Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,6 +87,7 @@ jobs:
- uses: dtolnay/rust-toolchain@master
with:
toolchain: ${{ env.RUST_TOOLCHAIN }}
components: rustfmt, clippy

- uses: swatinem/rust-cache@v2
with:
Expand Down
36 changes: 1 addition & 35 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,12 +78,6 @@ jobs:
- name: Release preflight
run: node ./scripts/release-preflight.mjs --release-tag "$RELEASE_TAG"

- name: Allow unsigned prerelease installer
if: runner.os == 'Windows' && contains(env.RELEASE_TAG, '-')
run: |
echo "USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1" >> "$GITHUB_ENV"
echo "Prerelease $RELEASE_TAG will publish an unsigned Windows installer until Authenticode signing is configured."

- name: Verify updater signing key is configured
if: runner.os == 'Windows' && !contains(env.RELEASE_TAG, '-')
env:
Expand All @@ -100,34 +94,6 @@ jobs:
echo "No Tauri updater signing key configured; publishing this technical-preview installer without updater signatures."
echo "USAGEBAR_ALLOW_UNSIGNED_UPDATER=1" >> "$GITHUB_ENV"

- name: Verify Windows Authenticode signing secrets are configured
if: runner.os == 'Windows'
env:
WINDOWS_CERTIFICATE_BASE64: ${{ secrets.WINDOWS_CERTIFICATE_BASE64 }}
WINDOWS_CERTIFICATE: ${{ secrets.WINDOWS_CERTIFICATE }}
WINDOWS_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_CERTIFICATE_PASSWORD }}
WINDOWS_CERTIFICATE_THUMBPRINT: ${{ secrets.WINDOWS_CERTIFICATE_THUMBPRINT }}
USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER: ${{ env.USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER }}
run: |
if [[ "$USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER" == "1" ]]; then
echo "Skipping Authenticode secret requirement for unsigned prerelease installer."
exit 0
fi

if [[ -n "$WINDOWS_CERTIFICATE_THUMBPRINT" ]]; then
exit 0
fi

if [[ -z "$WINDOWS_CERTIFICATE_BASE64" && -z "$WINDOWS_CERTIFICATE" ]]; then
echo "Missing Windows Authenticode certificate secret. Set WINDOWS_CERTIFICATE_BASE64."
exit 1
fi

if [[ -z "$WINDOWS_CERTIFICATE_PASSWORD" ]]; then
echo "Missing WINDOWS_CERTIFICATE_PASSWORD secret."
exit 1
fi

- uses: tauri-apps/tauri-action@v0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -139,7 +105,7 @@ jobs:
WINDOWS_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_CERTIFICATE_PASSWORD }}
WINDOWS_CERTIFICATE_THUMBPRINT: ${{ secrets.WINDOWS_CERTIFICATE_THUMBPRINT }}
WINDOWS_TIMESTAMP_URL: ${{ secrets.WINDOWS_TIMESTAMP_URL }}
USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER: ${{ env.USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER }}
USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER: "1"
with:
tagName: ${{ env.RELEASE_TAG }}
releaseName: ${{ env.RELEASE_TAG }}
Expand Down
36 changes: 36 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,41 @@
# Changelog

## 0.1.1

### Highlights

- Corrected the stable release version so Alpha 8 can detect and install it.
- Kept the signed updater metadata and Windows installer release path from v0.0.1.

### Notes

- Windows installers remain unsigned until the project gets an Authenticode certificate. Windows can show `Unknown publisher` or SmartScreen warnings.
- Stable releases use signed Tauri updater metadata.

## 0.0.1

### Highlights

- Added a complete in-app update flow that downloads the Windows installer, verifies it, restarts the app, and removes stale uninstall entries.
- Added managed accounts for supported providers and moved OpenCode Go usage to its official usage endpoint.
- Added usage-event notifications with duplicate protection and clearer quota, incident, and recovery alerts.
- Improved usage history with accurate token totals, explicit unknown totals, and a clearer empty state.
- Added a reset-all-settings action and reduced repeated copy across Settings.
- Improved tray behavior with stable resize anchoring, provider scroll hints, and the correct OpenAI API icon.

