Skip to main content

Extension user interface

Glixo owns navigation, menu layout, focus, keyboard behavior, dialogs, permission screens, and the shared visual system. Extensions add typed contributions at published placements; they do not select DOM nodes or depend on private React component names.

Shared controls and custom surfaces

The Accessible Theme example has four language action guests and a sandboxed settings panel. It is not an installed theme; Glixo Code has no theme selector or apply flow. Windows isolation checks passed 7/7 in a source-built app. The signed package, account grant, and full action journey are still being checked. Linux custom panels are unavailable; mobile is unsupported. See Reference for current status.

The separate @glixo/extension-ui helper provides reusable controls and theme tokens for extension authors. It is Preview authoring source, not an installable contribution or theme. Glixo Code has no installed-theme selector or apply flow; theme contributions remain Planned.

Configuration forms are also Preview. The current editor validates a bounded JSON Schema subset and the submitted value: each schema and value is limited to 64 KiB and nesting to 16 levels. Objects support recursive properties, required, and boolean additionalProperties; arrays require an items object schema and maxItems from 0 through 64, with optional minItems. It validates nested values against these limits and rejects nested secret markers. This is not full JSON Schema support or an installed contribution qualification. Credentials belong in host-managed connection setup.

Rich views can run in an isolated web surface with a versioned bridge and restrictive content policy. The browser-facing component kit follows the same semantic tokens and interaction rules. A theme bridge can provide mode, typography, color tokens, spacing, reduced motion, contrast, locale, and direction. An extension can still draw custom pixels; theme tokens cannot force arbitrary canvas or CSS to match the host.

Keep bridge calls bound to the current package digest, instance, contribution, account, grants, sequence, and cancellation state. Revoke the channel on update, uninstall, grant change, account switch, or frame reload. WebView support is reported separately for each mobile platform after native isolation tests; a browser demonstration does not prove mobile support.

Placements and responsive behavior

Host-rendered commands and actions use declarative descriptors. Views own their content while the host owns title, ordering, close behavior, focus, and recovery. On phones, sidebars and panels become sheets or screens while preserving state and accessibility.

The accepted placement inventory and source state are versioned with the host registry. Only placements with a registered renderer and installed-host acceptance carry an Available label. Current implementation and gaps appear in the UI source/reference lane.