Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path. Use for provider-backed, internal, or local optio
复制下面这句话,粘贴给 Claude Code、Codex、Cursor 等 AI 编程工具,它会读取安装说明并在你确认后完成安装。
请阅读 https://ai.atlankj.com/install/asset/gh-add-selector-a8bac1941bb5 ,按照其中的说明把「add-selector」安装到你(当前 AI 工具)中。执行前先告诉我将运行的命令和写入的位置,等我确认。
查看 AI 将读取的安装说明正在读取 GitHub 原文…
内容来自 GitHub 原始文件,由原作者维护。在 GitHub 查看
Dynamic selectors expose option metadata while a workflow or connector is being configured. Every
remote selector executes through the authorized selectors.execute application operation; the
browser never resolves credentials or calls a provider directly.
Before editing, read:
apps/sim/lib/selectors/types.tsapps/sim/lib/selectors/manifest.tsapps/sim/lib/selectors/context.tsapps/sim/lib/selectors/server/types.tsapps/sim/lib/selectors/server/registry.tsapps/sim/hooks/queries/selectors.tsThen read the nearest existing selector attachment and the block, trigger, or connector declaration that will consume the key.
provider-server: contacts an external provider or uses provider credentials.internal-server: reads protected Sim data through an existing authorized application use case.local: pure browser-safe data with no protected data, credentials, references, or network I/O.Add every key to the browser-safe manifest in lib/selectors/manifest.ts. SelectorKey derives from
that manifest; do not maintain a second union. Manifest entries contain data only: allowed context,
readiness, scope kinds, list/search/detail capabilities, and stale time. Do not import provider SDKs,
credentials, server helpers, or attachment functions into the manifest.
Declare dependsOn on the consuming sub-block or connector field. The shared context builder sends
only declared, active dependencies:
{{GMAIL_CREDENTIAL_ID}} remain unresolved in the browser.https://{{HOST}}/path is unsupported.impersonateUserEmail is the one explicit compatibility hint projected when the manifest allows
it, even when it is absent from dependsOn.Add a new SelectorContextKey only when the value is a real, reusable selector dependency. Allow it
explicitly on each relevant manifest entry. Never send a full block or connector configuration.
For provider-server, add the service's attachment map under
apps/sim/lib/selectors/server/providers/ and include it in the exhaustive server registry. For
internal-server, add the attachment in apps/sim/lib/selectors/server/internal.ts. Local keys use
the exhaustive browser-safe registry in apps/sim/lib/selectors/client/local.ts and never enter the
server registry. A provider attachment declares:
serviceIds. Raw-connection selectors instead validate the connection material projected from
their allowed context and bind it to a deliberate destination policy.fixed, credential-bound, or user-controlled.id, label, and allowlisted scalar meta.Stored credentials must pass actor-use, workspace, and provider/service binding checks. Do not trust a provider, service, operation kind, origin, or module name supplied by the browser.
Choose the destination policy deliberately:
fixed: provider origin is code-defined.credential-bound: origin/account/site comes from, or is verified against, the authorized
credential.user-controlled: the user selects the destination. Hidden use-only authentication requires an
explicit security policy; do not combine it with an arbitrary destination by default.Reuse or extract a server-only provider listing primitive. If an existing provider route has non-selector callers, keep the route as a thin caller of that primitive. If it is selector-only, move the logic and remove the obsolete route and contract. Never import a route handler or make an internal HTTP request from an attachment.
The attachment must return normalized selector results only. It must never deliberately or wholesale echo selector context, and hidden/server-only resolved material, credential IDs, tokens, and authentication secrets must never cross the response boundary. Browser-known literals and viewable personal/shared values are not automatically server-only secrets, but they may appear in an option only when the adapter intentionally projects them as provider resource metadata. Let the shared executor own scope authorization, exact-reference resolution, credential authorization, error projection, and output sanitization; adapters must pass and preserve the executor's abort signal during provider work.
Point the block, trigger, or connector field at selectorKey and declare its dependsOn fields.
Keep connector selector/manual canonical pairs and fork reconfiguration behavior intact. Static
options stay local and need no selector.
Do not add:
hooks/selectors/providers or any client provider fetcher.All server selectors use the shared POST contract and React Query facade. Query identities must stay opaque and must not include context values, references, credential IDs, secrets, or their hashes. Selector code must not add context, token, or result caches. The sole existing cache exception is authorized client-credential resolution after authorization and provider binding: it may reuse the credential service's TTL-governed, lazily pruned process-local token cache. This exception requires explicit security-owner acceptance; do not broaden it or describe it as hard-bounded.
Follow nearby Vitest and route-test style. Do not add an authorization matrix for every ordinary provider attachment; the shared executor tests own shared security behavior.
Add a focused adapter test when behavior is special, such as pagination, nontrivial destination binding, provider-specific projection, or a raw-connection policy. For an ordinary fixed-origin OAuth list, manifest/registry exhaustiveness plus an existing provider primitive test is usually enough.
Run the smallest relevant set, then:
bun run --cwd apps/sim test <focused selector tests>
bun run --cwd apps/sim type-check
bun run check:fork-dependent-coverage
bun run check:client-boundary
git diff --check
Confirm there is no browser-side provider call, every server key has one attachment, and every returned option is explicitly projected.