### Reliability and security

- Limited provider probe execution and shared local ccusage results across each refresh batch.
- Enforced deny-by-default plugin capabilities and updated vulnerable dependencies.
- Added dependency audits and more reliable security reporting to CI.
- Improved keyboard control semantics, accessible names, async feedback announcements, contrast, and reduced-motion behavior.
- Expanded interaction coverage and enforced changed-line coverage for executable code.

### Notes

- Windows installers remain unsigned until the project gets an Authenticode certificate. Windows can show `Unknown publisher` or SmartScreen warnings.
- Stable releases still use signed Tauri updater metadata.

## 0.1.0-alpha.8

### Highlights
Expand Down
27 changes: 12 additions & 15 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Status meanings:
| [**MiniMax**](docs/providers/minimax.md) | Experimental | Coding Plan session usage, explicit reported plan when available |
| [**Mistral**](docs/providers/mistral.md) | Experimental | La Plateforme usage and billing details via official Admin API key, with session-cookie fallback |
| [**Ollama**](docs/providers/ollama.md) | Supported | Plan, session, weekly |
| [**OpenCode**](docs/providers/opencode-go.md) | Supported | OpenCode Go account-wide 5h, weekly, and monthly quota from the official usage API; local history and optional OpenCode Zen balance |
| [**OpenCode**](docs/providers/opencode-go.md) | Supported | OpenCode Go account-wide 5h, weekly, and monthly quota from the official usage API; local history and optional OpenCode Zen balance |
| [**OpenAI API**](docs/providers/openai-api.md) | Experimental | Organization API spend windows, completions tokens, requests, and top model from the OpenAI Admin API |
| [**OpenRouter**](docs/providers/openrouter.md) | Experimental | Credits, balance, request-rate detail |
| [**Perplexity**](docs/providers/perplexity.md) | Experimental | Recurring, purchased, and bonus credit pools via manual cookie/env auth |
Expand All @@ -72,15 +72,17 @@ UsageBar sits in your Windows tray and gives you one quick view of your AI codin

You can also read cached usage locally through the [HTTP API](docs/local-http-api.md) or [CLI](docs/cli.md), review supported history/reporting, manage credentials, and configure quota notifications.

## Alpha Readiness And Current Limitations
## Current Limitations

UsageBar is still pre-release. Alpha 8 is intended to let Windows users install from GitHub, enable supported providers, refresh usage, inspect local history/reporting, manage credentials, and configure local quota notifications. The installer is unsigned; Authenticode signing is deferred.
UsageBar v0.1.1 is a Windows-first public release.

- Windows installers are unsigned until Authenticode signing is configured. Windows can show `Unknown publisher` or SmartScreen warnings.
- We welcome provider feedback about setup, usage data, and account support.
- Windows is the primary tested platform for this fork. macOS and Linux remain secondary until the Windows release path is boring.
- Provider coverage is uneven: `Supported` means the Windows path is intended to work; `Experimental` means setup, API shape, or live-account validation may still change.
- Some providers report usage directly; others estimate from local history, known quota pools, telemetry logs, or manually supplied session cookies. Provider docs describe the source per integration.
- Prerelease auto-updates use the GitHub release API when signed Tauri updater metadata is not available. UsageBar verifies the published asset digest, downloads the Windows installer, then restarts after the app exits.
- Authenticode-signed Windows artifacts, live Edge-account validation, and full crash-recovery expectations are full-release work, not an Alpha 8 promise.
- Signed updater metadata is the primary update path. UsageBar verifies the published asset digest, downloads the Windows installer, then restarts after the app exits.
- Authenticode-signed Windows artifacts, live Edge-account validation, and full crash-recovery expectations remain future work.

## Architecture

Expand All @@ -105,14 +107,9 @@ UsageBar is local-first. App settings, provider order, display preferences, and
- Telemetry uses the app's analytics integration only for product diagnostics; provider usage payloads and credentials are not telemetry data.
- Crash logs are local support artifacts under `%LOCALAPPDATA%\com.sunstory.usagebar` unless a user explicitly attaches sanitized logs to a report. Automatic crash upload is not part of the Alpha 1 promise.

## Fork Direction

This repository is no longer trying to stay narrowly aligned with upstream pull-request boundaries. The priority here is a clean Windows tray app, a plugin-first provider model, and pragmatic product decisions for this fork.

That means the fork can change UX, provider strategy, release packaging, and architecture when that is the right tradeoff for Windows.

## Contributing

- **Experimental providers.** Since they are in an experimental phase, we welcome feedback on your experience.
- **Add a provider.** Each one is just a plugin. See the [Plugin API](docs/plugins/api.md).
- **Read usage locally.** See the [Local HTTP API](docs/local-http-api.md).
- **Use terminal output.** See the [UsageBar CLI](docs/cli.md).
Expand Down Expand Up @@ -159,16 +156,16 @@ bun run test -- --run

### Local release build

For a Windows prerelease build on this machine:
For a Windows release build on this machine:

```bash
bun run release:check -- --release-tag v0.1.0-alpha.8
bun run release:check -- --release-tag v0.1.1
bun run build:release -- --bundles nsis
```

If `TAURI_SIGNING_PRIVATE_KEY` is unset, the helper automatically adds `--no-sign` so the local build can skip Tauri updater signatures. Windows installer builds require Authenticode material by default: `WINDOWS_CERTIFICATE_BASE64` plus `WINDOWS_CERTIFICATE_PASSWORD`, `WINDOWS_CERTIFICATE`, or `WINDOWS_CERTIFICATE_THUMBPRINT`. The helper signs the final setup executable after the build so the Windows launch prompt can show the certificate publisher. The setup executable lands under `src-tauri/target/release/bundle/nsis/`.
If `TAURI_SIGNING_PRIVATE_KEY` is unset, the helper automatically adds `--no-sign` so the local build can skip Tauri updater signatures. Set `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1` for local builds without an Authenticode certificate. The helper signs the final setup executable when Windows signing material exists. The setup executable lands under `src-tauri/target/release/bundle/nsis/`.

For Alpha 8 unsigned technical-preview builds, set `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1`; those installers can show `Unknown publisher` and trigger Windows SmartScreen's "unrecognized app" warning. Stable/public-confidence Windows builds should be Authenticode-signed; see [docs/releasing.md](docs/releasing.md).
GitHub publishes unsigned Windows installers until the project gets an Authenticode certificate. These installers can show `Unknown publisher` and trigger Windows SmartScreen's "unrecognized app" warning. Stable releases still require signed Tauri updater metadata; see [docs/releasing.md](docs/releasing.md).

Before pushing a release tag, run the same preflight with `--require-clean` so the tag is cut from a clean worktree.

Expand Down
37 changes: 19 additions & 18 deletions docs/releasing.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,22 +2,18 @@

This repo treats a release as a tagged, reproducible build with matching version metadata, current release notes, and a verified artifact path.

The next stranger-facing milestone should be an alpha, not a full release, unless the installer, updater, provider setup, privacy/telemetry copy, error states, docs, feedback path, and recovery behavior have all been verified end to end.

Current alpha label:
Current release:

```text
v0.1.0-alpha.8
v0.1.1
```

If the repo stays on the existing beta line instead, document the reason in `CHANGELOG.md` and release notes before tagging.

## Preflight

Before cutting a tag:

```bash
bun run release:check -- --release-tag v0.1.0-alpha.8 --require-clean
bun run release:check -- --release-tag v0.1.1 --require-clean
```

The preflight currently verifies:
Expand All @@ -32,55 +28,60 @@ The preflight currently verifies:

