Problem
PluginContext has no provider that lets a plugin ask "who are my active co-members across the organisations I belong to" — the operation any recipient-picker / sharing feature needs.
What exists today:
authDataProvider — only exposes the current user (identity/permissions), nothing about other members.
userManagementProvider — has getAllUsersWithRoles / searchUsersByEmail, but it's explicitly admin-only (global user directory for role management), not usable by a regular user's plugin.
supabaseDataProvider — the generic select/rpc escape hatch every plugin falls back to.
The organisation plugin itself doesn't register a plugin-to-plugin API (registerPluginAPI) either. It just calls two raw RPCs directly: get_my_organisations then list_organisation_members per org (OrganisationRepository.kt). There's no single call to get "all my co-members across every org, deduplicated."
Evidence this is a real gap
The screenshot-share plugin needed exactly this for its "send to teammate" recipient picker, and had to add its own new Supabase RPC (list_shareable_recipients, in BossConsole/supabase/migrations/20260824000000_screenshot_shares.sql) that:
- Joins
organisation_members twice to find active co-members across every org the caller belongs to
- Dedupes by user id
- Excludes the caller
This is exactly the kind of thing a shared PluginContext provider should offer, instead of every sharing/recipient-picker plugin hand-rolling its own SECURITY DEFINER RPC and migration.
Suggestion
Add something like:
interface OrganisationMembersProvider {
suspend fun listCoMembers(query: String? = null, limit: Int = 50): Result<List<CoMember>>
}
exposed as PluginContext.organisationMembersProvider, backed by the same query the new list_shareable_recipients RPC already implements (org-scoped, active-members-only, no global user directory). Plugins like screenshot-share could then drop their bespoke RPC/migration entirely.
Problem
PluginContexthas no provider that lets a plugin ask "who are my active co-members across the organisations I belong to" — the operation any recipient-picker / sharing feature needs.What exists today:
authDataProvider— only exposes the current user (identity/permissions), nothing about other members.userManagementProvider— hasgetAllUsersWithRoles/searchUsersByEmail, but it's explicitly admin-only (global user directory for role management), not usable by a regular user's plugin.supabaseDataProvider— the genericselect/rpcescape hatch every plugin falls back to.The organisation plugin itself doesn't register a plugin-to-plugin API (
registerPluginAPI) either. It just calls two raw RPCs directly:get_my_organisationsthenlist_organisation_membersper org (OrganisationRepository.kt). There's no single call to get "all my co-members across every org, deduplicated."Evidence this is a real gap
The screenshot-share plugin needed exactly this for its "send to teammate" recipient picker, and had to add its own new Supabase RPC (
list_shareable_recipients, inBossConsole/supabase/migrations/20260824000000_screenshot_shares.sql) that:organisation_memberstwice to find active co-members across every org the caller belongs toThis is exactly the kind of thing a shared
PluginContextprovider should offer, instead of every sharing/recipient-picker plugin hand-rolling its own SECURITY DEFINER RPC and migration.Suggestion
Add something like:
exposed as
PluginContext.organisationMembersProvider, backed by the same query the newlist_shareable_recipientsRPC already implements (org-scoped, active-members-only, no global user directory). Plugins like screenshot-share could then drop their bespoke RPC/migration entirely.