mirror of
https://github.com/tauri-apps/plugins-workspace.git
synced 2026-09-28 21:51:47 +02:00
feat(updater)!: add option to use insecure transport protocol (#1814)
This commit is contained in:
1 parent
e564e2aa91
commit
04a0aea0ab
5 files changed
+71
-31
No files matched your search
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
"updater": patch
|
||||||
|
---
|
||||||
|
|
||||||
|
**Breaking change**, Changed `UpdaterBuilder::endpoints` method to return a `Result`.
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
"updater": patch
|
||||||
|
---
|
||||||
|
|
||||||
|
Add `dangerousInsecureTransportProtocol` config option to allow using insecure transport protocols, like `http`
|
||||||
@@ -91,47 +91,69 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Updater configuration.
|
/// Updater configuration.
|
||||||
#[derive(Debug, Clone, Deserialize, Default)]
|
#[derive(Debug, Clone, Default)]
|
||||||
#[serde(rename_all = "camelCase")]
|
|
||||||
pub struct Config {
|
pub struct Config {
|
||||||
|
/// Dangerously allow using insecure transport protocols for update endpoints.
|
||||||
|
pub dangerous_insecure_transport_protocol: bool,
|
||||||
/// Updater endpoints.
|
/// Updater endpoints.
|
||||||
#[serde(default)]
|
pub endpoints: Vec<Url>,
|
||||||
pub endpoints: Vec<UpdaterEndpoint>,
|
|
||||||
/// Signature public key.
|
/// Signature public key.
|
||||||
pub pubkey: String,
|
pub pubkey: String,
|
||||||
/// The Windows configuration for the updater.
|
/// The Windows configuration for the updater.
|
||||||
pub windows: Option<WindowsConfig>,
|
pub windows: Option<WindowsConfig>,
|
||||||
}
|
}
|
||||||
|
|
||||||
/// A URL to an updater server.
|
impl<'de> Deserialize<'de> for Config {
|
||||||
///
|
|
||||||
/// The URL must use the `https` scheme on production.
|
|
||||||
#[derive(Debug, PartialEq, Eq, Clone)]
|
|
||||||
pub struct UpdaterEndpoint(pub Url);
|
|
||||||
|
|
||||||
impl std::fmt::Display for UpdaterEndpoint {
|
|
||||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
|
||||||
write!(f, "{}", self.0)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<'de> Deserialize<'de> for UpdaterEndpoint {
|
|
||||||
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
|
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
|
||||||
where
|
where
|
||||||
D: Deserializer<'de>,
|
D: Deserializer<'de>,
|
||||||
{
|
{
|
||||||
let url = Url::deserialize(deserializer)?;
|
#[derive(Deserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
if url.scheme() != "https" {
|
pub struct Config {
|
||||||
#[cfg(debug_assertions)]
|
#[serde(default, alias = "dangerous-insecure-transport-protocol")]
|
||||||
eprintln!("[\x1b[33mWARNING\x1b[0m] The configured updater endpoint doesn't use `https` protocol. This is allowed in development but will fail in release builds.");
|
pub dangerous_insecure_transport_protocol: bool,
|
||||||
|
#[serde(default)]
|
||||||
#[cfg(not(debug_assertions))]
|
pub endpoints: Vec<Url>,
|
||||||
return Err(serde::de::Error::custom(
|
pub pubkey: String,
|
||||||
"The configured updater endpoint must use the `https` protocol.",
|
pub windows: Option<WindowsConfig>,
|
||||||
));
|
|
||||||
}
|
}
|
||||||
|
|
||||||
Ok(Self(url))
|
let config = Config::deserialize(deserializer)?;
|
||||||
|
|
||||||
|
validate_endpoints(
|
||||||
|
