Marketplace: pin the commit the user reviewed (final review I2)
Install and update pinned whatever the marketplace head was when the click landed, so a background refresh between review and click could pin content nobody saw (including a hook's shell commands). install_marketplace_item and update_marketplace_item now take expected_commit and refuse with "changed since you reviewed this item — review it again" unless it is still the head. The UI passes the head the selected item was read at (Browse), the head frozen with a pending hook confirm (whose commands are frozen too), and the head of the accepted diff (Installed). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -184,7 +184,10 @@ password = token. Shallow fetch is not used (pins need history for diff/ancestry
|
||||
**Update detection** compares each installed item's own tree (item folder / file blob id) at
|
||||
its pin vs. the branch head; only a changed item shows "update available".
|
||||
**Update** shows a text diff of the item's files (pinned → head) and, on accept, moves the pin.
|
||||
Hooks' diffs always show the rendered commands.
|
||||
Hooks' diffs always show the rendered commands. Install and update both carry the commit the user
|
||||
reviewed (the head the item was read at, the head of the accepted diff); the backend pins exactly
|
||||
that commit and refuses with "changed since you reviewed this item — review it again" if the
|
||||
marketplace's head has moved since.
|
||||
|
||||
**Accounts** (`marketplace/auth.rs`):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user