feat(updater): bake a read-only update token into the build

The release repo is private, so the auto-updater previously required each
user to paste a Gitea token into Settings before it could see or download
updates. Inject a read-only token at build time (AEROFETCH_UPDATE_TOKEN env
var or a gitignored .update-token file) via electron.vite's `define`, and
fall back to it in authHeader() when the user hasn't set their own. The token
value lives only in the built bundle, never in source or git.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-03 08:20:21 -04:00
parent 48ce591702
commit 037ea2da32
4 changed files with 50 additions and 8 deletions
+18
View File
@@ -1,10 +1,28 @@
import { resolve } from 'path'
import { existsSync, readFileSync } from 'fs'
import { defineConfig, externalizeDepsPlugin } from 'electron-vite'
import react from '@vitejs/plugin-react'
// Read-only Gitea token compiled into the main bundle so the auto-updater can
// read the PRIVATE release repo without user setup (see config.ts BAKED_UPDATE_TOKEN).
// Source order: AEROFETCH_UPDATE_TOKEN env var (CI/secret), else a gitignored
// .update-token file (local builds). Absent → empty string → no token baked in.
// Keep this a dedicated read-only service-account token; the shipped bundle is public.
function bakedUpdateToken(): string {
const fromEnv = process.env.AEROFETCH_UPDATE_TOKEN?.trim()
if (fromEnv) return fromEnv
const file = resolve('.update-token')
return existsSync(file) ? readFileSync(file, 'utf8').trim() : ''
}
export default defineConfig({
main: {
plugins: [externalizeDepsPlugin()],
// Textually replaces the __AEROFETCH_UPDATE_TOKEN__ identifier in main-process
// code with the token literal at build time — value never lands in source/git.
define: {
__AEROFETCH_UPDATE_TOKEN__: JSON.stringify(bakedUpdateToken())
},
resolve: {
alias: {
'@shared': resolve('src/shared')