From 3b9dd6788d0d65891e82fb44a790f32d8e36a624 Mon Sep 17 00:00:00 2001 From: debont80 Date: Fri, 10 Jul 2026 10:39:12 -0400 Subject: [PATCH] chore(config): point the updater at the now-public AeroFetch repo The source repo is public now, so the separate releases-only repo (AeroFetch-releases) is no longer needed to keep the updater tokenless. Retarget UPDATE_REPO from AeroFetch-releases back to AeroFetch and refresh the config doc comment. The dedicated read-only baked-token service account (aerofetch-updater) has been deleted and its token revoked, so nothing reads a token any more; the .gitignore comment for the retired .update-token file is updated to match. Co-Authored-By: Claude Opus 4.8 --- .gitignore | 4 ++-- src/main/config.ts | 13 +++++++------ 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/.gitignore b/.gitignore index 55f6694..2229714 100644 --- a/.gitignore +++ b/.gitignore @@ -10,8 +10,8 @@ dist # Secrets — never commit .gitea-token -# Retired: no longer read by the build (baked update token removed), but the -# local file still holds a live token until it's revoked — keep it ignored. +# Retired: the baked update token was removed from the build and its service +# account revoked; kept ignored so a stray local .update-token can never be committed. .update-token # VS Code user settings (workspace settings/.vscode/launch.json are committed) diff --git a/src/main/config.ts b/src/main/config.ts index 0da70c1..40ee060 100644 --- a/src/main/config.ts +++ b/src/main/config.ts @@ -4,15 +4,16 @@ * timeouts, caps, tickers) and from user settings (settings.ts). Retarget a * fork's update source by editing these three values. * - * The update source is a PUBLIC, releases-only repo — it holds no source, just - * the published installers — so anonymous reads work and the updater sends no - * auth at all. Keeping releases separate from the (private) source repo is what - * lets the client stay tokenless: there is no secret in the bundle to leak. A - * private fork retargets its updater by editing these constants and rebuilding. + * The update source is the main AeroFetch repo itself, made PUBLIC — so anonymous + * reads work and the updater sends no auth at all; there is no secret in the bundle + * to leak. (A prior design split releases into a separate releases-only repo so the + * source could stay private; that's retired now that the source repo is public + * itself — one fewer moving part.) A private fork retargets its updater by editing + * these constants and rebuilding. */ export const UPDATE_HOST = 'https://gitea.netbird.zimspace.uk:5938' export const UPDATE_OWNER = 'debont80' -export const UPDATE_REPO = 'AeroFetch-releases' +export const UPDATE_REPO = 'AeroFetch' export const RELEASE_API = `${UPDATE_HOST}/api/v1/repos/${UPDATE_OWNER}/${UPDATE_REPO}/releases/latest` // --- ffmpeg dependency source ------------------------------------------------ -- 2.47.3