Skip to content

Commit 3ca2a1a

Browse files
author
xlx1212
committed
Merge remote-tracking branch 'origin/main' into pr-2836-merge-main
# Conflicts: # docs/interactive-capabilities/README.md # docs/interactive-capabilities/technical/tauri-command-map.json # src/crates/contracts/product-domains/src/generated/remote-surface-registry.json # src/shared/interactive-capabilities/catalog.json # src/web-ui/src/infrastructure/api/generated/remoteSurface.ts
2 parents c991171 + 339414b commit 3ca2a1a

1,772 files changed

Lines changed: 106494 additions & 29965 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/ci.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -655,6 +655,15 @@ jobs:
655655
if: needs.build-impact.outputs.frontend_required != 'false'
656656
run: pnpm --dir src/mobile-web run type-check
657657

658+
- name: Test mobile web account login and reload
659+
if: needs.build-impact.outputs.frontend_required != 'false'
660+
run: pnpm --dir src/mobile-web run test:account-login
661+
662+
- name: Test mobile web browser account persistence and concurrency
663+
if: needs.build-impact.outputs.frontend_required != 'false'
664+
timeout-minutes: 5
665+
run: pnpm --dir src/mobile-web run test:account-browser
666+
658667
- name: Build mobile web
659668
if: needs.build-impact.outputs.frontend_required != 'false'
660669
run: pnpm run build:mobile-web

‎.github/workflows/desktop-package.yml‎

Lines changed: 72 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -183,24 +183,41 @@ jobs:
183183
- os: windows-latest
184184
name: windows-x64
185185
target: x86_64-pc-windows-msvc
186-
build_command: |
187-
$ErrorActionPreference = 'Stop'
188-
pnpm run desktop:build:nsis --target x86_64-pc-windows-msvc --verbose
189-
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
190-
$desktopExe = "target/x86_64-pc-windows-msvc/release/openbitfun-desktop.exe"
191-
if (-not (Test-Path $desktopExe)) {
192-
throw "Desktop executable was not found after NSIS build: $desktopExe"
193-
}
194-
$env:OPENBITFUN_INSTALLER_APP_EXE = $desktopExe
195-
pnpm run installer:build:only
196-
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
186+
# Compile before opening the short-lived SimplySign session.
187+
build_command: node scripts/desktop-tauri-build.mjs --no-bundle --target x86_64-pc-windows-msvc --verbose
197188

198189
steps:
199190
- name: Checkout
200191
uses: actions/checkout@v5
201192
with:
202193
ref: ${{ needs.prepare.outputs.checkout_ref }}
203194

195+
- name: Check Windows signing configuration
196+
if: runner.os == 'Windows'
197+
id: windows-signing
198+
shell: pwsh
199+
env:
200+
CERTUM_USERNAME: ${{ secrets.CERTUM_USERNAME }}
201+
CERTUM_OTP_URI: ${{ secrets.CERTUM_OTP_URI }}
202+
CERTUM_KEY_ID: ${{ secrets.CERTUM_KEY_ID }}
203+
REQUIRE_SIGNING: ${{ needs.prepare.outputs.upload_to_release }}
204+
run: |
205+
$ErrorActionPreference = 'Stop'
206+
$names = @('CERTUM_USERNAME', 'CERTUM_OTP_URI', 'CERTUM_KEY_ID')
207+
$missing = @($names | Where-Object { [string]::IsNullOrWhiteSpace([Environment]::GetEnvironmentVariable($_)) })
208+
if ($missing.Count -eq 3 -and $env:REQUIRE_SIGNING -ne 'true') {
209+
'enabled=false' >> $env:GITHUB_OUTPUT
210+
Write-Host 'Artifact-only build without Authenticode signing; Certum secrets are not configured.'
211+
} elseif ($missing.Count -gt 0) {
212+
throw "Missing Windows signing secrets: $($missing -join ', '). Release publication requires Authenticode signing."
213+
} else {
214+
$thumbprint = ($env:CERTUM_KEY_ID -replace '\s', '').ToUpperInvariant()
215+
if ($thumbprint -notmatch '^[0-9A-F]{40}$') { throw 'CERTUM_KEY_ID must be a SHA-1 certificate fingerprint.' }
216+
if (-not $env:CERTUM_OTP_URI.StartsWith('otpauth://totp/')) { throw 'CERTUM_OTP_URI must be a TOTP otpauth URI.' }
217+
'enabled=true' >> $env:GITHUB_OUTPUT
218+
"WINDOWS_CERTIFICATE_THUMBPRINT=$thumbprint" >> $env:GITHUB_ENV
219+
}
220+
204221
- name: Install NSIS (Windows)
205222
if: runner.os == 'Windows'
206223
shell: pwsh
@@ -323,6 +340,50 @@ jobs:
323340
- name: Build desktop app
324341
run: ${{ matrix.platform.build_command }}
325342

