Files
ObsiGate/desktop/scripts/sign-windows.ps1
T
bruno ac16fc1f0e
CI / lint (push) Successful in 52s
CI / security (push) Successful in 36s
CI / test (push) Successful in 1m6s
CI / build (push) Successful in 1m15s
CI / e2e (push) Failing after 12m40s
Desktop Build / build-windows (push) Canceled after 0s
Desktop Build / build-linux (push) Canceled after 0s
feat: #78 Excalidraw finitions + #67 push + #68 health-detailed + #77 desktop jumplist
#78 Excalidraw — finitions B5/C8/F2/F3
- backend/indexer.py: port Python pur de lz-string decompressFromBase64 (bitsPerChar=6, resetValue=32) validé contre 4 fixtures JS truth (texte accentué, edge cases) — remplace le stub base64 non-fonctionnel
- B5 indexation: .excalidraw.md (format plugin Obsidian) maintenant décompressé côté Python → texte indexé pour recherche TF-IDF
- 7 nouveaux tests B5 dans tests/test_excalidraw.py (13/13 total)
- F2: excalidraw-viewer.test.mjs enregistré dans CI (lint job)
- F3: tests/e2e/excalidraw.spec.js (9 specs — ouverture .excalidraw/.excalidraw.md, création via modale/menu contextuel, toolbar, thème, pop-out, recherche)
- Fixtures test_vault/diagram.excalidraw + diagram.excalidraw.md

#67 Push notifications (Web Push API + VAPID)
- backend/push.py: router + VAPID keys + send_push_notification (pywebpush>=2.3.0)
- frontend/js/push.js: subscription UI + service worker integration
- tests/test_push.py: 10 tests (subscribe/list/unsubscribe/vapid key)
- requirements.txt + sw.js + locales push strings

#68 Health check enrichi
- backend/main.py: GET /api/health/detailed (admin) — memory/cpu/disk/backups/index/SSE connections
- backend/indexer.py: _last_full_index_ts tracking
- tests/conftest.py: admin_client fixture
- tests/test_api_main.py: 3 nouveaux tests health detailed

#77 Desktop jumplist
- desktop/src/jumplist.rs: Windows jumplist integration
- Cargo.toml/lock + capabilities + main.rs
- frontend/js/desktop.js: Tauri bridge (isTauriEnv, invoke, getSystemTheme, syncSystemTheme, shouldShowWizard, crash banner)
- tests/frontend/desktop.test.mjs: 21 tests JSDOM (détection, invoke degradation, theme gating, wizard, crash banner)
- tests/frontend/unit.test.mjs: desktop.js whitelisted (standalone global reader)

# Frontend & CI
- frontend/sw.js: réécriture complète (precache + push event handlers + offline)
- frontend/index.html: section push dans settings + about repositionné
- frontend/js/app.js: initDesktopIntegration + initPush
- CI .gitea/workflows/ci.yml: excalidraw-viewer.test.mjs ajouté au lint job

All checks: ruff clean, 552 backend tests pass, 9 frontend unit, 5 excalidraw-viewer, 21 desktop, 9 pane-manager, validate-imports 33 modules.
2026-09-09 23:18:29 -04:00

61 lines
2.5 KiB
PowerShell

#!/usr/bin/env pwsh
# ObsiGate Desktop — Windows code signing (scaffolding).
#
# Signe le binaire et l'installateur MSI/NSIS après un `cargo tauri build`.
# Aucun certificat n'est embarqué : les identifiants sont lus depuis
# l'environnement (jamais commités). Le script est un no-op explicite si
# l'env n'est pas configuré — le build reste donc fonctionnel sans signature.
#
# Variables d'environnement :
# OBSIGATE_SIGN_CERT_PFX chemin du .pfx (requis)
# OBSIGATE_SIGN_CERT_PASSWORD mot de passe du .pfx (optionnel)
# OBSIGATE_SIGN_TIMESTAMP_URL URL du serveur d'horodatage RFC3161
# (défaut : http://timestamp.digicert.com)
# OBSIGATE_SIGN_MODE "signtool" (Windows) ou "osslsigncode" (Linux)
#
# Usage :
# ./scripts/sign-windows.ps1 # après le build, signe les artefacts
# OBSIGATE_SIGN_CERT_PFX=cert.pfx ./scripts/sign-windows.ps1
$ErrorActionPreference = 'Stop'
$pfx = $env:OBSIGATE_SIGN_CERT_PFX
if (-not $pfx) {
Write-Host "⚠ Aucun certificat fourni (OBSIGATE_SIGN_CERT_PFX). Signature ignorée — build non signé."
exit 0
}
$password = $env:OBSIGATE_SIGN_CERT_PASSWORD
$tsUrl = if ($env:OBSIGATE_SIGN_TIMESTAMP_URL) { $env:OBSIGATE_SIGN_TIMESTAMP_URL } else { 'http://timestamp.digicert.com' }
$mode = if ($env:OBSIGATE_SIGN_MODE) { $env:OBSIGATE_SIGN_MODE } else { 'signtool' }
$targets = @(
'target/release/obsigate-desktop.exe',
'target/release/bundle/msi/*.msi',
'target/release/bundle/nsis/*-setup.exe'
) | ForEach-Object { Get-Item $_ -ErrorAction SilentlyContinue } | Where-Object { $_ }
if ($targets.Count -eq 0) {
Write-Host "⚠ Aucun artefact à signer trouvé (lancer d'abord `cargo tauri build`)."
exit 0
}
foreach ($t in $targets) {
Write-Host "✍ Signature de $($t.FullName) (mode: $mode)"
if ($mode -eq 'osslsigncode') {
$args = @('sign', '-pkcs12', $pfx, '-h', 'sha256')
if ($password) { $args += @('-pass', $password) }
$args += @('-ts', $tsUrl, '-in', $t.FullName, '-out', $t.FullName)
& osslsigncode @args
if ($LASTEXITCODE -ne 0) { throw "osslsigncode a échoué pour $($t.Name)" }
} else {
$args = @('sign', '/fd', 'SHA256', '/f', $pfx, '/tr', $tsUrl, '/td', 'SHA256')
if ($password) { $args += @('/p', $password) }
$args += $t.FullName
& signtool @args
if ($LASTEXITCODE -ne 0) { throw "signtool a échoué pour $($t.Name)" }
}
}
Write-Host "✅ $($targets.Count) artefact(s) signé(s)."