Commit Graph
3 Commits
Author SHA1 Message Date
Ludy87 ca739e14b0 Harden JRE verification and jlink modules
Tighten JRE/runtime handling and jlink safety.

- frontend/editor/scripts/verify-bundled-jre.mjs: import path.resolve, compute expected release path (src-tauri/runtime/jre/release) and refuse to read any unexpected release file path to avoid accidental/malicious file reads.
- scripts/build-jlink-runtime.ps1: add an allowed jlink module whitelist, sanitize/split the $Modules input, require at least one module, validate requested modules against the whitelist, and pass a safe ModulesArg to --add-modules to prevent injection or unsupported modules.
2026-07-06 09:38:15 +02:00
Ludy87 ca48361d26 Improve desktop build config and Windows support
Rename CACHE to JLINK_REUSE_CACHE for clarity about JAR reuse. Fix desktop:dev:login task to properly pass SECURITY_ENABLELOGIN as env var. Improve Windows compatibility in verify-bundled-jre.mjs by using cmd.exe as Task launcher. Rename desktop_enable_login_flag() to desktop_login_enabled_from_env() for clarity. Add documentation for desktop dev modes and override options. Add comments explaining compression fallback and file permissions handling.
2026-07-06 09:19:15 +02:00
Ludy87 f7c60e1fb4 Add desktop login support and improve jlink build
- Extract Windows jlink runtime building into dedicated PowerShell script (build-jlink-runtime.ps1) to improve maintainability and permission handling
- Add SECURITY_ENABLELOGIN environment variable support in Tauri backend to conditionally enable desktop login
- Enhance JRE verification script to automatically rebuild runtime if missing or outdated
- Add env section and new dev:login task to desktop.yml
- Add cache control (CACHE variable) to optionally remove build artifacts before rebuilding
- Improve error handling and user feedback in verify-bundled-jre.mjs with helper functions
2026-07-06 09:01:23 +02:00