Improved enterprise plugin rollouts and protected deployed plugins against changes (#938)

This commit is contained in:
Thorsten Sommer authored and GitHub committed 2026-08-28 14:06:24 +02:00
1 parent a4c35fc2f2
commit 3940ad7f29
11 files changed
+232 -54

No files matched your search

@@ -21,6 +21,14 @@ public sealed partial class PluginInstallService
if (plugin.IsInternal)
return CheckError(TB("Internal assistant plugins cannot be edited."));
//
// An assistant an organization rolled out is theirs to change, not the user's. Editing it
// would also change its content hash, which is what an enterprise approval is based on: the
// assistant would lose its approval and suddenly demand a security audit.
//
if (plugin.IsManagedByConfigServer)
return CheckError(TB("Only locally managed assistant plugins can be edited."));
if (string.IsNullOrWhiteSpace(plugin.LocalPath))
return CheckError(TB("The assistant plugin has no local directory."));
@@ -76,6 +84,11 @@ public sealed partial class PluginInstallService
if (plugin.IsInternal)
return UpdateError(plugin, plugin.LocalPath, TB("Internal assistant plugins cannot be edited."));
// See CheckInstalledAssistantUpdateAsync: an organization's assistant must keep the content
// its enterprise approval was granted for.
if (plugin.IsManagedByConfigServer)
return UpdateError(plugin, plugin.LocalPath, TB("Only locally managed assistant plugins can be edited."));
if (string.IsNullOrWhiteSpace(plugin.LocalPath))
return UpdateError(plugin, string.Empty, TB("The assistant plugin has no local directory."));