扩展原生壳替身扫描范围

将微信小程序生产 JS 纳入原生壳替身词扫描

将 H5 HostBridge 直接调用链纳入生产替身词扫描

为桌面壳最小 capability 文档增加正向门禁

同步方案文档、协议文档、开发流程和决策记录
This commit is contained in:
2026-06-19 01:31:03 +08:00
parent 13ef5a7a06
commit b5e1f68fe9
5 changed files with 28 additions and 4 deletions
+24 -1
View File
@@ -20,6 +20,16 @@ const productionShellScanRoots = [
'packages/shared/src/contracts/hostBridge.ts',
'src/services/host-bridge',
];
const h5HostBridgeCallChainScanFiles = [
'src/services/clipboard.ts',
'src/services/appTitle.ts',
'src/services/runtimeAudioFeedback.ts',
'src/hooks/useHostLifecycleActive.ts',
'src/hooks/useHostNetworkOnline.ts',
'src/components/common/PublishShareModal.tsx',
'src/components/common/publishShareCardImage.ts',
'src/components/common/CreativeAudioInputPanel.tsx',
];
const expectedWechatHostBridgeFiles = [
'dispatch.js',
'payment.js',
@@ -106,6 +116,7 @@ const capabilityListMarkers = {
const sharedHostBridgeContractPath =
'packages/shared/src/contracts/hostBridge.ts';
const productionShellExtensions = new Set([
'.js',
'.json',
'.mjs',
'.rs',
@@ -229,6 +240,10 @@ function collectProductionShellFiles(entryPath) {
return [];
}
if (!fs.existsSync(entryPath)) {
throw new Error(`production shell scan path does not exist: ${entryPath}`);
}
const stats = fs.statSync(entryPath);
if (stats.isDirectory()) {
const name = path.basename(entryPath);
@@ -245,7 +260,10 @@ function collectProductionShellFiles(entryPath) {
}
function assertNoProductionShellDevScaffoldTerms() {
const files = productionShellScanRoots.flatMap(collectProductionShellFiles);
const files = [
...productionShellScanRoots,
...h5HostBridgeCallChainScanFiles,
].flatMap(collectProductionShellFiles);
for (const file of files) {
const source = fs.readFileSync(file, 'utf8');
@@ -384,6 +402,11 @@ function assertNativeShellCapabilityPlan() {
'native shell plan must not document core:default as a desktop capability permission',
);
}
if (!planSource.includes('主窗口 capability 只授予 `allow-host-bridge-request`')) {
throw new Error(
'native shell plan must document the minimal desktop capability permission',
);
}
assertNativeShellScaffoldScanWording(planSource, 'native shell plan');
assertNativeShellScaffoldScanWording(
hostBridgeProtocolDocSource,