CI / lint (push) Successful in 52s
CI / security (push) Successful in 36s
CI / test (push) Successful in 1m6s
CI / build (push) Successful in 1m15s
CI / e2e (push) Failing after 12m40s
Desktop Build / build-windows (push) Canceled after 0s
Desktop Build / build-linux (push) Canceled after 0s
#78 Excalidraw — finitions B5/C8/F2/F3 - backend/indexer.py: port Python pur de lz-string decompressFromBase64 (bitsPerChar=6, resetValue=32) validé contre 4 fixtures JS truth (texte accentué, edge cases) — remplace le stub base64 non-fonctionnel - B5 indexation: .excalidraw.md (format plugin Obsidian) maintenant décompressé côté Python → texte indexé pour recherche TF-IDF - 7 nouveaux tests B5 dans tests/test_excalidraw.py (13/13 total) - F2: excalidraw-viewer.test.mjs enregistré dans CI (lint job) - F3: tests/e2e/excalidraw.spec.js (9 specs — ouverture .excalidraw/.excalidraw.md, création via modale/menu contextuel, toolbar, thème, pop-out, recherche) - Fixtures test_vault/diagram.excalidraw + diagram.excalidraw.md #67 Push notifications (Web Push API + VAPID) - backend/push.py: router + VAPID keys + send_push_notification (pywebpush>=2.3.0) - frontend/js/push.js: subscription UI + service worker integration - tests/test_push.py: 10 tests (subscribe/list/unsubscribe/vapid key) - requirements.txt + sw.js + locales push strings #68 Health check enrichi - backend/main.py: GET /api/health/detailed (admin) — memory/cpu/disk/backups/index/SSE connections - backend/indexer.py: _last_full_index_ts tracking - tests/conftest.py: admin_client fixture - tests/test_api_main.py: 3 nouveaux tests health detailed #77 Desktop jumplist - desktop/src/jumplist.rs: Windows jumplist integration - Cargo.toml/lock + capabilities + main.rs - frontend/js/desktop.js: Tauri bridge (isTauriEnv, invoke, getSystemTheme, syncSystemTheme, shouldShowWizard, crash banner) - tests/frontend/desktop.test.mjs: 21 tests JSDOM (détection, invoke degradation, theme gating, wizard, crash banner) - tests/frontend/unit.test.mjs: desktop.js whitelisted (standalone global reader) # Frontend & CI - frontend/sw.js: réécriture complète (precache + push event handlers + offline) - frontend/index.html: section push dans settings + about repositionné - frontend/js/app.js: initDesktopIntegration + initPush - CI .gitea/workflows/ci.yml: excalidraw-viewer.test.mjs ajouté au lint job All checks: ruff clean, 552 backend tests pass, 9 frontend unit, 5 excalidraw-viewer, 21 desktop, 9 pane-manager, validate-imports 33 modules.
61 lines
2.5 KiB
PowerShell
61 lines
2.5 KiB
PowerShell
#!/usr/bin/env pwsh
|
|
# ObsiGate Desktop — Windows code signing (scaffolding).
|
|
#
|
|
# Signe le binaire et l'installateur MSI/NSIS après un `cargo tauri build`.
|
|
# Aucun certificat n'est embarqué : les identifiants sont lus depuis
|
|
# l'environnement (jamais commités). Le script est un no-op explicite si
|
|
# l'env n'est pas configuré — le build reste donc fonctionnel sans signature.
|
|
#
|
|
# Variables d'environnement :
|
|
# OBSIGATE_SIGN_CERT_PFX chemin du .pfx (requis)
|
|
# OBSIGATE_SIGN_CERT_PASSWORD mot de passe du .pfx (optionnel)
|
|
# OBSIGATE_SIGN_TIMESTAMP_URL URL du serveur d'horodatage RFC3161
|
|
# (défaut : http://timestamp.digicert.com)
|
|
# OBSIGATE_SIGN_MODE "signtool" (Windows) ou "osslsigncode" (Linux)
|
|
#
|
|
# Usage :
|
|
# ./scripts/sign-windows.ps1 # après le build, signe les artefacts
|
|
# OBSIGATE_SIGN_CERT_PFX=cert.pfx ./scripts/sign-windows.ps1
|
|
|
|
$ErrorActionPreference = 'Stop'
|
|
|
|
$pfx = $env:OBSIGATE_SIGN_CERT_PFX
|
|
if (-not $pfx) {
|
|
Write-Host "⚠ Aucun certificat fourni (OBSIGATE_SIGN_CERT_PFX). Signature ignorée — build non signé."
|
|
exit 0
|
|
}
|
|
|
|
$password = $env:OBSIGATE_SIGN_CERT_PASSWORD
|
|
$tsUrl = if ($env:OBSIGATE_SIGN_TIMESTAMP_URL) { $env:OBSIGATE_SIGN_TIMESTAMP_URL } else { 'http://timestamp.digicert.com' }
|
|
$mode = if ($env:OBSIGATE_SIGN_MODE) { $env:OBSIGATE_SIGN_MODE } else { 'signtool' }
|
|
|
|
$targets = @(
|
|
'target/release/obsigate-desktop.exe',
|
|
'target/release/bundle/msi/*.msi',
|
|
'target/release/bundle/nsis/*-setup.exe'
|
|
) | ForEach-Object { Get-Item $_ -ErrorAction SilentlyContinue } | Where-Object { $_ }
|
|
|
|
if ($targets.Count -eq 0) {
|
|
Write-Host "⚠ Aucun artefact à signer trouvé (lancer d'abord `cargo tauri build`)."
|
|
exit 0
|
|
}
|
|
|
|
foreach ($t in $targets) {
|
|
Write-Host "✍ Signature de $($t.FullName) (mode: $mode)"
|
|
if ($mode -eq 'osslsigncode') {
|
|
$args = @('sign', '-pkcs12', $pfx, '-h', 'sha256')
|
|
if ($password) { $args += @('-pass', $password) }
|
|
$args += @('-ts', $tsUrl, '-in', $t.FullName, '-out', $t.FullName)
|
|
& osslsigncode @args
|
|
if ($LASTEXITCODE -ne 0) { throw "osslsigncode a échoué pour $($t.Name)" }
|
|
} else {
|
|
$args = @('sign', '/fd', 'SHA256', '/f', $pfx, '/tr', $tsUrl, '/td', 'SHA256')
|
|
if ($password) { $args += @('/p', $password) }
|
|
$args += $t.FullName
|
|
& signtool @args
|
|
if ($LASTEXITCODE -ne 0) { throw "signtool a échoué pour $($t.Name)" }
|
|
}
|
|
}
|
|
|
|
Write-Host "✅ $($targets.Count) artefact(s) signé(s)."
|