Documentation
¶
Overview ¶
Package copilotvscodeinstall owns binding-scoped Local consent and effect authority. This checkpoint supplies no installer, receipt producer or CLI.
Index ¶
- Constants
- Variables
- func CursorPolicyPatch(b portable.Binding, choices CursorChoices, previous *Consent) (map[string]json.RawMessage, error)
- func NewCursorDesktop(g CursorGate, b cursorevent.Binding, backend notification.DeliveryPort) notification.DeliveryPort
- func NewCursorWebhookSender(g CursorGate, b cursorevent.Binding, send cursorevent.WebhookSender) cursorevent.WebhookSender
- func NewDesktop(g Gate, b copilotvscodeevent.Binding, spool string, ...) notification.DeliveryPort
- func NewWebhookSender(g Gate, b copilotvscodeevent.Binding, send copilotvscodeevent.WebhookSender) copilotvscodeevent.WebhookSender
- func PolicyPatch(b portable.Binding, choices Choices, previous *Consent) (map[string]json.RawMessage, error)
- func PrepareNativeSpool(ctx context.Context, root string) (string, error)
- func RevokeChannels(ctx context.Context, b portable.Binding, selection RevokeSelection) (installruntime.Ledger, error)
- type Choices
- type Consent
- type CursorChoices
- type CursorGate
- func (g CursorGate) Channels(ctx context.Context, b cursorevent.Binding) cursorevent.Channels
- func (g CursorGate) ConsumerBinding(ctx context.Context) (cursorevent.Binding, error)
- func (g CursorGate) EffectiveConfig(ctx context.Context) (*config.Config, error)
- func (g CursorGate) Recheck(ctx context.Context, b cursorevent.Binding, channel cursorevent.Channel) bool
- type Gate
- type PhysicalProof
- type ProofPort
- type RevokeSelection
Constants ¶
const CopilotVSCodeToastAppID = opencodeinstall.CopilotVSCodeToastAppID
Variables ¶
var ErrDenied = errors.New("copilot_vscode_authority_unavailable")
Functions ¶
func CursorPolicyPatch ¶ added in v1.48.0
func CursorPolicyPatch(b portable.Binding, choices CursorChoices, previous *Consent) (map[string]json.RawMessage, error)
CursorPolicyPatch computes just desired consent. Existing caller generation and policy CAS, followed by the existing leaf merger, own mutation.
func NewCursorDesktop ¶ added in v1.48.0
func NewCursorDesktop(g CursorGate, b cursorevent.Binding, backend notification.DeliveryPort) notification.DeliveryPort
NewCursorDesktop enters the existing single-lease Linux desktop owner.
func NewCursorWebhookSender ¶ added in v1.48.0
func NewCursorWebhookSender(g CursorGate, b cursorevent.Binding, send cursorevent.WebhookSender) cursorevent.WebhookSender
NewCursorWebhookSender converts only the consumer's typed handoff. The existing sender owns its one lease and no-redirect completion semantics.
func NewDesktop ¶
func NewDesktop(g Gate, b copilotvscodeevent.Binding, spool string, backend notification.DeliveryPort) notification.DeliveryPort
NewDesktop accepts only the native informational route. The other-platform backend must be the unleased Linux/Windows effect port selected by the trusted composer; Mac builds its own single-lease StructuredDelivery.
func NewWebhookSender ¶
func NewWebhookSender(g Gate, b copilotvscodeevent.Binding, send copilotvscodeevent.WebhookSender) copilotvscodeevent.WebhookSender
NewWebhookSender uses the same one-lease checks as desktop. N1 supplies fixed private content/config and already retains the observation claim on errors. Even a successful POST becomes uncertain if completion authority drifted.
func PolicyPatch ¶
func PolicyPatch(b portable.Binding, choices Choices, previous *Consent) (map[string]json.RawMessage, error)
PolicyPatch computes desired intent only. It cannot produce physical proof or authorize a backend. The caller must still use generation AND policy-byte CAS. Kernel leaf merging preserves unknown nested and sibling members.
func PrepareNativeSpool ¶
PrepareNativeSpool reuses the existing product spool ownership/deadline rules. Only a later explicit setup caller may prepare it; Gate never creates assets.
func RevokeChannels ¶
func RevokeChannels(ctx context.Context, b portable.Binding, selection RevokeSelection) (installruntime.Ledger, error)
RevokeChannels uses consent ownership, not delivery availability. No physical profile/helper/package lookup precedes the false commit. It retains the one consumer and all Files/Native records; cleanup/removal belongs to N2b.
