feat(updater): bake a read-only update token into the build

The release repo is private, so the auto-updater previously required each
user to paste a Gitea token into Settings before it could see or download
updates. Inject a read-only token at build time (AEROFETCH_UPDATE_TOKEN env
var or a gitignored .update-token file) via electron.vite's `define`, and
fall back to it in authHeader() when the user hasn't set their own. The token
value lives only in the built bundle, never in source or git.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-03 08:20:21 -04:00
parent 48ce591702
commit 037ea2da32
4 changed files with 50 additions and 8 deletions
+1
View File
@@ -10,6 +10,7 @@ dist
# Secrets — never commit
.gitea-token
.update-token
# VS Code user settings (workspace settings/.vscode/launch.json are committed)
.vscode/settings.json