Commit Graph

3 Commits

Author SHA1 Message Date
JacobZyy 0a20844bd4 fix: address PR #4180 review - security, typing, and test coverage
- Apply mcp_env_allowlist to plugin hooks: intersect HTTP allowedEnvVars
  with MCP allowlist, set command allowedEnvVars to full MCP allowlist
- Scrub process.env in executeHookCommand when allowedEnvVars provided
- Add PluginHooksState class with per-directory Map storage
- Add PluginHooksConfig interface for typed boundary layer
- Pass directory context through hook-config-handler
- Add 16 tests across 4 files (40 assertions) covering allowlist
  filtering, env scrubbing, directory isolation, and edge cases
- Remove unnecessary 'as' type assertions, use discriminated union
  narrowing instead
2026-05-20 22:30:25 +08:00
JacobZyy 5e20842262 fix(hooks): always persist plugin hook config state, even when empty
When all plugin hooks are removed (user disables/uninstalls plugins),
hooksConfigs becomes an empty array. The previous guard
(hooksConfigs.length > 0) skipped setPluginHooksConfigs(), leaving
stale plugin hooks active in pendingPluginHooksConfigs. Now we always
call setPluginHooksConfigs() so empty configs properly clear the
pending state and invalidate the cache.
2026-05-19 14:15:42 +08:00
JacobZyy 4d105d0559 fix(hooks): merge marketplace plugin hooksConfigs into claude-code-hooks at config time
Previously, loadPluginHooksConfigs() loaded plugin hooks from marketplace
plugins (hookify, superpowers, zzcommon, zzfe, etc.) into
pluginComponents.hooksConfigs, but config-handler.ts never consumed them.
This meant plugin hooks were discovered but never merged into the runtime
hooks dispatch system.

Changes:
- Extend ClaudeHookEvent and ClaudeHooksConfig to support all 12 event
  types (PostToolUseFailure, PermissionRequest, Notification,
  SubagentStart, SubagentStop, SessionStart, SessionEnd) in addition to
  the existing 5
- Add ALL_HOOK_EVENT_TYPES constant as single source of truth for event
  type iteration
- Add mergePluginHooksConfigs() to unwrap plugin HooksConfig (with hooks
  wrapper) into flat ClaudeHooksConfig, filtering out unsupported
  prompt/agent hook types
- Add setPluginHooksConfigs() to store pending plugin configs and
  invalidate the config cache
- Create applyHookConfig() handler following existing applyXxxConfig
  pattern, wired into config-handler after loadPluginComponents()
- Extend DisabledHooksConfig and mergeDisabledHooks for all 12 events

Closes #4179
2026-05-19 14:03:13 +08:00