Types ¶
type Choices ¶
type Choices struct{ Desktop, Webhook, Manual *bool }
Choices changes exactly the three owned leaves. Nil preserves only consent from the same recorded binding; a fresh registration starts with all false.
type Consent ¶
type Consent struct {
// contains filtered or unexported fields
}
Consent is an immutable observation of explicit user intent, not an effect grant. Only ReadConsent can retain affirmative omitted choices.
func ReadConsent ¶
func ReadConsent(s installruntime.PolicySnapshot, b portable.Binding) (Consent, error)
ReadConsent refuses malformed containers and any mismatched registration. Missing/null/nonboolean leaves deny independently. Shared enabled is neither borrowed for native channels nor changed by a Local selection.
func ReadCursorConsent ¶ added in v1.48.0
func ReadCursorConsent(s installruntime.PolicySnapshot, b portable.Binding) (Consent, error)
ReadCursorConsent observes this exact registration's explicit native intent. Unknown, missing, null and nonboolean leaves cannot enable a channel.
type CursorChoices ¶ added in v1.48.0
type CursorChoices struct{ Desktop, Webhook *bool }
CursorChoices owns only the two native Stop channel leaves.
type CursorGate ¶ added in v1.48.0
type CursorGate struct {
// contains filtered or unexported fields
}
CursorGate is a closed typed consumer of the existing policy/effect owner. Its composition inputs grant no channel; each observation checks installed receipts and revalidates the original recorded physical token.
func NewCursorGate ¶ added in v1.48.0
func NewCursorGate(b portable.Binding, cfg uapinstaller.Config, fixed cursorinstall.Authority) (CursorGate, error)
NewCursorGate requires trusted, already qualified fixed vendor authority and an explicit installed layout. It neither captures authority nor prepares any live assets. Caller registry/callbacks are not retained by this observer.
func (CursorGate) Channels ¶ added in v1.48.0
func (g CursorGate) Channels(ctx context.Context, b cursorevent.Binding) cursorevent.Channels
func (CursorGate) ConsumerBinding ¶ added in v1.48.0
func (g CursorGate) ConsumerBinding(ctx context.Context) (cursorevent.Binding, error)
ConsumerBinding copies all current identity and generation fields.
func (CursorGate) EffectiveConfig ¶ added in v1.48.0
EffectiveConfig returns a fresh independent config for the same qualified registration and generation. Every effect check separately reloads opt-out.
func (CursorGate) Recheck ¶ added in v1.48.0
func (g CursorGate) Recheck(ctx context.Context, b cursorevent.Binding, channel cursorevent.Channel) bool
type Gate ¶
Gate implements the ACTUAL N1 consumer interface. It binds one immutable portable registration; every request supplies the observed generation.
func (Gate) Channels ¶
func (g Gate) Channels(ctx context.Context, b copilotvscodeevent.Binding) copilotvscodeevent.Channels
func (Gate) ConsumerBinding ¶
ConsumerBinding returns only a qualified N1 value; it is not an authorizedGrant.
func (Gate) Recheck ¶
func (g Gate) Recheck(ctx context.Context, b copilotvscodeevent.Binding, channel copilotvscodeevent.Channel) bool
type PhysicalProof ¶
type PhysicalProof struct {
// contains filtered or unexported fields
}
PhysicalProof is an immutable normalized observation. All fields are private. Only the private Cursor producer derives affirmative Cursor facts from the public installed observations. Local still has no producer. Zero values deny.
type ProofPort ¶
type ProofPort interface {
CheckLocal(context.Context, portable.Binding, installruntime.InstalledSnapshot) (PhysicalProof, error)
}
ProofPort reloads actual physical profile/receipt/package/projection authority. It is not a lease and never executes a native app. Missing/unqualified proof denies. The private Cursor producer retains this existing interface.
type RevokeSelection ¶
type RevokeSelection uint8
const ( RevokeAll RevokeSelection = iota + 1 RevokeNative RevokeManual )