Files
AeroFetch/src/main/config.ts
T
debont80 44230c757e feat: retarget the auto-updater from Gitea to GitHub
The source repo moved to github.com/debont80/AeroFetch; the in-app
updater and release links still pointed at the old self-hosted Gitea
instance. Repoint RELEASE_API at the GitHub REST API, replace the
single-host download trust check with an allowlist (github.com plus
its release-asset CDN hosts, which GitHub 302s downloads through —
mirrors the existing FFMPEG_TRUSTED_HOSTS pattern), and add the
User-Agent header GitHub's API requires.

No bridge: installs on a Gitea-pointed build (<=0.7.3) won't
auto-discover releases published to GitHub and need one manual
download, matching the precedent set by the earlier releases-repo
migration.
2026-07-16 12:47:27 -04:00

56 lines
3.3 KiB
TypeScript

/**
* Build/host configuration (CC11): the deploy-specific constants that identify
* WHERE this build talks to, separated from runtime tunables (constants.ts —
* timeouts, caps, tickers) and from user settings (settings.ts). Retarget a
* fork's update source by editing these values.
*
* The update source is the main AeroFetch repo itself, made PUBLIC — so anonymous
* reads work and the updater sends no auth at all; there is no secret in the bundle
* to leak. (Earlier designs split releases into a separate releases-only repo, then
* moved the whole source repo off a self-hosted Gitea to GitHub — each retirement
* left one fewer moving part.) A private fork retargets its updater by editing
* these constants and rebuilding.
*/
export const UPDATE_OWNER = 'debont80'
export const UPDATE_REPO = 'AeroFetch'
export const UPDATE_API_HOST = 'https://api.github.com'
export const RELEASE_API = `${UPDATE_API_HOST}/repos/${UPDATE_OWNER}/${UPDATE_REPO}/releases/latest`
// Hosts a release asset download may touch, HTTPS-only, re-checked on EVERY redirect
// hop (mirrors FFMPEG_TRUSTED_HOSTS below): github.com serves browser_download_url,
// which GitHub 302s to one of these asset-storage CDN hosts.
export const UPDATE_TRUSTED_HOSTS = [
'github.com',
'release-assets.githubusercontent.com',
'objects.githubusercontent.com'
] as const
// --- ffmpeg dependency source ------------------------------------------------
// ffmpeg/ffprobe are NOT bundled in the installer (they're the bulk of its size);
// they're fetched once on first run into the managed userData/bin dir (ffmpegSetup.ts).
//
// Unlike the app updater — which pulls from our own host-pinned release server — this
// downloads from UPSTREAM (gyan.dev's GitHub releases). Integrity therefore rests on a
// PINNED exact-version URL + SHA-256 here, re-verified against the streamed bytes: a
// swapped or tampered upstream asset fails the check and nothing is installed. Bumping
// ffmpeg is a deliberate edit to these three constants in its own commit (recompute the
// hash from the new zip) — the same "pinned decisions" discipline the app version follows.
//
// Licensing note: gyan's "essentials" is a GPL build. That's fine here because AeroFetch
// never redistributes it — it invokes ffmpeg.exe as a separate process (as yt-dlp does)
// and the user fetches the binary from upstream themselves. Swapping to an LGPL build
// (e.g. a BtbN win64 build) is purely a change to FFMPEG_ARCHIVE_URL/SHA-256 below,
// provided the zip still carries ffmpeg.exe + ffprobe.exe under a `*/bin/` path.
export const FFMPEG_VERSION = '8.1.2'
export const FFMPEG_ARCHIVE_URL = `https://github.com/GyanD/codexffmpeg/releases/download/${FFMPEG_VERSION}/ffmpeg-${FFMPEG_VERSION}-essentials_build.zip`
export const FFMPEG_ARCHIVE_SHA256 =
'db580001caa24ac104c8cb856cd113a87b0a443f7bdf47d8c12b1d740584a2ec'
// The setup UI quotes ~105 MB for this archive; keep that copy in sync when bumping above.
// Hosts the archive download may touch, HTTPS-only, re-checked on EVERY redirect hop
// (github.com 302s a release asset to release-assets.githubusercontent.com; the older
// objects.githubusercontent.com is kept for resilience). Anything off this list fails safe.
export const FFMPEG_TRUSTED_HOSTS = [
'github.com',
'release-assets.githubusercontent.com',
'objects.githubusercontent.com'
] as const