Schema source-of-truth for the proserveapi DB, versioned outside the
release ZIPs (the actual binaries live in version/ but are gitignored).
0001_Init.sql — full bootstrap of proserveapi (12 tables + view +
reference data + FKs). Reworked from a phpMyAdmin dump to be safely
re-runnable on:
- fresh install (everything created)
- existing customer DB pre-populated manually before launcher rollout
- re-import via phpMyAdmin or mysql CLI
Idempotency tools used:
- CREATE TABLE IF NOT EXISTS
- INSERT IGNORE INTO ... for reference rows
- ADD PRIMARY KEY / KEY / UNIQUE KEY IF NOT EXISTS
- ADD FOREIGN KEY IF NOT EXISTS `name` (...) REFERENCES ...
(note: MariaDB does NOT accept `ADD CONSTRAINT IF NOT EXISTS name
FOREIGN KEY ...` — the IF NOT EXISTS goes after FOREIGN KEY, not
after CONSTRAINT)
- CREATE OR REPLACE VIEW
- Removed the dump's `START TRANSACTION` / `COMMIT` (the launcher
wraps each script in its own tx; embedded BEGIN/COMMIT would break
the rollback semantics)
- Removed `DEFINER=root@localhost` (uses CURRENT_USER, more portable)
0002_SessionType_ps_1.4.5.sql — adds id=7 'LongRange' + renames id=6
to 'Rescue'. Now uses INSERT IGNORE for the new row (skips if 0001
already inserted it on a fresh install) and the UPDATE is naturally
idempotent.
0003_UserSize_ps_1.5.0.sql — adds users.size column. Now uses
ADD COLUMN IF NOT EXISTS (the column is also in the recent 0001
baseline, so on a fresh install this will skip; on an upgrade from a
pre-0003 DB it actually adds it).
Validated locally on MariaDB 10.4 (XAMPP) with two consecutive runs of
each file: exit code 0 on every run, no errors.
.gitignore tightened so version/ only tracks _migrations/*.sql — the
~14 GB UE5 binaries and the _report/ build artifacts stay out of git.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- gate.php : ETag now derived from size+mtime instead of md5_file($zip).
Previously the gate hashed the entire 14 GB ZIP on every HEAD/GET call
(including each of 8 parallel segments) → 30s-5min preparation lag for
clients before the first byte. Now <1ms per request.
- SignManifest : disk-backed cache for SHA-256 keyed by (path,size,mtime).
Re-signing 5×14 GB versions used to take ~25 min, now ~1s when nothing
changed. New "Force re-hash" toggle in admin to ignore the cache.
- versions.php : per-row "🔁 Hash" button to sign a single version, plus
a "⚙ Hash" dropdown to toggle hashAlgorithm:none for builds where the
user accepts skipping client-side verification (manifest stays signed
Ed25519, only the per-ZIP SHA-256 verification is bypassed).
- DownloadUrl.php : signed-URL TTL bumped 1h → 6h to cover slow ADSL users
who need >1h to finish a 14 GB download.
- .gitignore : track server/builds/.htaccess + gate.php (still ignore the
actual ZIP/exe binaries).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Last commit accidentally captured two large binaries that landed in the
working tree during the self-update test prep:
- PSLauncher-0.6.0.exe at repo root
- installer/output/PSLauncher-Setup-0.5.0.exe
Neither belongs in version control. Add /PSLauncher-*.exe and
/installer/output/ to .gitignore and `git rm --cached` the existing
entries so the next push doesn't reupload them.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
After every `dotnet publish -c Release`, the single-file binaries land
in C:\ASTERION\GIT\PS_Launcher\ next to PS_Launcher.sln so they can be
launched directly without digging into bin/Release/.../publish/.
Implemented as an MSBuild AfterTargets="Publish" target on each csproj
(PSLauncher.App, PSLauncher.Updater) using $(MSBuildThisFileDirectory)
to resolve the repo root portably. Condition='Release' so debug builds
don't pollute the root.
.gitignore covers /PSLauncher.exe and /PSLauncher.Updater.exe so the
committed tree stays clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Client (C# / .NET 8 / WPF, MVVM via CommunityToolkit.Mvvm):
- PSLauncher.App: WPF UI dark theme (Epic-style sidebar + hero + big play button)
with UpdateAvailableDialog rendering Markdown release notes via Markdig.Wpf.
- PSLauncher.Core: services for installation registry (scans Proserve v{X.Y.Z}/),
process launcher, manifest fetch, SHA-256 integrity, HTTP download with
progress, ZIP install via .tmp + atomic rename, update orchestrator.
- PSLauncher.Models: RemoteManifest, InstalledVersion, LocalConfig DTOs.
Server (PHP 8 for OVH mutualisé, deployed under www/PS_Launcher/):
- Front controller + routes /manifest and /releasenotes/{version}.
- Static signed-manifest workflow with tools/sign-manifest.php CLI to
recompute SHA-256 and sizeBytes after each ZIP upload.
- .htaccess: HTTPS redirect, rewrite, security headers.
- config.example.php template; real config.php is gitignored.
Cohabiting versions: each release lives in its own Proserve v{version}/ folder
under installRoot. Old versions are never deleted automatically.
Roadmap: v0.3 = HTTP Range resume + Polly retry + state.json,
v0.4 = MySQL license + Ed25519 signatures + DPAPI, v0.5 = settings/UX polish.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>