feat(setup): fetch ffmpeg on first run instead of bundling it
Ship a smaller installer that no longer carries ffmpeg.exe/ffprobe.exe (the bulk of its size). On first run they are downloaded from a pinned upstream archive (gyan 8.1.2), verified against a pinned SHA-256, and unpacked with the OS tar.exe into the managed userData/bin dir -- the same place as the self-updating yt-dlp, so they survive app updates and portable re-extraction. A hard onboarding gate blocks the app until they are present, with a "locate existing ffmpeg" folder-picker fallback for offline machines and a Repair action in Settings > About. The updater's streaming/checksum/redirect/idle-timeout download loop is extracted to lib/verifiedDownload.streamVerifiedFile and shared by both the app-installer download and the ffmpeg fetch; the updater's public behaviour and error strings are unchanged (its boundary tests still pass). No new npm dependency: extraction uses the System32 bsdtar resolved by absolute path (audit F3). Note: this commit also carries pre-existing, in-progress aria2c/network and updater-token work that was already uncommitted in the working tree and is entangled with the above in shared files (updater.ts, ipc.ts, preload/index.ts, mockApi.ts, shared/ipc.ts, plus the settings/network files and aria2c.exe). It was not cleanly separable by path, so it is included here rather than split out. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,28 +1,10 @@
|
||||
import { resolve } from 'path'
|
||||
import { existsSync, readFileSync } from 'fs'
|
||||
import { defineConfig, externalizeDepsPlugin } from 'electron-vite'
|
||||
import react from '@vitejs/plugin-react'
|
||||
|
||||
// Read-only Gitea token compiled into the main bundle so the auto-updater can
|
||||
// read the PRIVATE release repo without user setup (see config.ts BAKED_UPDATE_TOKEN).
|
||||
// Source order: AEROFETCH_UPDATE_TOKEN env var (CI/secret), else a gitignored
|
||||
// .update-token file (local builds). Absent → empty string → no token baked in.
|
||||
// Keep this a dedicated read-only service-account token; the shipped bundle is public.
|
||||
function bakedUpdateToken(): string {
|
||||
const fromEnv = process.env.AEROFETCH_UPDATE_TOKEN?.trim()
|
||||
if (fromEnv) return fromEnv
|
||||
const file = resolve('.update-token')
|
||||
return existsSync(file) ? readFileSync(file, 'utf8').trim() : ''
|
||||
}
|
||||
|
||||
export default defineConfig({
|
||||
main: {
|
||||
plugins: [externalizeDepsPlugin()],
|
||||
// Textually replaces the __AEROFETCH_UPDATE_TOKEN__ identifier in main-process
|
||||
// code with the token literal at build time — value never lands in source/git.
|
||||
define: {
|
||||
__AEROFETCH_UPDATE_TOKEN__: JSON.stringify(bakedUpdateToken())
|
||||
},
|
||||
resolve: {
|
||||
alias: {
|
||||
'@shared': resolve('src/shared')
|
||||
|
||||
Reference in New Issue
Block a user