Bodu.Globalization.Calendar.Plugins
1.0.0
dotnet add package Bodu.Globalization.Calendar.Plugins --version 1.0.0
NuGet\Install-Package Bodu.Globalization.Calendar.Plugins -Version 1.0.0
<PackageReference Include="Bodu.Globalization.Calendar.Plugins" Version="1.0.0" />
<PackageVersion Include="Bodu.Globalization.Calendar.Plugins" Version="1.0.0" />
<PackageReference Include="Bodu.Globalization.Calendar.Plugins" />
paket add Bodu.Globalization.Calendar.Plugins --version 1.0.0
#r "nuget: Bodu.Globalization.Calendar.Plugins, 1.0.0"
#:package Bodu.Globalization.Calendar.Plugins@1.0.0
#addin nuget:?package=Bodu.Globalization.Calendar.Plugins&version=1.0.0
#tool nuget:?package=Bodu.Globalization.Calendar.Plugins&version=1.0.0
Bodu.Globalization.Calendar.Plugins
API stability — Stable. The public API surface is committed; breaking changes are reserved for a major-version bump per SemVer.
Trust-gated loading of external Bodu.Globalization.Calendar algorithm plugins. Third-party assemblies can contribute custom INotableDateAlgorithm implementations, but only after passing an explicit trust policy — loading executes attacker-controlled code, so the gate is opt-in and fails closed.
Installation
dotnet add package Bodu.Globalization.Calendar.Plugins
Targets net8.0. All types live in the Bodu.Globalization.Calendar.Plugins namespace.
Trust model
NotableDatePluginLoader evaluates a candidate assembly against an IPluginTrustPolicy before activating any plugin. The policy receives a PluginTrustContext (assembly name, file path, SHA-256 hash, strong-name public-key token) and returns a PluginTrustResult.
| Policy | Trust basis | Guarantee |
|---|---|---|
FileHashPluginTrustPolicy |
SHA-256 file-hash allow-list | Integrity — the exact reviewed bytes, or nothing; the strongest bundled policy |
StrongNamePluginTrustPolicy |
Strong-name public-key token allow-list | Identity claim only — .NET (Core) does not verify strong-name signatures at load, and the token is copyable metadata; never sufficient alone for untrusted input — combine with the hash policy |
CompositePluginTrustPolicy |
Every constituent policy (AND) | Fails closed; an empty composite trusts nothing |
DelegatingPluginTrustPolicy |
Custom delegate | As strong as the delegate |
AllowAllPluginTrustPolicy |
Nothing | Development only — accepts everything; unsafe |
The gate is an admission check, not a sandbox: an admitted plugin runs with the full trust of the process. The complete contract — entry-point strength, registration collision policy, unloading — is documented in the plugin trust guide.
Plugin contract
A plugin assembly declares its entry point with NotableDatePluginAttribute and implements INotableDateAlgorithmPlugin (deriving from INotableDatePlugin, which carries Name and Version). On load, contributed algorithms are registered into the algorithm registry. Failures surface through a typed exception hierarchy rooted at NotableDatePluginException: PluginNotTrustedException, PluginActivationException, and PluginMissingAttributeException.
Construct a policy (for untrusted input, a CompositePluginTrustPolicy combining the file-hash pin with the strong-name label) and pass it to NotableDatePluginLoader with the plugin's file path; untrusted assemblies are rejected before any plugin type is instantiated. LoadFromFile additionally returns a disposable NotableDatePluginHandle owning the plugin's collectible load context, so the plugin can later be unloaded.
Testing
dotnet test Bodu.Globalization.Calendar.Plugins/test/Bodu.Globalization.Calendar.Plugins.Test.csproj --settings bvt.runsettings
License
MIT. © Bodu Pty. Ltd.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Bodu.Globalization.Calendar (>= 1.0.0)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.12)
-
net8.0
- Bodu.Globalization.Calendar (>= 1.0.0)
- Microsoft.Extensions.Logging.Abstractions (>= 8.0.2)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.