&config.endpoints,
|
||||||
|
config.dangerous_insecure_transport_protocol,
|
||||||
|
)
|
||||||
|
.map_err(serde::de::Error::custom)?;
|
||||||
|
|
||||||
|
Ok(Self {
|
||||||
|
dangerous_insecure_transport_protocol: config.dangerous_insecure_transport_protocol,
|
||||||
|
endpoints: config.endpoints,
|
||||||
|
pubkey: config.pubkey,
|
||||||
|
windows: config.windows,
|
||||||
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub(crate) fn validate_endpoints(
|
||||||
|
endpoints: &[Url],
|
||||||
|
dangerous_insecure_transport_protocol: bool,
|
||||||
|
) -> crate::Result<()> {
|
||||||
|
if !dangerous_insecure_transport_protocol {
|
||||||
|
for url in endpoints {
|
||||||
|
#[cfg(debug_assertions)]
|
||||||
|
#[cfg(debug_assertions)]
|
||||||
|
eprintln!("[\x1b[33mWARNING\x1b[0m] The updater endpoint \"{url}\" doesn't use `https` protocol. This is allowed in development but will fail in release builds.");
|
||||||
|
#[cfg(debug_assertions)]
|
||||||
|
eprintln!("[\x1b[33mWARNING\x1b[0m] if this is a desired behavior, you can enable `dangerousInsecureTransportProtocol` in the plugin configuration");
|
||||||
|
|
||||||
|
#[cfg(not(debug_assertions))]
|
||||||
|
if url.scheme() != "https" {
|
||||||
|
return Err(crate::Error::InsecureTransportProtocol);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
@@ -71,6 +71,9 @@ pub enum Error {
|
|||||||
InvalidHeaderValue(#[from] http::header::InvalidHeaderValue),
|
InvalidHeaderValue(#[from] http::header::InvalidHeaderValue),
|
||||||
#[error(transparent)]
|
#[error(transparent)]
|
||||||
InvalidHeaderName(#[from] http::header::InvalidHeaderName),
|
InvalidHeaderName(#[from] http::header::InvalidHeaderName),
|
||||||
|
/// The configured updater endpoint must use a secure protocol like `https`
|
||||||
|
#[error("The configured updater endpoint must use a secure protocol like `https`.")]
|
||||||
|
InsecureTransportProtocol,
|
||||||
#[error(transparent)]
|
#[error(transparent)]
|
||||||
Tauri(#[from] tauri::Error),
|
Tauri(#[from] tauri::Error),
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -148,9 +148,14 @@ impl UpdaterBuilder {
|
|||||||
self
|
self
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn endpoints(mut self, endpoints: Vec<Url>) -> Self {
|
pub fn endpoints(mut self, endpoints: Vec<Url>) -> Result<Self> {
|
||||||
|
crate::config::validate_endpoints(
|
||||||
|
&endpoints,
|
||||||
|
self.config.dangerous_insecure_transport_protocol,
|
||||||
|
)?;
|
||||||
|
|
||||||
self.endpoints.replace(endpoints);
|
self.endpoints.replace(endpoints);
|
||||||
self
|
Ok(self)
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn executable_path<P: AsRef<Path>>(mut self, p: P) -> Self {
|
pub fn executable_path<P: AsRef<Path>>(mut self, p: P) -> Self {
|
||||||
@@ -219,7 +224,7 @@ impl UpdaterBuilder {
|
|||||||
pub fn build(self) -> Result<Updater> {
|
pub fn build(self) -> Result<Updater> {
|
||||||
let endpoints = self
|
let endpoints = self
|
||||||
.endpoints
|
.endpoints
|
||||||
.unwrap_or_else(|| self.config.endpoints.iter().map(|e| e.0.clone()).collect());
|
.unwrap_or_else(|| self.config.endpoints.clone());
|
||||||
|
|
||||||
if endpoints.is_empty() {
|
if endpoints.is_empty() {
|
||||||
return Err(Error::EmptyEndpoints);
|
return Err(Error::EmptyEndpoints);
|
||||||
|
|||||||
Reference in new issue
Block a user