Lock screen (main-window overlay, no second window): - scrypt password verifier in <userData>/lock.json (per-write salt, timingSafeEqual); salt/hash/password never leave the main process - lock now / idle auto-lock / lock at startup, growing failure cooldown, lock flags persisted so a quit-and-relaunch cannot bypass the lock - locked shell and body portals go inert while sessions keep running; menu accelerators (reload, DevTools, zoom) are swallowed while locked - settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja Security and stability: - packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv) - renderer preload runs with sandbox: true - unreadable known_hosts store fails closed instead of being overwritten - connect-time secrets gated by the bookmark's auth method (connectPromptFor) - ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once - sysinfo polling is refcounted for split panes (forceStopPolling on close) - session-log index entries are path-contained; settings store writes atomically with EPERM/EBUSY retry - sync-changelog tolerates CRLF checkouts (was a silent no-op) - retry ssh2 host-key generation (flaky malformed key, ~1/500) Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e; GitHub Actions CI (typecheck + 10 offline tests + build)
29 lines
1.1 KiB
TypeScript
29 lines
1.1 KiB
TypeScript
import { app } from 'electron'
|
|
|
|
/**
|
|
* Dev-only environment overrides. A packaged build must ignore these variables
|
|
* even when they are present in its environment: whoever can inject env vars
|
|
* into a launch (a wrapper script, a shortcut, malware with user rights) could
|
|
* otherwise point the renderer — and with it the IPC trust check — at a remote
|
|
* origin, or redirect the update feed to a hostile server.
|
|
*/
|
|
|
|
/**
|
|
* Vite dev server URL, or undefined when the packaged renderer file must be
|
|
* loaded. Packaged builds never honor ELECTRON_RENDERER_URL.
|
|
*/
|
|
export function devRendererUrl(): string | undefined {
|
|
if (app.isPackaged) return undefined
|
|
return process.env['ELECTRON_RENDERER_URL'] || undefined
|
|
}
|
|
|
|
/**
|
|
* Custom update feed URL for development, or undefined to use the production
|
|
* Gitea feed. Packaged builds never honor OT_UPDATE_URL (OT_UPDATE_TOKEN is
|
|
* unrelated and still read from the environment in every build).
|
|
*/
|
|
export function devUpdateFeedUrl(): string | undefined {
|
|
if (app.isPackaged) return undefined
|
|
return process.env['OT_UPDATE_URL'] || undefined
|
|
}
|