feat(lock): main-window lock screen; harden env gating, sandbox and ssh teardown
Lock screen (main-window overlay, no second window): - scrypt password verifier in <userData>/lock.json (per-write salt, timingSafeEqual); salt/hash/password never leave the main process - lock now / idle auto-lock / lock at startup, growing failure cooldown, lock flags persisted so a quit-and-relaunch cannot bypass the lock - locked shell and body portals go inert while sessions keep running; menu accelerators (reload, DevTools, zoom) are swallowed while locked - settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja Security and stability: - packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv) - renderer preload runs with sandbox: true - unreadable known_hosts store fails closed instead of being overwritten - connect-time secrets gated by the bookmark's auth method (connectPromptFor) - ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once - sysinfo polling is refcounted for split panes (forceStopPolling on close) - session-log index entries are path-contained; settings store writes atomically with EPERM/EBUSY retry - sync-changelog tolerates CRLF checkouts (was a silent no-op) - retry ssh2 host-key generation (flaky malformed key, ~1/500) Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e; GitHub Actions CI (typecheck + 10 offline tests + build)
This commit is contained in:
1 parent
471f8c3e73
commit
35583b2c15
47 files changed
+3058
-105
No files matched your search
+6
-1
@@ -3,6 +3,7 @@ import { autoUpdater } from 'electron-updater'
|
||||
import { Ipc, type ReleaseNote, type UpdateState } from '../shared/ipc'
|
||||
import { t } from '../shared/i18n'
|
||||
import { broadcast } from './broadcast'
|
||||
import { devUpdateFeedUrl } from './devEnv'
|
||||
import { loadSettings } from './settingsStore'
|
||||
import { markQuitting } from './tray'
|
||||
|
||||
@@ -32,11 +33,15 @@ function useFeed(feed: 'gitea' | 'github'): void {
|
||||
activeFeed = feed
|
||||
if (feed === 'gitea') {
|
||||
// Domestic feed: always direct — a system proxy only breaks it.
|
||||
// OT_UPDATE_URL overrides the feed in dev builds only; OT_UPDATE_TOKEN is
|
||||
// read from the environment in every build, which is only safe because the
|
||||
// packaged URL is the hardcoded GITEA_FEED — making it configurable again
|
||||
// would turn the token into a credential sent to whatever host it names.
|
||||
void autoUpdater.netSession.setProxy({ mode: 'direct' })
|
||||
const token = process.env.OT_UPDATE_TOKEN
|
||||
autoUpdater.setFeedURL({
|
||||
provider: 'generic',
|
||||
url: process.env.OT_UPDATE_URL || GITEA_FEED,
|
||||
url: devUpdateFeedUrl() ?? GITEA_FEED,
|
||||
...(token ? { requestHeaders: { Authorization: `token ${token}` } } : {})
|
||||
})
|
||||
} else {
|
||||
|
||||
Reference in new issue
Block a user