aab2e411529e04c41e1dabea364414616fe6f850
6 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
| c371a79f93 |
v0.26.0 — Channels per-license + tag BÊTA sur versions
DEUX features liées :
1. CHANNELS : chaque license peut être attribuée à un manifest distinct
(« channel »). Permet de servir des versions différentes selon le
client. Le serveur lit ?channel=X et sert manifest/versions-{X}.json
avec fallback transparent sur versions.json. NULL = default.
2. BÊTA : nouveau flag isBeta + betaNotes par version dans le manifest.
Visible uniquement par les licenses avec can_see_betas=1. Affichage
d'une pill orange « BÊTA » sur la row + tooltip avec les notes pour
les testeurs. Les installations locales déjà présentes restent
visibles même si l'accès BÊTA est retiré ensuite (on n'efface pas
le disque du client).
DB :
002_channel_betas.sql ajoute channel + can_see_betas sur licenses.
Idempotent (ALTER TABLE IF NOT EXISTS), zero data migration.
Serveur PHP :
- ValidateLicense.php signe channel + canSeeBetas dans la réponse
(ordre des clés CRITIQUE pour matcher le canonical client).
- Manifest.php : whitelist regex anti-traversal sur ?channel=, fallback
silencieux sur versions.json si channel inconnu (évite leak de la
liste de channels par probing).
- SignManifest.php prend un channel optionnel → l'admin peut signer
chaque manifest indépendamment.
- admin/licenses.php : dropdown channel + checkbox bêta sur create,
bouton détails repliable par-row pour edit.
- admin/versions.php : channel switcher en tête, badge BÊTA sur chaque
row, dialog repliable « Bêta » avec checkbox + notes des testeurs.
Client C# :
- License.Channel + License.CanSeeBetas (dans le canonical signé).
- VersionManifest.IsBeta + BetaNotes.
- ManifestService prend un channelProvider via DI, lu depuis license
cachée à chaque fetch (lazy, pas de circular dep).
- MainViewModel.RebuildList filtre les versions IsBeta si !CanSeeBetas
(mais conserve les installées locales — on ne retire pas l'accès
rétroactivement à ce qui est déjà sur disque).
- VersionRowViewModel : props IsBeta / BetaNotes / BetaTooltip.
- MainWindow.xaml : pill orange à côté du n° version pour le featured
et les rows compactes, tooltip dynamique avec les notes testeurs.
Backward compat signature :
Anciennes licenses cachées (signées sans channel/canSeeBetas) sont
toujours validées via un fallback canonical legacy dans VerifySignature.
Sans ce fallback, le passage à v0.26 invaliderait toutes les caches
hors-ligne et bloquerait les users en mobilité.
Migration côté admin : jouer 002_channel_betas.sql sur la base, déployer
les fichiers PHP, créer manifest/versions-{channel}.json pour les
nouveaux channels (l'admin versions.php propose un input « Créer/utiliser
un nouveau channel »). Les licenses existantes restent en channel=NULL
= default = comportement actuel.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
|||
| 30eceaea2c |
v0.20.0 — Cancel-from-red-button waits for segments + new Verifying row state
Two related UX bugs fixed. 1) Red "Annuler" button on a row : DL appeared to keep going The button calls RestartFromZeroAsync which used to fire _activeDownloadCts.Cancel() then sleep 200 ms then delete the .partial. With 16 parallel segments mid-write, 200 ms is way too short — the segments were still flushing buffers when the file got deleted, then recreated it from their own write streams, making it look like the download "continued". Now we keep a reference to the in-flight install Task (_activeInstallTask) and properly await it (with a 10 s safety timeout) before discarding state. This guarantees all segment FileStreams are closed and the .partial deletion is the final word. 2) Progress bar said "Downloading…" during SHA-256 verification The footer message switched to "🔍 Vérification SHA-256 v…" but the row's badge stayed on "⬇ Downloading…" because row.State stayed at Downloading throughout DownloadAsync (which internally chains DL + verify). New VersionRowState.Verifying inserted between Downloading and Installing, applied on the first hashProgress callback. Badge now reads "🔍 Vérification…" / "🔍 Verifying…" during the hash phase. VersionRowViewModel.IsBusy now also includes Verifying so commands that gate on busy stay disabled during verification. Versions bumped to 0.20.0. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
