Skip to content

Files Changed: adopt app and extension user mutation routes #1080

Description

@jeonghun-jj-lee

Files Changed: adopt app and extension user mutation routes

Important

Problem - Sidebar, Preview, and Files Changed editing can currently mutate through client or extension paths that have weaker session identity and fallback guarantees than the proposed ledger contract.
Approach - Make user-initiated file operations host-mediated mutation intents. Use the negotiated capability to create registered operation groups; preserve clearly labelled legacy behavior only when protocol discovery selects legacy.
Scope - in: Sidebar leaf, move, Trash, restore, directory, and recursive operations; Preview and review editing; panel ownership; opaque host transport; and watcher revalidation. out: engine tool adoption and plugin/runner records.
Assumptions - The mutation gate and privacy policy are available. Existing #976 remains the v1 foundation pending its release and pin gate.

Acceptance Criteria

  • User-initiated file operations bind to the initiating panel and active session before storage work begins.
  • Sidebar create, move, Trash, restore, directory, and recursive operations use registered contexts or deny before mutation in full-provenance mode.
  • Preview and Files Changed editing cannot bypass host-mediated context validation.
  • A capability-discovery legacy result preserves existing behavior with a visible legacy label; an invalid mutation context never falls back to untracked mutation.
  • Watchers only revalidate server-owned receipts and cannot determine ownership or lifecycle locally.
  • User-originated receipts remain distinguishable from agent, child-agent, and system receipts.

Testing Decisions

  • Extend extension-host, panel ownership, Sidebar, Preview, review-editing, watcher, and legacy-fallback tests.
  • Add paired app-extension integration coverage for invalid context denial and exact idempotent retry.

Key Decisions

  • Browser code never receives a mutation capability or determines externality.
  • User actions are first-class session origins, not anonymous filesystem events.

Constraints & Invariants

Prior Art

Deliberation Resolution

Source

Part of #972. Blocked by #976, #1077, and #1078.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

afkImplementable without human interaction

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions