* chore: remove dead code, deprecate unused plugin APIs (over-engineering audit)
Whole-tree audit. Every symbol was checked against core, the plugin
monorepo and all eight third-party plugins in plugins.json first.
- Deprecate (removal 3.10.0) plugin-facing methods nothing calls:
LogoDownloader bulk download, ConfigManager backup/secret wrappers,
APIHelper extras, BackgroundDataService poll API, PluginManager /
PluginStateManager info readers, and a few CacheManager, FontManager,
BaseOddsManager, DynamicTeamResolver methods and PluginTestCase.
plugin_api_usage.py learns their receiver names; DEPRECATIONS doc
regenerated.
- Remove core-internal dead code: CacheMetrics, Vegas status/stats
plumbing, sync "new cycle" message (followers ignore unknown types),
unused operation types, test-only PluginCatalog readers, IPC to_dict
and ping, _parse_form_value, CacheStrategyProtocol, ErrorAggregator
callbacks, duplicate web response helpers.
- Web UI: drop never-mounted json-file-manager.js, the example widget,
utils/error_handler.js, four uncalled PluginAPI methods, and 29
escapeHtml shims (call window.LEDEscape directly). Public globals,
BaseWidget and widget names unchanged.
- Remove six one-off scripts (owner decision) and the unused markupsafe
and pytest-mock pins.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): calendar picker error text goes in a text node, not innerHTML
Same output as the escaped innerHTML it replaces; clears Codacy's
XSS-pattern alerts on the line.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
GET /plugins/installed called get_registry_info() per plugin. Despite the
"no network call" comment, a cold or expired cache made that download
plugins.json (10 s timeout, three attempts), and with no cached copy each
plugin's lookup repeated it -- offline, every load waited out the timeouts.
The route now reads the registry copy already in memory, however old, via
get_cached_registry_info(). A missing or expired copy starts a single
background refresh (backing off after an offline failure), so a later load
gets update and verified badges. Store, install and update paths still fetch.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The store reads three optional registry fields: ledmatrix_min_version
(an incompatible install/update is refused before any download, with a
"Needs LEDMatrix X+" card badge), aliases (update/uninstall/reinstall by
registry id find a plugin installed under its manifest id, with registry
proof only), and commit (shown and linked on the store card). An older
plugins.json behaves as before.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* refactor(plugins): split PluginStoreManager into mixins
src/plugin_system/store_manager.py (2,977 lines) keeps the class, its
shared state, locks, the uninstall registry, directory lookup and
uninstall; its methods are split by area into:
- store_registry.py (_RegistryMixin): registry, GitHub metadata, search,
manifest validation
- store_install.py (_InstallMixin): install paths and dependencies
- store_update.py (_UpdateMixin): updates, rollback, local git state
Pure move: all 56 members are byte-identical (checked with ast) and the
assembled class has exactly the same attributes as before (checked at
runtime). PluginStoreManager is imported from store_manager.py as before.
Tests that patched shared modules (subprocess, requests, tempfile, shutil)
through store_manager now reach them through the module whose code they
exercise; a source-text contract test reads all store_*.py modules.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: annotate findings the split moved into new store modules
subprocess imports and a list-form git clone (no shell), and the config
template's placeholder token string -- existing code that Codacy reported
as new because it moved. Annotated with the repo's nosec/nosemgrep style.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: annotate the default-branch git clone the split moved
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>