Files
PS_Launcher/server
j.foucher 7a29dbb049 v0.4: licensing — server validation, DPAPI cache, Ed25519 signed responses
UX bonus: clicking "Reprendre" on an interrupted download skips the
release-notes confirmation dialog (the user already approved when they
first clicked Installer).

Server side
-----------
- migrations/001_init.sql: licenses, license_machines, rate_limit,
  audit_log on InnoDB/utf8mb4. Foreign keys, unique on license_key, slot
  uniqueness per (license_id, machine_id).
- api/lib/Db.php: thin PDO singleton (exception mode, prepared, no emul).
- api/lib/Crypto.php: Ed25519 sign/verify via libsodium (sodium_crypto_*),
  HMAC-SHA-256 helper for v0.6, canonicalJson() that strips `signature`
  before serializing — must match exactly the encoding done client-side
  before verify.
- api/routes/ValidateLicense.php: POST /license/validate. Looks up the
  key, walks the machine slot logic (insert or update last_seen),
  enforces max_machines, returns a payload signed Ed25519 + status of
  valid/expired/revoked/machine_limit_exceeded/invalid. Audit logs every
  outcome. Rate-limit 10/min/IP via the rate_limit table.
- tools/generate-keypair.php: prints a fresh sodium keypair so the
  operator drops the hex into config.php and the public_key_hex into the
  launcher resource.
- tools/issue-license.php: PRSRV-XXXX-XXXX-XXXX-XXXX generator (32-char
  unambiguous alphabet), inserts the license, prints the key once.
- tools/sign-manifest.php: now also signs the manifest itself with
  Ed25519 after computing the per-zip sha256s.
- config.example.php: schema rewritten with sections db / hmac / ed25519
  / jwt / rate-limit. config.php remains gitignored.

Client side
-----------
- Models/License.cs: LicenseValidationRequest + LicenseValidationResponse
  with CanDownload(VersionManifest) — entitlement_until vs version's
  minLicenseDate. The status valid|expired|revoked|machine_limit_exceeded
  flow is preserved end-to-end.
- Core/Licensing/LicenseService.cs:
  * machineId = SHA-256 of HKLM/Software/Microsoft/Cryptography/MachineGuid
    + UserName (stable, no PII leak)
  * online ValidateAsync calls /license/validate with launcher version
  * embedded server-pubkey.txt drives Ed25519 verification of the
    response (skipped gracefully if pubkey not yet provisioned)
  * SaveCached / GetCached use DPAPI CurrentUser scope on the license
    key; the cleartext key never touches disk
  * GetCached has a 7-day offline grace window after the last successful
    validation, so going offline doesn't lock the user out
- Core/Resources/server-pubkey.txt: EmbeddedResource. Default content is
  a comment, which the service treats as "no pubkey configured" and
  bypasses verification. Operator pastes the real hex post-deploy and
  rebuilds.
- Core/PSLauncher.Core.csproj: Polly, NSec.Cryptography (Ed25519),
  System.Security.Cryptography.ProtectedData (DPAPI).
- App/Views/OnboardingDialog.xaml(.cs): first-launch / "🔑 Activer"
  modal. Calls LicenseService, displays status messages with red
  foreground on errors and green-tinted secondary text otherwise.
- ViewModels/VersionRowViewModel.cs: new LicenseAllowsDownload property.
  Install button label switches to "🔒 License insuffisante" when the
  user's entitlement_until precedes the version's minLicenseDate;
  CanInstall is false in that case so the click is a no-op too.
- ViewModels/MainViewModel.cs: loads the cached license at startup (no
  network call), surfaces it as LicenseSummary in the top bar, exposes
  ActivateLicenseCommand to (re)open the onboarding dialog. RebuildList
  applies the per-version license filter so older installed versions
  remain launchable but newer-than-license ones can't be downloaded.
- Views/MainWindow.xaml: top bar gains a "🔑 Activer / changer" button
  next to the license summary.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-01 10:12:37 +02:00
..

PS_Launcher — Côté serveur

Contenu de ce dossier à uploader sous www/PS_Launcher/ sur le mutualisé OVH.

Arborescence finale après upload

www/
└── PS_Launcher/
    ├── .htaccess
    ├── api/
    │   ├── config.php          ← À ÉDITER avec tes vraies valeurs (DB, secrets)
    │   ├── index.php
    │   ├── lib/Response.php
    │   └── routes/
    │       ├── Manifest.php
    │       └── Releasenotes.php
    ├── manifest/
    │   └── versions.json       ← Régénéré par tools/sign-manifest.php
    ├── releasenotes/
    │   ├── 1.4.5.md
    │   └── 1.4.6.md
    ├── builds/                 ← Tu uploades ici les ZIPs en SFTP
    │   └── proserve-1.4.6.zip
    └── tools/
        └── sign-manifest.php   ← Lance après chaque upload de ZIP

Workflow de release

  1. Packager Unreal → produit le dossier Proserve v1.4.6/.
  2. Le zipper localement : le contenu du ZIP doit reproduire ce qui est attendu côté client (le client extrait dans Proserve v1.4.6/, donc le ZIP peut soit contenir un dossier racine Proserve v1.4.6/, soit son contenu directement — voir ci-dessous).
  3. Uploader le ZIP via SFTP dans www/PS_Launcher/builds/proserve-1.4.6.zip.
  4. Éditer manifest/versions.json pour ajouter (ou modifier) l'entrée 1.4.6 et le champ latest.
  5. Ajouter releasenotes/1.4.6.md.
  6. Se connecter en SSH OVH et lancer :
    cd www/PS_Launcher
    php tools/sign-manifest.php
    
    Cela calcule automatiquement sizeBytes et sha256 à partir du ZIP.

Convention du contenu du ZIP

Le client extrait le ZIP dans installRoot/Proserve v{version}/. Donc le ZIP doit contenir directement les fichiers PROSERVE_UE_5_5.exe, Engine/, PROSERVE_UE_5_5/, etc. à sa racine (pas de dossier englobant).

Test rapide en ligne de commande :

unzip -l proserve-1.4.6.zip | head -10

Doit lister PROSERVE_UE_5_5.exe à la racine, pas Proserve v1.4.6/PROSERVE_UE_5_5.exe.

Test de l'API depuis ton poste

Une fois uploadé, vérifier :

curl https://www.tondomaine.com/PS_Launcher/api/health
curl https://www.tondomaine.com/PS_Launcher/api/manifest
curl https://www.tondomaine.com/PS_Launcher/api/releasenotes/1.4.6

À mettre à jour avant prod

  • api/config.php : tous les replace_me / replace_with_*. Ce fichier ne doit JAMAIS être commit dans un repo public.
  • Dans manifest/versions.json, remplace www.exemple-asterion.com par ton vrai domaine.