Editor

VS Code in the browser, per account, with an Open VSX extension policy and framework packs.

In preview editor version 0.1.0

Actions

16 actions, callable from the panel, the command palette and the API as POST /api/v1/a/<id>. Internal actions used between modules are not listed.

ActionWhat it doesRiskPreview
editor.install Install code-server on a server high No dry run
editor.session.open Open the editor medium No dry run
editor.status Editor status of an account (read) low No dry run
editor.instance.stop Stop the editor low No dry run
editor.instance.list Running editor instances (read) low No dry run
editor.instance.admin_stop Stop any editor instance low No dry run
editor.extension.install Install an extension medium No dry run
editor.extension.uninstall Uninstall an extension low No dry run
editor.extension.list Installed extensions (read) low No dry run
editor.pack.list Recommended extension packs (read) low No dry run
editor.pack.install Install a recommended pack medium No dry run
editor.policy.get Show the extension policy (read) low No dry run
editor.policy.set Set the extension policy high No dry run
editor.policy.check Test an extension id against the policy (read) low No dry run
editor.settings.get Show editor settings (read) low No dry run
editor.settings.set Change editor settings high No dry run

Permissions and limits

Permissions

  • editor.use Open the editor and manage own extensions
  • editor.admin.view See editor instances, policy and settings
  • editor.instance.manage Stop any editor instance
  • editor.policy.manage Change the extension policy
  • editor.admin Install code-server and change editor settings

Engineering notes

Generated from modules/editor/docs.md at build d90e9e2. These are the notes the engineers keep next to the code: precise, technical, and honest about what is not done yet.

Declared in module.yaml; agent driver internal/agent/editor.go; op types sdk/agentop/editor.go; policy and packs in modules/editor/policy.

Model

  • editor.install (admin): downloads the pinned code-server 4.141.0 deb (MIT), verifies its sha256, installs it.
  • editor.session.open: starts (or reuses) rc-editor-<user>.service and returns a ticket. The unit runs as the account user in rc-acct-<user>.slice, NoNewPrivileges, PrivateTmp, ProtectSystem=strict, TemporaryFileSystem=/home + BindPaths=<own home> (other accounts' homes do not exist in its mount namespace), optional MemoryMax. It listens only on /run/rc-editor-<user>/code.sock (runtime dir 0700, socket 0600), auth none behind the socket, telemetry and update checks off (telemetry.telemetryLevel=off, update.mode=none are enforced on every start, plus the admin's locked settings), --idle-timeout-seconds (default 30 min) so it stops itself. Extensions: EXTENSIONS_GALLERY points at Open VSX only.
  • editor.session.open {app_id} opens ~/apps/<app>/current and returns the matching suggested_pack; file + line deep-link into the workbench. Nothing is installed without an explicit editor.pack.install.
  • Extensions: editor.extension.install/uninstall/list, editor.pack.list/install (16 vetted packs, every id checked on Open VSX), policy editor.policy.get/set/check (open | allow_list, allow/deny publisher.name or publisher.*, deny wins). The control plane checks and the agent checks again.
  • Admin: editor.settings.get/set (idle minutes, memory, max_running_per_node, default + locked settings), editor.instance.list/admin_stop.

The gateway (core, not built here)

Same pattern as the terminal (docs/security/terminal.md). This module provides the ticket side: editor.ticket.redeem (internal, system actor only) consumes the ticket atomically if it is unused, unexpired, opened by that principal from that browser session (web_session<>'', so API-token tickets never redeem), and returns {node_id, username, socket, url_path}. What core must add (internal/api, outside this card's paths): a GET /api/v1/editor/open?ticket= + proxied /editor/... HTTP and WebSocket route that checks, in order, Origin (as terminalGW.originAllowed), ticket shape, session cookie only (AuthenticateStream), redeems via the system actor, then reverse-proxies to the unix socket (same node) or over the bus (other nodes), re-validating the session every 15 s and on every WebSocket upgrade, with a per-principal/global cap and audit editor.stream.opened|closed|denied. See the handover for the exact request.

Not done

Socket activation (the unit starts on session.open and idles out by itself; no systemd .socket), queueing instead of a refusal at max_running_per_node, workbench-side enforcement of the policy (the policy is enforced on panel installs; the workbench's own marketplace view talks to Open VSX directly until a gallery proxy exists), port-forward previews, debug-mode toggle, Git credential helper, collaboration (AC-editor-10/12/13/17).