* chore: remove dead code, deprecate unused plugin APIs (over-engineering audit)
Whole-tree audit. Every symbol was checked against core, the plugin
monorepo and all eight third-party plugins in plugins.json first.
- Deprecate (removal 3.10.0) plugin-facing methods nothing calls:
LogoDownloader bulk download, ConfigManager backup/secret wrappers,
APIHelper extras, BackgroundDataService poll API, PluginManager /
PluginStateManager info readers, and a few CacheManager, FontManager,
BaseOddsManager, DynamicTeamResolver methods and PluginTestCase.
plugin_api_usage.py learns their receiver names; DEPRECATIONS doc
regenerated.
- Remove core-internal dead code: CacheMetrics, Vegas status/stats
plumbing, sync "new cycle" message (followers ignore unknown types),
unused operation types, test-only PluginCatalog readers, IPC to_dict
and ping, _parse_form_value, CacheStrategyProtocol, ErrorAggregator
callbacks, duplicate web response helpers.
- Web UI: drop never-mounted json-file-manager.js, the example widget,
utils/error_handler.js, four uncalled PluginAPI methods, and 29
escapeHtml shims (call window.LEDEscape directly). Public globals,
BaseWidget and widget names unchanged.
- Remove six one-off scripts (owner decision) and the unused markupsafe
and pytest-mock pins.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): calendar picker error text goes in a text node, not innerHTML
Same output as the escaped innerHTML it replaces; clears Codacy's
XSS-pattern alerts on the line.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(plugins): web mode lookups use the modes the display registered (#668)
A plugin may compute its display modes from its config: soccer-scoreboard
registers soccer_<league>_live/recent/upcoming for every custom_leagues
entry, which no manifest can list ahead of time. The display always rotated
them (_register_loaded_plugin prefers plugin.modes), but the web process
reads plugins as files, so /display/modes, the on-demand dialog and
on-demand/start with a mode and no plugin_id saw only manifests -- a custom
league's mode was missing from every list and 404'd on lookup.
- PluginStateManager.record_modes(): the controller records what it
registered, on the loaded record (an unload or reload forgets it)
- the runtime snapshot carries it per plugin as "modes" (bounded), and
PluginRuntimeView.display_modes() reports it only while live
- PluginCatalog takes a runtime_source; get_plugin_display_modes and
find_plugin_for_mode prefer the live modes, falling back to the manifest
when the display is stopped or has not loaded the plugin. The view is read
at most once a second, so a listing is one read, not one per plugin.
No manifest or plugin change needed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(plugins): call the runtime view's display_modes directly
Codacy flagged the getattr/callable indirection as 'lookup is not callable'.
The view is a PluginRuntimeView or None; anything else raises inside the
existing try and falls back to the manifest.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(plugins): address review -- no manifest fallback for live plugins, keep mode names whole, send registered spelling
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Control socket stage 2: the render thread wakes for queued commands (static screens ~1 ms, Vegas within one frame), brightness.set, and plugin.reload after a store update, with mailbox/restart fallbacks. Rig checks listed in the PR body are still to run.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The web process built its own PluginManager and loaded plugins into itself:
store installs and updates loaded or reloaded a web-side copy, and config
saves and enable/disable called on_config_change, on_enable and on_disable
on it. None of that reached the panel, and /plugins/installed reported
runtime state from those copies.
- Add PluginCatalog (src/plugin_system/plugin_catalog.py): manifests,
directories, display modes, installed version, schema and config reads,
with no way to run a plugin. app.py and both blueprints use it; the
plugin_manager blueprint attribute is gone.
- Remove every lifecycle call from the web routes. Config changes already
reach the display through ConfigService (on_config_change) and the
enabled-set reconcile.
- Health and metrics readers move to api_v3.health_tracker /
resource_monitor. /plugins/installed reports loaded/state/error_info as
null (the display does not publish them) and enabled by the display's
rule.
- Store install, update and uninstall answer restart_required when the
running display will not pick the change up by itself
(display_restart_required). The restart banner follows the flag via
window.noteRestartRequired instead of the /config/main URL heuristic;
/config/main now sends restart_required: true.
- The one remaining in-process import of plugin code (Starlark helper
modules, oauth_flow action scripts) goes through
_import_plugin_code_in_web_process() until a web-entry contract.
- /plugins/installed reports vegas_participation (from #682) from the
user's setting or the manifest, with vegas_participation_source; when
only the plugin's code decides it, null with source 'runtime', since the
web process no longer has plugin instances to ask.
- Check & Update All keeps its restart flags when the final list refresh
fails, and asks for a restart when an enabled plugin's first request got
no answer and the re-sent one found it up to date.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>