|||
| 7fb02e4945 |
v0.9.0 — DL UX: cancel/restart confirmations, auto-revalidate license, fix progress refresh
UX - Red "Annuler" button next to "↻ Reprendre" on rows with a partial download. Confirmation MessageBox before discarding the .partial + state.json. - "Recommencer depuis zéro" entry in the row's "..." context menu, visible only when a partial exists. - Cancel button visibility tied to a new ShowRestartFromZero property (HasResumableDownload && State == AvailableIdle): hides during active DL to avoid colliding with the inline cancel. - ResumableBytes refreshed from state.json after cancel/error so the "Reprendre (X%)" label reflects the actual percentage reached, not the stale value from launcher startup. - MainWindow.Closing prompts for confirmation if a download is in progress (HasActiveDownload), so an accidental ✕ doesn't waste a 14 GB transfer. - "🔧 Préparation du téléchargement v…" status set immediately on click and kept visible during HEAD/SetLength so the user knows something's happening before the first byte. ProgressDetail wired with NotifyPropertyChangedFor (FooterText) so download speed shows during DL and not just at install transition. Auto-revalidation - CheckForUpdatesAsync now runs RefreshLicenseFromServerAsync first: every startup auto-check + every manual "Vérifier les MAJ" click pulls the latest license state from /api/license/validate. Date changes / revocations done in the backoffice propagate to clients without waiting for the 100-day cache to expire. Silent fallback to cached state if offline. Version bumped to 0.9.0. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
|||
| 7a29dbb049 |
v0.4: licensing — server validation, DPAPI cache, Ed25519 signed responses
UX bonus: clicking "Reprendre" on an interrupted download skips the
release-notes confirmation dialog (the user already approved when they
first clicked Installer).
Server side
-----------
- migrations/001_init.sql: licenses, license_machines, rate_limit,
audit_log on InnoDB/utf8mb4. Foreign keys, unique on license_key, slot
uniqueness per (license_id, machine_id).
- api/lib/Db.php: thin PDO singleton (exception mode, prepared, no emul).
- api/lib/Crypto.php: Ed25519 sign/verify via libsodium (sodium_crypto_*),
HMAC-SHA-256 helper for v0.6, canonicalJson() that strips `signature`
before serializing — must match exactly the encoding done client-side
before verify.
- api/routes/ValidateLicense.php: POST /license/validate. Looks up the
key, walks the machine slot logic (insert or update last_seen),
enforces max_machines, returns a payload signed Ed25519 + status of
valid/expired/revoked/machine_limit_exceeded/invalid. Audit logs every
outcome. Rate-limit 10/min/IP via the rate_limit table.
- tools/generate-keypair.php: prints a fresh sodium keypair so the
operator drops the hex into config.php and the public_key_hex into the
launcher resource.
- tools/issue-license.php: PRSRV-XXXX-XXXX-XXXX-XXXX generator (32-char
unambiguous alphabet), inserts the license, prints the key once.
- tools/sign-manifest.php: now also signs the manifest itself with
Ed25519 after computing the per-zip sha256s.
- config.example.php: schema rewritten with sections db / hmac / ed25519
/ jwt / rate-limit. config.php remains gitignored.
Client side
-----------
- Models/License.cs: LicenseValidationRequest + LicenseValidationResponse
with CanDownload(VersionManifest) — entitlement_until vs version's
minLicenseDate. The status valid|expired|revoked|machine_limit_exceeded
flow is preserved end-to-end.
- Core/Licensing/LicenseService.cs:
* machineId = SHA-256 of HKLM/Software/Microsoft/Cryptography/MachineGuid
+ UserName (stable, no PII leak)
* online ValidateAsync calls /license/validate with launcher version
* embedded server-pubkey.txt drives Ed25519 verification of the
response (skipped gracefully if pubkey not yet provisioned)
* SaveCached / GetCached use DPAPI CurrentUser scope on the license
key; the cleartext key never touches disk
* GetCached has a 7-day offline grace window after the last successful
validation, so going offline doesn't lock the user out
- Core/Resources/server-pubkey.txt: EmbeddedResource. Default content is
a comment, which the service treats as "no pubkey configured" and
bypasses verification. Operator pastes the real hex post-deploy and
rebuilds.
