feat(lock): main-window lock screen; harden env gating, sandbox and ssh teardown
Lock screen (main-window overlay, no second window): - scrypt password verifier in <userData>/lock.json (per-write salt, timingSafeEqual); salt/hash/password never leave the main process - lock now / idle auto-lock / lock at startup, growing failure cooldown, lock flags persisted so a quit-and-relaunch cannot bypass the lock - locked shell and body portals go inert while sessions keep running; menu accelerators (reload, DevTools, zoom) are swallowed while locked - settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja Security and stability: - packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv) - renderer preload runs with sandbox: true - unreadable known_hosts store fails closed instead of being overwritten - connect-time secrets gated by the bookmark's auth method (connectPromptFor) - ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once - sysinfo polling is refcounted for split panes (forceStopPolling on close) - session-log index entries are path-contained; settings store writes atomically with EPERM/EBUSY retry - sync-changelog tolerates CRLF checkouts (was a silent no-op) - retry ssh2 host-key generation (flaky malformed key, ~1/500) Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e; GitHub Actions CI (typecheck + 10 offline tests + build)
This commit is contained in:
1 parent
471f8c3e73
commit
35583b2c15
47 files changed
+3058
-105
No files matched your search
@@ -3,6 +3,7 @@ import { Ipc } from '../shared/ipc'
|
||||
import type { AppSettings } from '../shared/settings'
|
||||
import type { AppApi } from '../shared/api'
|
||||
import type { LayoutMeta, PtyCreateOptions, PtyDataEvent, PtyExitEvent, ReleaseNote, SessionSnapshot, UpdateState, ZmodemOfferEvent, ZmodemResponse, ZmodemDoneEvent } from '../shared/ipc'
|
||||
import type { LockOperationResult, LockPasswordInput, LockSettingsState } from '../shared/ipc'
|
||||
import type {
|
||||
HostKeyAction,
|
||||
HostKeyPromptEvent,
|
||||
@@ -113,6 +114,18 @@ const api: AppApi = {
|
||||
return () => ipcRenderer.removeListener(Ipc.SETTINGS_CHANGED, listener)
|
||||
},
|
||||
|
||||
getLockState: () => ipcRenderer.invoke(Ipc.LOCK_STATE_GET),
|
||||
setLockPassword: (input: LockPasswordInput) => ipcRenderer.invoke(Ipc.LOCK_SET_PASSWORD, input),
|
||||
clearLockPassword: (input: { currentPassword?: string }) =>
|
||||
ipcRenderer.invoke(Ipc.LOCK_CLEAR_PASSWORD, input),
|
||||
unlockLock: (input: { password?: string }) => ipcRenderer.invoke(Ipc.LOCK_UNLOCK, input),
|
||||
lockNow: () => ipcRenderer.invoke(Ipc.LOCK_NOW),
|
||||
onLockStateChanged: (cb: (state: LockSettingsState) => void) => {
|
||||
const listener = (_: unknown, state: LockSettingsState): void => cb(state)
|
||||
ipcRenderer.on(Ipc.LOCK_STATE_CHANGED, listener)
|
||||
return () => ipcRenderer.removeListener(Ipc.LOCK_STATE_CHANGED, listener)
|
||||
},
|
||||
|
||||
listFonts: () => ipcRenderer.invoke(Ipc.FONTS_LIST),
|
||||
|
||||
listLayouts: () => ipcRenderer.invoke(Ipc.LAYOUTS_LIST),
|
||||
|
||||
Reference in new issue
Block a user