridge SDK stays at /api/plugin/page/bridge-sdk.js
- Dashboard calls the view-named endpoints; regenerate the API client
and the OpenAPI scopes docs
Restore the page-named plugin view routes removed in the previous commit
and keep them for a transition period, with view as the canonical API:
- /plugins/page(s) and /plugins/{plugin_id}/pages{,/{page_name}} serve as
aliases of the corresponding /views routes (same handlers)
- The OpenAPI spec marks the page operations deprecated and points new
clients at the view routes; the v1 page-bridge-sdk.js route is restored
- The dashboard keeps calling the view endpoints by default
The view entry and path-token asset routes now use {view_name} instead of
{page_name} in the OpenAPI-visible path, and the service layer renames its
internal page_name variables to match. Wire-compatible surfaces stay
unchanged: the page_name JWT claim, the pageName JSON field, query
parameters, and the deprecated /pages aliases. Error messages and the
plugin view docs (zh/en) complete the Page to View rename.
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two related changes around plugin views:
1. Complete the Pages -> Views rename
The rename was left half-done: the plugin card "Open View" button crashed with
No match for {"name":"PluginPage"}. This finishes it:PluginViewroutePluginPagePage.vue->PluginViewPage.vue(plus internal identifiers and CSS classes)openPluginWebui->openPluginView,open-webuiemit ->open-view,pluginPageTitle/Description->pluginViewTitle/Description,isPluginPageRoute->isPluginViewRoutepluginWebui->pluginView,openWebui->openView,pluginPageType->pluginViewType, related messages)Plugin Pages->Plugin ViewsThe postMessage bridge channel name (
astrbot-plugin-page) is intentionally kept: it is part of the wire protocol shared withplugin_page_bridge.js.2. Path-token authentication for view assets
Plugin view assets are now served from:
The scoped token travels in the URL path, so relative URLs inside the view inherit it through normal path resolution. View assets are served raw — the server-side HTML/CSS/JS URL rewriting is removed entirely (only bridge SDK injection and theme handling remain for HTML).
page_sessionpurpose claim; scoped to a single plugin and pagecontent_pathis serialized as the_tURL (with theasset_tokenquery echoed for view scripts that read it fromlocation.search)3. Legacy surface removed
/api/plugin/page/content/...?asset_token=...route removed/plugins/page/assets,/plugins/view/assets,/plugins/{id}/(pages|views)/{page}/assets/...) removed — no callers outside the generated clientPluginPageAuthslimmed to the bridge SDK endpoint, the only non-v1 path still authenticating scoped query tokensOld-to-new mapping
PluginPagePluginView/api/plugin/page/content/<plugin>/<page>/...?asset_token=<token>/api/v1/plugins/<plugin>/views/<page>/_t/<token>/...,/api/v1/plugins//(pagespluginWebui/openWebui/pluginPageTypepluginView/openView/pluginViewTypeImpact on plugin authors
None: relative asset paths and the
plugin_page_bridgeJS APIs are unchanged. Only the dashboard-internal URLs and auth mechanism changed.Testing
pytest tests/test_dashboard.py: 88 passed (path-token route: anonymous fetch OK, assets served raw, wrong-plugin token 401, missing token rejected, traversal blocked, legacy route 404)ruff format --check/ruff check: cleanpnpm build: passesSummary by Sourcery
Complete the plugin Pages-to-Views rename and replace rewritten query-token asset URLs with scoped path-token authentication for raw plugin view assets.
New Features:
Bug Fixes:
Enhancements:
Documentation:
Tests: