Don't trust manifest.latest, no-cache the manifest fetch

Two robustness fixes after a real-world miss where v1.4.7 was uploaded but
the launcher kept reporting v1.4.6 as latest:

1. UpdateChecker: ignore the `latest` field of the manifest entirely.
   Always pick the highest SemVer in the versions[] array (filtered by
   availableForDownload). Removes a class of "I forgot to bump latest"
   bugs at the server.

2. ManifestService: send Cache-Control: no-cache, no-store + Pragma:
   no-cache when fetching. The user explicitly clicked "Check for
   updates", they want fresh data — bypass any intermediate cache
   (browser-style HTTP cache, OVH static handler default 2-day expires).

3. sign-manifest.php: after hashing the uploaded ZIPs, auto-update
   `manifest.latest` to the highest version that actually has a ZIP
   on the server. Prevents the same drift the client now ignores, but
   keeps the field meaningful for any consumer that reads it.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-01 09:26:06 +02:00
parent b8ac2488fe
commit 3a00b0e677
3 changed files with 31 additions and 5 deletions

View File

@@ -27,7 +27,15 @@ public sealed class ManifestService : IManifestService
{
var url = TrimSlash(_serverBaseUrlProvider()) + "/manifest";
_logger.LogInformation("Fetching manifest: {Url}", url);
using var resp = await _http.GetAsync(url, ct).ConfigureAwait(false);
using var req = new HttpRequestMessage(HttpMethod.Get, url);
// Bypass des caches intermédiaires — l'utilisateur a explicitement cliqué « Vérifier ».
req.Headers.CacheControl = new System.Net.Http.Headers.CacheControlHeaderValue
{
NoCache = true,
NoStore = true,
};
req.Headers.Pragma.ParseAdd("no-cache");
using var resp = await _http.SendAsync(req, ct).ConfigureAwait(false);
resp.EnsureSuccessStatusCode();
var manifest = await resp.Content.ReadFromJsonAsync<RemoteManifest>(JsonOptions, ct).ConfigureAwait(false)
?? throw new InvalidOperationException("Empty manifest");