https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=35837 --- Comment #25 from Martin Renvoize (ashimema) <martin.renvoize@openfifth.co.uk> --- Created attachment 206484 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206484&action=edit Bug 35837: Add a verified, restriction-aware install path for plugin-store plugins Adds Koha::Plugins::Install and Koha::Plugins::Store, the backend foundation for installing plugins discovered via a community plugin-store service. Given a downloaded .kpz file, install() runs a fixed set of checks before ever touching the plugins directory: * the file has a .kpz extension and the plugins directory is writable * its origin repository, if known, is on the configured allowlist (plugin_repos), when plugins_restricted is enabled * its Ed25519 signature, if the plugin store provided one, verifies against the configured verification key and matches this exact file's SHA-256 digest * an unsigned plugin is only installed once explicitly confirmed (plugins_allow_unsigned), and blocked outright if that's disabled * its certification tier, if the store knows one, meets the PluginStoreMinimumLevel system preference Nothing is extracted or installed unless every check passes. The Ed25519 verification key is resolved from koha-conf.xml's plugin_store_public_key_file, when a sysadmin has set one (e.g. for a self-hosted mirror or a scripted multi-instance deploy), falling back to the new PluginStorePublicKey system preference otherwise. With neither configured, a signed plugin is treated the same as an unsigned one rather than reported as a signature mismatch, since there's no key to check it against. Koha::Plugins::Store is a thin client for the plugin store's public discovery API, resolving a kpz_url or a file digest to its known repo_url, certification tier, and signed manifest/signature. Also adds the PluginStoreMinimumLevel and PluginStorePublicKey system preferences (installer/data/mysql/atomicupdate/), the CryptX dependency (for Crypt::PK::Ed25519), and sample koha-conf.xml entries documenting plugin_store_url, plugins_allow_unsigned and plugin_store_public_key_file. Test plan: 1. prove t/Koha/Plugins/Install.t t/Koha/Plugins/Store.t 2. Set the PluginStorePublicKey system preference to a store's real public key and confirm a correctly-signed plugin verifies. 3. Set koha-conf.xml's plugin_store_public_key_file and confirm it takes precedence over the system preference. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> -- You are receiving this mail because: You are watching all bug changes.