- Core/PSLauncher.Core.csproj: Polly, NSec.Cryptography (Ed25519),
System.Security.Cryptography.ProtectedData (DPAPI).
- App/Views/OnboardingDialog.xaml(.cs): first-launch / "🔑 Activer"
modal. Calls LicenseService, displays status messages with red
foreground on errors and green-tinted secondary text otherwise.
- ViewModels/VersionRowViewModel.cs: new LicenseAllowsDownload property.
Install button label switches to "🔒 License insuffisante" when the
user's entitlement_until precedes the version's minLicenseDate;
CanInstall is false in that case so the click is a no-op too.
- ViewModels/MainViewModel.cs: loads the cached license at startup (no
network call), surfaces it as LicenseSummary in the top bar, exposes
ActivateLicenseCommand to (re)open the onboarding dialog. RebuildList
applies the per-version license filter so older installed versions
remain launchable but newer-than-license ones can't be downloaded.
- Views/MainWindow.xaml: top bar gains a "🔑 Activer / changer" button
next to the license summary.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
|||
| 9bdcdabb9e |
v0.3: resumable downloads with HTTP Range, Polly retry, persistent state
This is the robustness layer needed for real 14 GB builds. A 99%-complete
download that gets interrupted no longer means re-downloading 14 GB.
DownloadManager
---------------
- Range: bytes={resumeFrom}- on every (re)attempt; reads resumeFrom from
the actual size of the .partial file so retries always resume from real
on-disk state, not from a remembered counter.
- If-Range: ETag (or Last-Modified fallback). When the server returns 200
instead of 206 we know the resource changed under us, so we discard
.partial and start fresh.
- Polly resilience pipeline: 6 retries, exponential 1-32s with jitter,
on HttpRequestException / IOException / TimeoutException / 5xx / 408 /
429. Each retry re-evaluates resumeFrom from disk, so the server is
asked only for what's actually missing.
- state.json persisted every 5s OR every 100 MiB, whichever comes first,
via atomic write-then-rename. Holds url, total, downloaded, sha256,
etag, last-modified, and the .partial path.
- Disk-space check happens once at fresh-start (1.05x expected size); a
resume doesn't redo it.
- On final success: SHA-256 of the assembled .partial verified, then
atomic rename to .zip and state.json deleted.
DownloadStateStore
------------------
- New IDownloadStateStore in PSLauncher.Core/Downloads.
- Stores under %LocalAppData%/PSLauncher/downloads/.
- Save / Load / Discard / ScanResumable. Tolerates malformed state files
by ignoring them.
UI hint
-------
VersionRowViewModel now has ResumableBytes; when > 0, the install button
label switches to "↻ Reprendre (X%)" computed from
ResumableBytes / Remote.Download.SizeBytes. MainViewModel.RebuildList
queries IDownloadManager.GetResumableState(version) for each remote-only
row and populates ResumableBytes. Both the featured hero card and the
compact rows bind to InstallButtonLabel.
API change
----------
IDownloadManager gains GetResumableState(version) and
DiscardResumableState(version) so callers (and the UI) can reason about
in-progress downloads without poking at the filesystem directly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
|||
| 4e9f757ce1 |
UI rework: per-row actions, drop sidebar
Replace the sidebar + hero + single big-button layout with a flat list of per-version cards. Each card carries its own action button: - Installed: ▶ Lancer (green, primary) - Available on server only: ⬇ Installer (blue, accent) + lighter blue card - Busy: inline mini progress bar with %, card tinted green Each card also exposes a "..." menu (left-click opens it) with: - Voir les release notes (works for installed and remote-only versions) - Ouvrir le dossier (installed only) - Supprimer cette version (installed only, with confirmation dialog) VersionRowViewModel owns its state (InstalledIdle / AvailableIdle / Downloading / Installing / Uninstalling) and its commands; MainViewModel wires per-row handlers after instantiation so the row VM stays UI-only and the services live one layer up. ReleaseNotesViewerDialog: separate dialog reused by the menu — same Markdown rendering as UpdateAvailableDialog but no download CTA. Theme: AccentButton + IconButton + dark ContextMenu/MenuItem styles. Behavior changes: - The single global SelectedVersion + AvailableUpdate are gone; each row is independently actionable. - The list now merges installed + remote: a version present on the server but not locally appears as a "remote-only" row, and vice-versa. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |