Skip to content

Latest commit

 

History

History
67 lines (61 loc) · 5.36 KB

File metadata and controls

67 lines (61 loc) · 5.36 KB

Folder Structure

Push Latte v2 is a pnpm/TypeScript monorepo (see pnpm-workspace.yaml). The v1 vanilla-JS single-page app that used to live at the repo root was removed in M8.

psdlat/
├── packages/
│   ├── core/                     # @psdlat/core — DOM-free domain logic
│   │   └── src/
│   │       ├── automation/       # source identity, encrypted provisioning, invite codec, send-envelope policy
│   │       ├── crypto/           # identity, envelope v2, fingerprint, SAS, replay, canonical, recovery-kit
│   │       ├── net/              # connection-engine (reconnect FSM), turn, lifecycle, ws/p2p wire
│   │       ├── p2p/              # PeerLink over trystero-over-DO strategy, signaling, mesh-strategy
│   │       ├── store/            # IndexedDB identity/peer/automation/inbox/outbox/replay stores, outbox-runner
│   │       ├── protocol/         # frames, automation constants/types, codec, delivery-state machine
│   │       ├── pairing/          # commit-reveal SAS pairing state machine
│   │       └── files/            # chunker, incremental hash (hash-wasm), OPFS store, transfer, R2 pointer
│   ├── ui/                       # @psdlat/ui — presentation system
│   │   └── src/                  # tokens.css, fonts.css (self-hosted), theme.ts, components/, icons/, i18n/, dom/
│   └── automation-agent/         # @psdlat/automation-agent — local E2EE send-only integration
│       ├── src/                  # CLI, claim/send agent, config + retry stores, authenticated loopback API
│       │   └── mcp/              # stdio MCP plus optional OAuth/OIDC-protected HTTP MCP
│       └── test/                 # claim/send, storage, SSRF, loopback, OAuth, and MCP contracts
├── apps/
│   ├── pwa/                      # @psdlat/pwa — installable PWA (Vite + vite-plugin-pwa)
│   │   ├── src/app/              # boot/shell, messaging/files, pairing, onboarding, automation-channel UI/API
│   │   ├── src/                  # main.ts, sw.ts (service worker), share-target, marketing/ (landing pages)
│   │   └── public/               # _headers (CSP source-of-truth mirror), icons/, manifest assets
│   ├── extension/                # @psdlat/extension — Chrome MV3 (WXT)
│   │   ├── entrypoints/          # background SW, offscreen engine host, popup, side panel, options
│   │   └── lib/                  # engine/bus/notify plus offscreen automation keys/API and shared channel UI
│   └── android/                  # @psdlat/android — Capacitor shell around the PWA bundle
│       ├── android/              # generated native Gradle project; app/src/main/java/lat/psh/app/
│       │                         #   holds Billing/FileSave/ShareIntake/TransferService + FCM
│       ├── scripts/              # build-apk / build-aab / build-play-release / verify-bundle
│       ├── store-assets/         # Play listing graphics and copy
│       └── test/                 # packaging pins only — capacitor config, manifest hardening,
│                                 #   release wiring, and the bundle validator (skipped without a bundle)
├── worker/                       # @psdlat/worker — Cloudflare Worker
│   └── src/                      # router, SQLite MeshDO/mailbox, automation control/send API, turn, push, r2, headers, locale
├── docs/                         # product, UX, design bible, security (threat model/privacy), strategy
│   └── spikes/                   # throwaway PoCs, kept for their findings — excluded from build/lint/test
├── e2e/ · visual-tests/          # manual Playwright release tiers; neither is part of `pnpm test`
├── wrangler.jsonc                # production psdlat Worker + PWA assets, MeshDO, R2
├── pnpm-workspace.yaml · tsconfig.base.json · eslint.config.js · vitest.config.ts

Ownership boundaries

  • packages/core is DOM-free and platform-agnostic (crypto/transport/store must not touch the DOM); all clients and the Worker consume its permitted entry points.
  • Presentation (tokens, components, theme) lives in packages/ui; the design contract is docs/design-bible.md.
  • packages/automation-agent is a local send-only integration. A hosted relay must never terminate its plaintext or credentials.
  • Automation receiver trust is owned by each target client in a separate local source-pin store; it is never merged into the paired-device roster.
  • The typed CSP/security-header source of truth is worker/src/security-headers.ts (mirrored into apps/pwa/public/_headers).
  • The Chrome MV3 SW must stay engine-free (WebRTC/OPFS/wasm live only in the offscreen document) — see docs/chrome-extension-constraints.md.
  • Deploy is push-driven from main to the psdlat Worker; there is exactly one worker (worker/) and one service worker per app.

Browser release tiers

  • e2e/ — Playwright coverage for the built extension, WebRTC pairing, OPFS, share-target behavior, and service-worker registration. Run with pnpm e2e.
  • visual-tests/ — committed PWA, marketing, and extension baselines. Run with pnpm e2e:visual.

These are local release gates. pnpm test remains the simulated-DOM/unit tier; run all three commands before a release push.