Build the Windows installer locally before the first publish of a version:

```bash
```powershell
$env:USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER = "1"
bun run build:release -- --bundles nsis
```

If `TAURI_SIGNING_PRIVATE_KEY` is unset, the helper automatically adds `--no-sign` so local builds can still complete without Tauri updater signatures. Windows installer builds require Authenticode material by default. When that material is configured, the helper signs the final NSIS/MSI artifact after the build so the setup executable has a real publisher.

Alpha 8 exception: unsigned Windows prerelease installers are allowed as technical-preview artifacts while Authenticode signing is deferred. Set `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1` for local unsigned builds. GitHub prerelease publishes set this automatically for tags that contain a prerelease suffix such as `v0.1.0-alpha.8`. These artifacts can show `Unknown publisher`, can trigger Windows SmartScreen's "unrecognized app" warning, and must be described as unsigned in release notes.
If `TAURI_SIGNING_PRIVATE_KEY` is unset, the helper automatically adds `--no-sign` so local builds can complete without Tauri updater signatures. Local Windows builds need an explicit unsigned-build opt-in when no Authenticode material exists. GitHub publishes set this option for prerelease and stable tags. Unsigned artifacts can show `Unknown publisher` and can trigger Windows SmartScreen's "unrecognized app" warning.

## Windows Code Signing

Windows release artifacts need two separate signatures:
Windows release artifacts support two separate signatures:

- Tauri updater signatures: `TAURI_SIGNING_PRIVATE_KEY` and optional `TAURI_SIGNING_PRIVATE_KEY_PASSWORD`.
- Windows Authenticode signatures: `WINDOWS_CERTIFICATE_BASE64` plus `WINDOWS_CERTIFICATE_PASSWORD`, or an already-installed certificate selected by `WINDOWS_CERTIFICATE_THUMBPRINT`.

`src-tauri/tauri.conf.json` calls [scripts/sign-windows.ps1](../scripts/sign-windows.ps1) through Tauri's Windows `signCommand`. `scripts/build-release.mjs` also runs the same script over generated NSIS/MSI artifacts after local builds when Windows signing material exists. In CI and locally, unsigned Windows installer builds require `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1`; otherwise missing Authenticode material is a hard failure.
`src-tauri/tauri.conf.json` calls [scripts/sign-windows.ps1](../scripts/sign-windows.ps1) through Tauri's Windows `signCommand`. `scripts/build-release.mjs` also runs the script over generated NSIS/MSI artifacts after local builds when Windows signing material exists. GitHub publishes set `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1`. Local unsigned builds must set it explicitly.

Recommended GitHub secrets:
Optional GitHub secrets:

- `WINDOWS_CERTIFICATE_BASE64`: base64-encoded `.pfx` code-signing certificate.
- `WINDOWS_CERTIFICATE_PASSWORD`: `.pfx` export password.
- `WINDOWS_TIMESTAMP_URL`: optional timestamp server; defaults to `http://timestamp.digicert.com`.

SmartScreen note: Authenticode signing is necessary but not always sufficient. EV certificates usually get immediate SmartScreen reputation. OV certificates and new certificates can still warn until Microsoft has enough reputation for the certificate or submitted binary.

## Stable Release Gate

Authenticode is not a stable-release gate while the project has no Windows code-signing certificate. Stable releases still require signed Tauri updater metadata.

The [v0.1.1 installer smoke-test record](testing/installer-smoke-test-0.1.1.md) must identify the exact installer. Include its SHA-256, signature state, source commit, and release URL. Record install, launch, update, CLI, and uninstall results from that file. Release notes must state that `Unknown publisher` and SmartScreen warnings can occur.

## GitHub Publish

The publish workflow lives in [.github/workflows/publish.yml](../.github/workflows/publish.yml).

You can publish in two ways:

1. Push a `v*` tag, for example `v0.1.0-alpha.8`
1. Push a `v*` tag, for example `v0.1.1`
2. Trigger `Publish` manually with `workflow_dispatch` and provide `release_tag`

The workflow runs the same release preflight, builds platform artifacts, and verifies that the GitHub release contains:

- a Windows setup executable ending in `setup.exe`

Stable releases require `TAURI_SIGNING_PRIVATE_KEY` and updater signature assets. For prerelease tags, the workflow passes `--no-sign` when that key is unavailable and publishes an unsigned technical-preview installer without updater assets. Prerelease tags also set `USAGEBAR_ALLOW_UNSIGNED_WINDOWS_INSTALLER=1` so Authenticode signing remains optional.
Stable releases require `TAURI_SIGNING_PRIVATE_KEY` and updater signature assets. For prerelease tags, the workflow passes `--no-sign` and publishes without updater assets. All Windows publishes allow an unsigned installer while Authenticode signing remains unavailable.

Current updater channel note:

- Signed Tauri updater metadata is the primary update path.
- GitHub's `releases/latest` alias does not resolve prereleases, so UsageBar queries the release API when a prerelease has no signed updater metadata.
- The Windows fallback accepts only the exact `UsageBar_<version>_x64-setup.exe` asset and verifies GitHub's SHA-256 digest before installation.

## Alpha Gate
## Release Gate

Before publishing Alpha 8, verify and record:
Before publishing v0.1.1, verify and record:

- Windows installer exists as a GitHub release asset or local NSIS artifact.
- If the installer is unsigned, release notes must say `Unknown publisher` / SmartScreen warnings are expected for this technical preview.
Expand Down
Loading
Loading