mirror of
https://github.com/NanmiCoder/claude-code-haha.git
synced 2026-10-10 11:53:10 +08:00
fix: finalize Electron migration boundaries
Complete the Electron replacement boundary before merging by removing the renderer-side Tauri host fallback, tightening H5/browser access so only desktop navigation is tokenless, and moving desktop release publication to a tag-driven GitHub Actions matrix with a single final publish job. Constraint: H5/browser capability access must not gain tokenless access through localhost or retired Tauri origins Constraint: Desktop release artifacts must be built by GitHub Actions from version tags, not treated as local build outputs Rejected: Keep localhost browser origins trusted for convenience | local browser contexts can access loopback services and must use the H5 token path Rejected: Publish from each matrix job | partial releases can be created before all platforms finish Confidence: high Scope-risk: broad Directive: Do not reintroduce Tauri origins or localhost browser origins into the trusted desktop origin set without a reviewed security design Tested: bun test src/server/__tests__/h5-access-policy.test.ts src/server/__tests__/h5-access-auth.test.ts src/server/__tests__/diagnostics-service.test.ts src/server/middleware/cors.test.ts Tested: bun test scripts/pr/release-workflow.test.ts scripts/release-update-metadata.test.ts Tested: bun run check:desktop Tested: bun run check:native Tested: git diff --check Not-tested: bun run check:server is blocked by expired quarantine entries server:cron-scheduler, server:providers-real, server:tasks, server:e2e:business-flow, server:e2e:full-flow
This commit is contained in:
@@ -134,22 +134,6 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Load release notes
|
||||
id: release_notes
|
||||
shell: bash
|
||||
run: |
|
||||
NOTES_FILE="release-notes/v${{ steps.version.outputs.value }}.md"
|
||||
if [ ! -f "$NOTES_FILE" ]; then
|
||||
echo "::error::Missing release notes file: $NOTES_FILE"
|
||||
exit 1
|
||||
fi
|
||||
{
|
||||
echo 'body<<__RELEASE_NOTES__'
|
||||
cat "$NOTES_FILE"
|
||||
echo
|
||||
echo '__RELEASE_NOTES__'
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Install Linux dependencies
|
||||
if: contains(matrix.platform, 'ubuntu')
|
||||
run: |
|
||||
@@ -210,6 +194,69 @@ jobs:
|
||||
if: matrix.smoke_platform == 'macos'
|
||||
run: bun run test:package-smoke --platform macos --package-kind release --artifacts-dir desktop/build-artifacts/electron --require-macos-gatekeeper
|
||||
|
||||
- name: Validate matrix release asset set
|
||||
shell: bash
|
||||
working-directory: desktop/build-artifacts/electron
|
||||
env:
|
||||
APP_VERSION: ${{ steps.version.outputs.value }}
|
||||
run: |
|
||||
case "${{ matrix.label }}" in
|
||||
macOS-ARM64)
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.dmg"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.dmg.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.zip"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.zip.blockmap"
|
||||
"latest-mac.yml"
|
||||
)
|
||||
;;
|
||||
macOS-x64)
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.dmg"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.dmg.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.zip"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.zip.blockmap"
|
||||
"latest-mac.yml"
|
||||
)
|
||||
;;
|
||||
Linux-x64)
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.AppImage"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.AppImage.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.deb"
|
||||
"latest-linux.yml"
|
||||
)
|
||||
;;
|
||||
Linux-ARM64)
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.AppImage"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.AppImage.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.deb"
|
||||
"latest-linux.yml"
|
||||
)
|
||||
;;
|
||||
Windows-x64)
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-win-x64.exe"
|
||||
"Claude-Code-Haha-${APP_VERSION}-win-x64.exe.blockmap"
|
||||
"latest.yml"
|
||||
)
|
||||
;;
|
||||
*)
|
||||
echo "::error::No expected asset list for matrix label ${{ matrix.label }}"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
missing=()
|
||||
for file in "${expected[@]}"; do
|
||||
[ -f "$file" ] || missing+=("$file")
|
||||
done
|
||||
if [ "${#missing[@]}" -gt 0 ]; then
|
||||
printf '::error::Missing release assets for %s: %s\n' "${{ matrix.label }}" "${missing[*]}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Namespace update metadata assets
|
||||
shell: bash
|
||||
working-directory: desktop/build-artifacts/electron
|
||||
@@ -226,15 +273,11 @@ jobs:
|
||||
path: desktop/build-artifacts/electron/latest*.yml
|
||||
if-no-files-found: ignore
|
||||
|
||||
- name: Upload artifacts
|
||||
uses: softprops/action-gh-release@v2
|
||||
- name: Upload release artifacts for final publish
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
tag_name: v${{ steps.version.outputs.value }}
|
||||
name: Claude Code Haha v${{ steps.version.outputs.value }}
|
||||
body: ${{ steps.release_notes.outputs.body }}
|
||||
draft: ${{ github.event_name == 'workflow_dispatch' && inputs.draft || false }}
|
||||
prerelease: false
|
||||
files: |
|
||||
name: desktop-release-artifacts-${{ matrix.label }}
|
||||
path: |
|
||||
desktop/build-artifacts/electron/*.dmg
|
||||
desktop/build-artifacts/electron/*.zip
|
||||
desktop/build-artifacts/electron/*.exe
|
||||
@@ -242,8 +285,9 @@ jobs:
|
||||
desktop/build-artifacts/electron/*.deb
|
||||
desktop/build-artifacts/electron/*.blockmap
|
||||
desktop/build-artifacts/electron/*.yml
|
||||
if-no-files-found: error
|
||||
|
||||
publish-update-metadata:
|
||||
publish-release:
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
@@ -258,6 +302,32 @@ jobs:
|
||||
VERSION=$(node -p "require('./desktop/package.json').version")
|
||||
echo "value=$VERSION" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Validate tag matches version
|
||||
if: github.event_name == 'push'
|
||||
shell: bash
|
||||
run: |
|
||||
EXPECTED_TAG="v${{ steps.version.outputs.value }}"
|
||||
if [ "${GITHUB_REF_NAME}" != "$EXPECTED_TAG" ]; then
|
||||
echo "::error::Tag ${GITHUB_REF_NAME} does not match app version ${EXPECTED_TAG}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Load release notes
|
||||
id: release_notes
|
||||
shell: bash
|
||||
run: |
|
||||
NOTES_FILE="release-notes/v${{ steps.version.outputs.value }}.md"
|
||||
if [ ! -f "$NOTES_FILE" ]; then
|
||||
echo "::error::Missing release notes file: $NOTES_FILE"
|
||||
exit 1
|
||||
fi
|
||||
{
|
||||
echo 'body<<__RELEASE_NOTES__'
|
||||
cat "$NOTES_FILE"
|
||||
echo
|
||||
echo '__RELEASE_NOTES__'
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Setup Bun
|
||||
uses: oven-sh/setup-bun@v2
|
||||
with:
|
||||
@@ -266,6 +336,46 @@ jobs:
|
||||
- name: Install root dependencies
|
||||
run: bun install
|
||||
|
||||
- name: Download release artifacts
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: desktop-release-artifacts-*
|
||||
path: artifacts/release-assets
|
||||
merge-multiple: true
|
||||
|
||||
- name: Validate complete release asset set
|
||||
shell: bash
|
||||
env:
|
||||
APP_VERSION: ${{ steps.version.outputs.value }}
|
||||
run: |
|
||||
expected=(
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.dmg"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.dmg.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.zip"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-arm64.zip.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.dmg"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.dmg.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.zip"
|
||||
"Claude-Code-Haha-${APP_VERSION}-mac-x64.zip.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.AppImage"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.AppImage.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-x64.deb"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.AppImage"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.AppImage.blockmap"
|
||||
"Claude-Code-Haha-${APP_VERSION}-linux-arm64.deb"
|
||||
"Claude-Code-Haha-${APP_VERSION}-win-x64.exe"
|
||||
"Claude-Code-Haha-${APP_VERSION}-win-x64.exe.blockmap"
|
||||
)
|
||||
|
||||
missing=()
|
||||
for file in "${expected[@]}"; do
|
||||
[ -f "artifacts/release-assets/$file" ] || missing+=("$file")
|
||||
done
|
||||
if [ "${#missing[@]}" -gt 0 ]; then
|
||||
printf '::error::Missing complete release assets: %s\n' "${missing[*]}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Download update metadata artifacts
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
@@ -276,10 +386,38 @@ jobs:
|
||||
- name: Merge standard update metadata
|
||||
run: bun run scripts/release-update-metadata.ts --metadata-dir artifacts/update-metadata --out-dir artifacts/update-metadata-standard
|
||||
|
||||
- name: Upload standard update metadata
|
||||
- name: Validate standard update metadata set
|
||||
shell: bash
|
||||
run: |
|
||||
expected=(
|
||||
"latest-mac.yml"
|
||||
"latest-linux.yml"
|
||||
"latest-linux-arm64.yml"
|
||||
"latest.yml"
|
||||
)
|
||||
missing=()
|
||||
for file in "${expected[@]}"; do
|
||||
[ -f "artifacts/update-metadata-standard/$file" ] || missing+=("$file")
|
||||
done
|
||||
if [ "${#missing[@]}" -gt 0 ]; then
|
||||
printf '::error::Missing standard update metadata: %s\n' "${missing[*]}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Publish complete GitHub release
|
||||
uses: softprops/action-gh-release@v2
|
||||
with:
|
||||
tag_name: v${{ steps.version.outputs.value }}
|
||||
name: Claude Code Haha v${{ steps.version.outputs.value }}
|
||||
body: ${{ steps.release_notes.outputs.body }}
|
||||
draft: ${{ github.event_name == 'workflow_dispatch' && inputs.draft || false }}
|
||||
prerelease: false
|
||||
files: artifacts/update-metadata-standard/*.yml
|
||||
fail_on_unmatched_files: true
|
||||
files: |
|
||||
artifacts/release-assets/**/*.dmg
|
||||
artifacts/release-assets/**/*.zip
|
||||
artifacts/release-assets/**/*.exe
|
||||
artifacts/release-assets/**/*.AppImage
|
||||
artifacts/release-assets/**/*.deb
|
||||
artifacts/release-assets/**/*.blockmap
|
||||
artifacts/update-metadata-standard/*.yml
|
||||
|
||||
Reference in New Issue
Block a user