343+
- name: Connect Certum SimplySign
344+
if: runner.os == 'Windows' && steps.windows-signing.outputs.enabled == 'true'
345+
timeout-minutes: 10
346+
# Pinned immutable revision; this community action automates the Desktop login.
347+
uses: dismine/windows-app-signing-setup-action@89ae3b032d4bc7a5b98d1a42a34e61ecb6faad64
348+
with:
349+
certum-username: ${{ secrets.CERTUM_USERNAME }}
350+
certum-otp-uri: ${{ secrets.CERTUM_OTP_URI }}
351+
certum-key-id: ${{ env.WINDOWS_CERTIFICATE_THUMBPRINT }}
352+
capture-diagnostics: 'false'
353+
354+
- name: Bundle Windows updater and verify Authenticode
355+
if: runner.os == 'Windows'
356+
timeout-minutes: 20
357+
shell: pwsh
358+
run: |
359+
$ErrorActionPreference = 'Stop'
360+
node scripts/desktop-tauri-build.mjs --bundle-only --target x86_64-pc-windows-msvc --bundles nsis --verbose
361+
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
362+
if ($env:WINDOWS_CERTIFICATE_THUMBPRINT) {
363+
# Tauri restores the unsigned raw EXE after bundling; sign it again
364+
# before the custom installer snapshots and hashes its payload.
365+
& ./scripts/ci/sign-windows.ps1 -Path 'target/x86_64-pc-windows-msvc/release/openbitfun-desktop.exe'
366+
$installers = @(Get-ChildItem 'target/x86_64-pc-windows-msvc/release/bundle/nsis/*.exe' -File)
367+
if ($installers.Count -eq 0) { throw 'NSIS installer was not produced.' }
368+
foreach ($installer in $installers) {
369+
& ./scripts/ci/sign-windows.ps1 -Path $installer.FullName -VerifyOnly
370+
}
371+
}
372+
373+
- name: Build and sign custom Windows installer
374+
if: runner.os == 'Windows'
375+
timeout-minutes: 60
376+
shell: pwsh
377+
run: |
378+
$ErrorActionPreference = 'Stop'
379+
# The payload manifest must hash the already signed desktop executable.
380+
$env:OPENBITFUN_INSTALLER_APP_EXE = 'target/x86_64-pc-windows-msvc/release/openbitfun-desktop.exe'
381+
pnpm run installer:build:only
382+
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
383+
if ($env:WINDOWS_CERTIFICATE_THUMBPRINT) {
384+
& ./scripts/ci/sign-windows.ps1 -Path 'OpenBitFun-Installer/src-tauri/target/release/openbitfun-installer.exe'
385+
}
386+
326387
- name: Verify Apple signature and notarization
327388
if: runner.os == 'macOS'
328389
shell: bash
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
name: Windows Signing Checks
2+
3+
on:
4+
pull_request:
5+
paths:
6+
- '.github/workflows/desktop-package.yml'
7+
- '.github/workflows/windows-signing-checks.yml'
8+
- 'scripts/ci/sign-windows*.ps1'
9+
- 'scripts/desktop-tauri-build*.mjs'
10+
push:
11+
branches: [main]
12+
paths:
13+
- '.github/workflows/desktop-package.yml'
14+
- '.github/workflows/windows-signing-checks.yml'
15+
- 'scripts/ci/sign-windows*.ps1'
16+
- 'scripts/desktop-tauri-build*.mjs'
17+
18+
permissions:
19+
contents: read
20+
21+
jobs:
22+
signing-contracts:
23+
runs-on: windows-latest
24+
timeout-minutes: 5
25+
steps:
26+
- uses: actions/checkout@v5
27+
- uses: actions/setup-node@v5
28+
with:
29+
node-version: 22
30+
package-manager-cache: false
31+
- name: Test Tauri signing configuration
32+
run: node --test scripts/desktop-tauri-build.test.mjs
33+
- name: Test signing failure handling without credentials
34+
shell: pwsh
35+
run: ./scripts/ci/sign-windows.test.ps1

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,3 +125,6 @@ src/apps/mobile/android/.kotlin/
125125
# Downloaded Flashgrep release assets (metadata stays tracked).
126126
/resources/flashgrep/flashgrep-*
127127
/resources/flashgrep/*.download-*
128+
129+
# Local generated workspace output.
130+
/output/

‎.release-please-manifest.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
{
2-
".": "1.0.0-beta"
2+
".": "1.0.0"
33
}

0 commit comments

Comments
 (0)