Skip to content

fix(nextly): reject duplicate plugin admin slugs at boot - #747

Merged
mobeenabdullah merged 4 commits into
mainfrom
fix/plugin-slug-uniqueness
Aug 13, 2026
Merged

mobeenabdullah merged 4 commits into
mainfrom
fix/plugin-slug-uniqueness

Conversation

@mobeenabdullah

Copy link
Copy Markdown
Collaborator

Two plugins can currently share one admin address, silently.

The defect

pluginAdminSlug lowercases a package name and collapses every non-alphanumeric run to a single dash, so it is not injective. All of these produce acme-plugin-seo:

@acme/plugin-seo    @acme/plugin.seo    ACME_Plugin_SEO
acme-plugin-seo     @acme//plugin--seo

That slug is the plugin's address: the admin builds /admin/plugins/<slug> from it, core namespaces the plugin's admin routes with it, and host pluginOverrides are looked up by it. Nothing enforces uniqueness — resolvePlugins validates versions (validate-versions.ts) and client configs (validate-client-config.ts) and never the slug.

So with two colliding plugins installed, one plugin's detail page opens the other's, and one plugin's overrides apply to its neighbour. No error is raised at any point.

Why the check goes at registration

Nowhere downstream can detect it. At a lookup, find() returns a plugin — and a plugin is exactly what a correct lookup returns, so no code at the point of use can separate "the right one" from "the first of two". Registration is the last moment at which the ambiguity is still visible as ambiguity.

resolvePlugins now calls validatePluginSlugs, which throws a PLUGIN_RESOLUTION_ERROR with reason: "duplicate-admin-slug", naming both packages and the slug they collide on — the reader has to rename one, and the message is the only place the pair is ever stated together. This mirrors the existing fail-fast shape of validate-versions.ts.

Audit

Before relying on a boot check, I confirmed nothing derives the slug independently: every consumer imports the single pluginAdminSlug helper from core (admin re-exports it as pluginSlug). The other [^a-z0-9] collapsing regexes in the repo are for field names, table names and single names — different domains, not plugin addresses. So this check is authoritative rather than one of two answers.

Tests

validate-slugs.test.ts covers five distinct collision shapes — scope separator, dot-for-dash, case, underscores, doubled separator — plus the same name registered twice, which is the likelier mistake (an app and a preset both registering one plugin). Assertions read logContext.reason rather than the error message, since NextlyError deliberately carries a generic public message that every resolution failure shares.

resolve.test.ts covers the wiring separately. That matters: break-verification showed that removing the call from resolvePlugins left every validator test green, because they exercise the validator directly.

Break-verified in both directions — unwiring the call fails only the wiring test; the validator suite fails only on real collisions, with a control asserting the helper reports undefined when nothing collides.

Notes

  • packages/nextly/src/plugins/schema/caching.test.ts fails 2 tests on this branch. Pre-existing: measured identically on origin/main at the same commit, and the stack (assertNoLegacyFieldGroupKey) is not in this change's call path.
  • Follows decision D8, taken after this was raised on feat(admin): add a plugin directory to browse and search published plugins #742. The alternative considered and rejected was giving the plugin catalogue its own URL namespace — it reverses design decision D5 (one URL per plugin), fixes only the catalogue half, and leaves the installed-vs-installed case untouched.

pluginAdminSlug collapses every non-alphanumeric run to one dash, so distinct
package names map to one slug and the plugins silently share an admin address.
No lookup downstream can detect it, because every lookup along that address
returns a plugin, which is what a correct lookup returns.
@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex please review this PR

@coderabbitai

coderabbitai Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@mobeenabdullah, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 7 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 9bdd1572-8f76-405a-9450-541a1fb779fa

📥 Commits

Reviewing files that changed from the base of the PR and between d4f6480 and 9c85534.

⛔ Files ignored due to path filters (1)
  • .changeset/plugin-admin-slug-uniqueness.md is excluded by !.changeset/**
📒 Files selected for processing (7)
  • packages/nextly/src/cli/utils/config-loader.ts
  • packages/nextly/src/di/register.ts
  • packages/nextly/src/plugins/admin-meta.ts
  • packages/nextly/src/plugins/resolve.test.ts
  • packages/nextly/src/plugins/resolve.ts
  • packages/nextly/src/plugins/validate-slugs.test.ts
  • packages/nextly/src/plugins/validate-slugs.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 12ada287c2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/nextly/src/plugins/resolve.ts
Comment thread packages/nextly/src/plugins/resolve.ts
…y at boot

resolvePlugins runs before setup transformers can rewrite config.plugins, and
createDynamicHandlers serves the public admin-meta endpoint before services
initialize at all. Both published ambiguous addresses from a list the boot check
never saw. buildPluginAdminMeta is the one place a plugin list becomes
addresses, so it validates what it is about to address.
@pkg-pr-new

pkg-pr-new Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@nextlyhq/adapter-drizzle

npm i https://pkg.pr.new/@nextlyhq/adapter-drizzle@19e068c

@nextlyhq/adapter-mysql

npm i https://pkg.pr.new/@nextlyhq/adapter-mysql@19e068c

@nextlyhq/adapter-postgres

npm i https://pkg.pr.new/@nextlyhq/adapter-postgres@19e068c

@nextlyhq/adapter-sqlite

npm i https://pkg.pr.new/@nextlyhq/adapter-sqlite@19e068c

@nextlyhq/admin

npm i https://pkg.pr.new/@nextlyhq/admin@19e068c

@nextlyhq/admin-css

npm i https://pkg.pr.new/@nextlyhq/admin-css@19e068c

@nextlyhq/blocks-engine

npm i https://pkg.pr.new/@nextlyhq/blocks-engine@19e068c

@nextlyhq/blocks-react

npm i https://pkg.pr.new/@nextlyhq/blocks-react@19e068c

@nextlyhq/builder

npm i https://pkg.pr.new/@nextlyhq/builder@19e068c

create-nextly-app

npm i https://pkg.pr.new/create-nextly-app@19e068c

nextly

npm i https://pkg.pr.new/nextly@19e068c

@nextlyhq/plugin-form-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-form-builder@19e068c

@nextlyhq/plugin-page-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-page-builder@19e068c

@nextlyhq/plugin-sdk

npm i https://pkg.pr.new/@nextlyhq/plugin-sdk@19e068c

@nextlyhq/plugin-seo

npm i https://pkg.pr.new/@nextlyhq/plugin-seo@19e068c

@nextlyhq/storage-s3

npm i https://pkg.pr.new/@nextlyhq/storage-s3@19e068c

@nextlyhq/storage-uploadthing

npm i https://pkg.pr.new/@nextlyhq/storage-uploadthing@19e068c

@nextlyhq/storage-vercel-blob

npm i https://pkg.pr.new/@nextlyhq/storage-vercel-blob@19e068c

@nextlyhq/ui

npm i https://pkg.pr.new/@nextlyhq/ui@19e068c

commit: 19e068c

@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex please review this PR

@github-actions github-actions Bot added scope: core nextly type: docs Documentation only labels Aug 13, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 19e068cd47

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/nextly/src/di/register.ts
The CLI runs its own transformer loop, so a setup() that renames plugins into a
slug collision was accepted by nextly build, migrations and db sync while the
deployed app refused to start on the same config.
@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex please review this PR

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 9c8553420c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mobeenabdullah
mobeenabdullah merged commit c92db86 into main Aug 13, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scope: core nextly type: docs Documentation only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant