Harden audit findings: correctness, type-safety, Windows conventions & polish
Audit-pass over CODE-AUDIT.md (~48 items closed this pass; all verified — typecheck + 234 tests + eslint + prettier green). Correctness / bugs: - B3: match the release checksum to the asset's filename line (no wrong-hash verify) - B4: newline-safe metadata probe (one --print with a unit-separator delimiter) - B5 / L88: guard the meta event against canceled items; progress no longer promotes a queued item outside pump() - B7: cookie-login promise always resolves (handles destroy-without-close) - L146: trim parser rejects >2 colon-group times; M36: Library selection counts only actionable rows - L11 / L50 / L156 / L57 / L159 / L15 / L3: live queue count, empty-cookie message, schedule picker min, dead-code/comment cleanup Type safety: - Enable noUncheckedIndexedAccess + noFallthroughCasesInSwitch (15 real edge cases fixed) Resilience / Windows / metadata: - R5: settings write failure handled (no unhandled IPC rejection; reconciles to truth) - W1 / W5 / W6: min window size, seeded folder picker, parented sign-in window; L147 dead macOS branches removed - CL1: shared stdout markers; package/builder metadata (license, homepage, repository, copyright, tsbuildinfo glob) Copy / docs / tests: - M37 / SR9 dev-jargon cleanup in hints; M8 / M25 / M26 / L66 / L80 / L81 reconciled - New unit tests for L35 (isValidMediaItem) and L36 (compareVersions) This commit also checkpoints the previously-uncommitted feat/tray-background-clipboard work it builds on: background running + auto-download, library clipboard detection, tray, binary management & library scale, credential encryption at rest, the shared jsonStore and ui/ primitives, and the eslint/prettier tooling. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+10
-5
@@ -1,6 +1,6 @@
|
||||
appId: com.aerofetch.app
|
||||
productName: AeroFetch
|
||||
copyright: yt-dlp frontend
|
||||
copyright: Copyright © 2026 AeroFetch
|
||||
|
||||
# Lets a browser/another app hand AeroFetch a link via aerofetch://download?url=<encoded>
|
||||
# (src/main/deeplink.ts) — the closest Windows analog to Android's share-to-app intent.
|
||||
@@ -15,13 +15,18 @@ directories:
|
||||
buildResources: build
|
||||
output: dist
|
||||
|
||||
# Generate a <installer>.exe.sha256 next to every built .exe (H8). The updater
|
||||
# hard-requires this checksum asset or it refuses to install the update.
|
||||
afterAllArtifactBuild: ./scripts/generate-checksums.cjs
|
||||
|
||||
files:
|
||||
- '!**/.vscode/*'
|
||||
- '!src/*'
|
||||
- '!electron.vite.config.{js,ts,mjs,cjs}'
|
||||
- '!{.eslintignore,.eslintrc.cjs,.eslintrc.js,.prettierignore,.prettierrc.yaml,dev-app-update.yml,CHANGELOG.md,README.md}'
|
||||
- '!{.env,.env.*,.npmrc,pnpm-lock.yaml,package-lock.json}'
|
||||
- '!{tsconfig.json,tsconfig.node.json,tsconfig.web.json,tsconfig.tsbuildinfo}'
|
||||
- '!{tsconfig.json,tsconfig.node.json,tsconfig.web.json}'
|
||||
- '!*.tsbuildinfo'
|
||||
|
||||
# yt-dlp.exe + ffmpeg.exe ship outside the asar archive so they can be spawned
|
||||
# directly. They land in <install>/resources/bin, reachable via process.resourcesPath.
|
||||
@@ -46,9 +51,9 @@ win:
|
||||
- portable
|
||||
# Never request admin elevation.
|
||||
requestedExecutionLevel: asInvoker
|
||||
# Placeholder icon (audit M3): white download glyph on the teal brand square,
|
||||
# mirroring the in-app brand mark. Generated from build/icon.svg as a multi-size
|
||||
# .ico (256/128/64/48/32/16). Replace with a designed asset before v1.0 — re-run
|
||||
# App icon (audit W14): white download glyph on the teal brand square with a
|
||||
# top-lit gradient. Generated from build/icon.svg as a multi-size .ico
|
||||
# (256/128/64/48/32/16). After editing the SVG, regenerate with:
|
||||
# magick -background none build/icon.svg -define icon:auto-resize=256,128,64,48,32,16 build/icon.ico
|
||||
icon: build/icon.ico
|
||||
|
||||
|
||||
Reference in New Issue
Block a user