# Task: Plugin navigation remediation ## Identity - Task ID: 20260903-plugin-navigation-remediation-c5e8a731 - Mode: Feature - Branch: codex/20260903-plugin-navigation-remediation-c5e8a731-plugin-navigation-remediation - Worktree: C:\Users\7brot\.codex\worktrees\plugin-nav-remediation-c5e8a731\makelore - Base commit: 1b1f206dd8aeb7bf69e61b0cd684f70accce9e26 - Owner: codex-01a0656d - Status: Ready for Integration ## Scope - Remediate the five fixed-range Spec failures reported by task `20260903-plugin-navigation-acceptance-5e8b3c72` on implementation head `1b1f206dd8aeb7bf69e61b0cd684f70accce9e26`. - Own only `src/pages/Plugins/**`, their focused unit/page tests, and this task record. No store, Electron Main, server, runtime, billing authority, sidebar, module guard, or legacy redirect change is in scope. - Deliver one remediation commit for a fresh fixed-range Standards + Spec review; do not merge `main`, push, create a PR, deploy, publish, package, or install. ## Intent And Constraints - Concurrent Task Gate passed for the exact identity/base/worktree above. The prior implementation and acceptance tasks are Ready for Integration and are read-only. The AI Design peer explicitly excludes Plugin pages/navigation, so no file or semantic ownership overlap exists. - Planning Gate passed after reading the exact project-memory tree, authoritative Spec `ML-PLUGIN-NAV-001`, ADR-006, prior implementation/acceptance records, and the current Renderer projection/page/controller plus Marketplace DTO/store contracts. - Confirmed public TDD seams are the pure projection/query resolver, the local command dispatcher, and `PluginsView`/route composition. Tests must fail before each production correction and observe URL, commands, copy, and detail output rather than private implementation calls. - Continuously canonicalize invalid URL state without a one-shot ref or replace loop, while preserving one visible no-project fallback notice. - Preserve a source-qualified `retained:` project selection even when Catalog or Library recognizes the same ID; it may use those sources only for display metadata and may dispatch only disable for the projection's original project ID. - Treat `status=unavailable` plus retained version/channel/reason as an existing device package for cleanup and same-channel update semantics. Show its reason, mark retained snapshots stale after refresh failure, and distinguish suspended from retired without inferring state across sources. - Render operation-level pricing only from Marketplace detail or current project policy, deduplicated by capability/operation identity and without client-side price calculation. - Distinguish signed-out acquisition from authenticated Library failure. Signed-out users receive an explicit login command; authenticated unknown Library state remains fail-closed. - Existing DTOs already expose every required field, so no authority/interface conflict is present. If later evidence contradicts that conclusion, stop the affected range rather than add a compatibility layer or broaden ownership. - Preserve the root workspace and all peer worktrees; in particular do not write or clean `D:\\Datas\\OthersProjects\\makelore`. ## Project Context Loaded - Product goal: one understandable Plugin workspace that composes, but never merges, Catalog, Library, device package, project, Agent, admission, and billing authorities. - Current state: official bundled Plugins, conversation-only Device Packages, and selected-model native Web Search already have separate delivery/runtime rules; the unified Renderer implementation is complete but failed five acceptance roots. - Relevant decisions: Electron Main retains runtime/credential ownership; Device Packages are device-global and child workers remain empty; account acquisition, device delivery, project enablement, Agent assignment, admission, and billing do not advance one another. - Relevant evidence: the acceptance record identifies unreachable scope fallback, lost recognized retained IDs, mishandled unavailable installations/stale status, omitted detail operations/pricing, and missing signed-out action as exact failures. - Canonical-memory candidate remains the prior implementation task's deferred module-map promotion; this feature remediation does not edit integrated memory. - Known documentation drift: `read-before-planning.md` names old locations for `memory-index.md` and `current-state.md`; the exact existing files were resolved with `rg --files` and read successfully, so this is non-blocking. ## Outcome - Replaced one-shot URL normalization with a pure query resolution result and a Router-location marker that carries the no-project fallback notice across the canonical replace. Canonical URL and scope controls now remain aligned when the active project changes or the same mounted route receives a new invalid query, without a `setSearchParams` loop or effect-owned React state. - Preserved catalog/Library-recognized `unknownPluginIds` as source-qualified `retained:` rows in both project and all scopes. They reuse only recognizable display metadata and expose exactly one mutation: disable against the project ID recorded by the project projection. - Treated `MarketplaceInstallation.status=unavailable` with a retained version and channel as an existing device package for same-channel update and device removal, while keeping runtime/project actions fail-closed. Cards and details display the retained version reason, failed retained snapshots show `缓存`, and suspended/retired states have distinct copy. - Added a read-only detail operation projection. Marketplace detail operations render without a project; the current project policy replaces a duplicate operation as one complete server-owned billing projection, while detail-only operations remain visible. No pricing is calculated or inferred locally. - Added an explicit `sign_in` command for signed-out free catalog entries and dispatch it to the existing `/login` route. Authenticated Library failure still reports unknown delivery and exposes no acquisition mutation. - No route, store, Electron Main, server, runtime, billing authority, sidebar, or E2E file changed. No new authority, fallback, feature flag, compatibility layer, or visible local-package installation entry was added. - This task supplies a remediation candidate only. It does not claim the fresh fixed-range Standards + Spec review has passed. ## Verification - TDD URL RED: focused query/page tests failed because the production composition erased `scope=project` before the fallback notice and only normalized the first URL. GREEN: the final query + page run passed 2 files / 13 tests. - TDD projection/action RED: focused model/controller/page tests produced the six expected failures for retained unavailable installation semantics, stale and lifecycle copy, recognized retained IDs, signed-out action, login dispatch, and visible status copy. GREEN: the focused five-file suite passed 5 files / 34 tests. - TDD detail RED: the two new page assertions failed because Marketplace detail operations were absent without a project and a detail-only operation disappeared when project policy existed. GREEN: `tests/unit/plugins-page.test.tsx` passed all 9 tests with server pricing output and duplicate identity coverage. - `corepack pnpm run typecheck`: passed (`tsc --noEmit`). - `corepack pnpm run lint:check`: passed with zero errors. Five pre-existing warnings remain in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`; neither file is owned or changed by this task. - `corepack pnpm test`: passed 225 files / 1830 tests with 2 skipped, followed by the isolated pressure file passing 1 file / 1 test (aggregate 226 files / 1831 passed / 2 skipped). - `corepack pnpm run build:vite`: passed all Renderer, Electron Main, Preload, and release utility builds. Existing Browserslist-age, mixed dynamic/static import, and large-chunk warnings remain non-blocking. - `corepack pnpm run test:e2e -- tests/e2e/plugin-marketplace.spec.ts tests/e2e/project-plugins.spec.ts --reporter=line`: passed the existing 4/4 Electron flows. The command also rebuilt all production targets successfully. The E2E set was not expanded because the remediation is covered at the production composition/pure projection seams and did not require a route or Host API change. - `git diff --check`: passed before documentation closeout. ## Follow-ups - Run fresh fixed-range Standards + Spec review over `959e2faf03dfacb3c8e2035e44774436c752d4b0...remediation HEAD`; do not integrate or merge `main` before that independent acceptance completes. ## Promotion Candidates - None. This remediation changes no durable authority or architecture decision; the prior implementation task's module-map candidate remains the correct owner.