Documentation
¶
Overview ¶
Package copilotvscodeinstall owns binding-scoped Local consent and effect authority. This checkpoint supplies no installer, receipt producer or CLI.
Index ¶
- Constants
- Variables
- func NewDesktop(g Gate, b copilotvscodeevent.Binding, spool string, ...) notification.DeliveryPort
- func NewWebhookSender(g Gate, b copilotvscodeevent.Binding, send copilotvscodeevent.WebhookSender) copilotvscodeevent.WebhookSender
- func PolicyPatch(b portable.Binding, choices Choices, previous *Consent) (map[string]json.RawMessage, error)
- func PrepareNativeSpool(ctx context.Context, root string) (string, error)
- func RevokeChannels(ctx context.Context, b portable.Binding, selection RevokeSelection) (installruntime.Ledger, error)
- type Choices
- type Consent
- type Gate
- type PhysicalProof
- type ProofPort
- type RevokeSelection
Constants ¶
const CopilotVSCodeToastAppID = opencodeinstall.CopilotVSCodeToastAppID
Variables ¶
var ErrDenied = errors.New("copilot_vscode_authority_unavailable")
Functions ¶
func NewDesktop ¶
func NewDesktop(g Gate, b copilotvscodeevent.Binding, spool string, backend notification.DeliveryPort) notification.DeliveryPort
NewDesktop accepts only the native informational route. The other-platform backend must be the unleased Linux/Windows effect port selected by the trusted composer; Mac builds its own single-lease StructuredDelivery.
func NewWebhookSender ¶
func NewWebhookSender(g Gate, b copilotvscodeevent.Binding, send copilotvscodeevent.WebhookSender) copilotvscodeevent.WebhookSender
NewWebhookSender uses the same one-lease checks as desktop. N1 supplies fixed private content/config and already retains the observation claim on errors. Even a successful POST becomes uncertain if completion authority drifted.
func PolicyPatch ¶
func PolicyPatch(b portable.Binding, choices Choices, previous *Consent) (map[string]json.RawMessage, error)
PolicyPatch computes desired intent only. It cannot produce physical proof or authorize a backend. The caller must still use generation AND policy-byte CAS. Kernel leaf merging preserves unknown nested and sibling members.
func PrepareNativeSpool ¶
PrepareNativeSpool reuses the existing product spool ownership/deadline rules. Only a later explicit setup caller may prepare it; Gate never creates assets.
func RevokeChannels ¶
func RevokeChannels(ctx context.Context, b portable.Binding, selection RevokeSelection) (installruntime.Ledger, error)
RevokeChannels uses consent ownership, not delivery availability. No physical profile/helper/package lookup precedes the false commit. It retains the one consumer and all Files/Native records; cleanup/removal belongs to N2b.
Types ¶
type Choices ¶
type Choices struct{ Desktop, Webhook, Manual *bool }
Choices changes exactly the three owned leaves. Nil preserves only consent from the same recorded binding; a fresh registration starts with all false.
type Consent ¶
type Consent struct {
// contains filtered or unexported fields
}
Consent is an immutable observation of explicit user intent, not an effect grant. Only ReadConsent can retain affirmative omitted choices.
func ReadConsent ¶
func ReadConsent(s installruntime.PolicySnapshot, b portable.Binding) (Consent, error)
ReadConsent refuses malformed containers and any mismatched registration. Missing/null/nonboolean leaves deny independently. Shared enabled is neither borrowed for native channels nor changed by a Local selection.
type Gate ¶
Gate implements the ACTUAL N1 consumer interface. It binds one immutable portable registration; every request supplies the observed generation.
func (Gate) Channels ¶
func (g Gate) Channels(ctx context.Context, b copilotvscodeevent.Binding) copilotvscodeevent.Channels
func (Gate) ConsumerBinding ¶
ConsumerBinding returns only a qualified N1 value; it is not an authorizedGrant.
func (Gate) Recheck ¶
func (g Gate) Recheck(ctx context.Context, b copilotvscodeevent.Binding, channel copilotvscodeevent.Channel) bool
type PhysicalProof ¶
type PhysicalProof struct {
// contains filtered or unexported fields
}
PhysicalProof is an immutable normalized observation. All fields are private; N2a supplies NO affirmative constructor. The later receipt adapter in this package must derive them from actual public NewLocal/Engine/observed receipts, never configuration, a bool, or fabricated SDK facts. Zero values deny.
type ProofPort ¶
type ProofPort interface {
CheckLocal(context.Context, portable.Binding, installruntime.InstalledSnapshot) (PhysicalProof, error)
}
ProofPort reloads actual physical profile/receipt/package/projection authority. It is not a lease and never executes a native app. Missing/unqualified proof denies. No production implementation is wired at this checkpoint.
type RevokeSelection ¶
type RevokeSelection uint8
const ( RevokeAll RevokeSelection = iota + 1 RevokeNative RevokeManual )