https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=35837

--- Comment #32 from Martin Renvoize (ashimema) 
<[email protected]> ---
Created attachment 206520
  -->
https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206520&action=edit
Bug 35837: Add a verified, restriction-aware install path for plugin-store
plugins

Adds Koha::Plugins::Install and Koha::Plugins::Store, the backend
foundation for installing plugins discovered via a community
plugin-store service. Given a downloaded .kpz file, install() runs a
fixed set of checks before ever touching the plugins directory:

 * the file has a .kpz extension and the plugins directory is
   writable
 * its origin repository, if known, is on the configured allowlist
   (plugin_repos), when plugins_restricted is enabled
 * its Ed25519 signature, if the plugin store provided one, verifies
   against the configured verification key and matches this exact
   file's SHA-256 digest
 * an unsigned plugin is only installed once explicitly confirmed
   (plugins_allow_unsigned), and blocked outright if that's disabled
 * its certification tier, if the store knows one, meets the
   PluginStoreMinimumLevel system preference

Nothing is extracted or installed unless every check passes.

The Ed25519 verification key is resolved from koha-conf.xml's
plugin_store_public_key_file, when a sysadmin has set one (e.g. for a
self-hosted mirror or a scripted multi-instance deploy), falling back
to the new PluginStorePublicKey system preference otherwise. With
neither configured, a signed plugin is treated the same as an
unsigned one rather than reported as a signature mismatch, since
there's no key to check it against.

Koha::Plugins::Store is a thin client for the plugin store's public
discovery API, resolving a kpz_url or a file digest to its known
repo_url, certification tier, and signed manifest/signature.

Also adds the PluginStoreMinimumLevel and PluginStorePublicKey system
preferences (installer/data/mysql/atomicupdate/), the CryptX
dependency (for Crypt::PK::Ed25519), and sample koha-conf.xml entries
documenting plugin_store_url, plugins_allow_unsigned and
plugin_store_public_key_file.

Test plan:
1. prove t/Koha/Plugins/Install.t t/Koha/Plugins/Store.t
2. Set the PluginStorePublicKey system preference to a store's real
   public key and confirm a correctly-signed plugin verifies.
3. Set koha-conf.xml's plugin_store_public_key_file and confirm it
   takes precedence over the system preference.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to