Compare commits
4 Commits
v0.1.3
...
8bcdea9e4a
| Author | SHA1 | Date | |
|---|---|---|---|
| 8bcdea9e4a | |||
| 7804285dec | |||
| 4a7029cea6 | |||
| 7317042e8d |
@@ -9,6 +9,17 @@
|
|||||||
// and never tries to resolve the Tauri APIs. Offline-first: a failed check (no
|
// and never tries to resolve the Tauri APIs. Offline-first: a failed check (no
|
||||||
// network — the appliance is usually offline) is swallowed; updates only happen
|
// network — the appliance is usually offline) is swallowed; updates only happen
|
||||||
// when someone has brought the box online (e.g. a phone hotspot) on purpose.
|
// when someone has brought the box online (e.g. a phone hotspot) on purpose.
|
||||||
|
//
|
||||||
|
// A release build's console.error is invisible with no way to attach devtools
|
||||||
|
// in the field (kiosk mode blocks the context menu; this WebKitGTK build's
|
||||||
|
// remote inspector doesn't answer standard discovery endpoints either — both
|
||||||
|
// confirmed dead ends 2026-09-03). logClient() ships straight to the
|
||||||
|
// server-side app_logs store regardless of the client's console-forward log
|
||||||
|
// level (that gate is meant for noisy console chatter, not this), so a real
|
||||||
|
// post-accept install failure is visible via wiki/concepts/app-logs.md /
|
||||||
|
// LogsViewer.tsx without needing a terminal or devtools at all.
|
||||||
|
|
||||||
|
import { logClient } from "./logger.js";
|
||||||
|
|
||||||
/** True when running inside the Tauri webview (not a normal browser). */
|
/** True when running inside the Tauri webview (not a normal browser). */
|
||||||
function inTauri(): boolean {
|
function inTauri(): boolean {
|
||||||
@@ -42,13 +53,24 @@ export async function checkForDesktopUpdate(
|
|||||||
// Download + install the signed update (signature verified against the
|
// Download + install the signed update (signature verified against the
|
||||||
// pubkey in tauri.conf.json), then relaunch into the new version.
|
// pubkey in tauri.conf.json), then relaunch into the new version.
|
||||||
try {
|
try {
|
||||||
await update.downloadAndInstall();
|
await update.downloadAndInstall((progress) => {
|
||||||
|
logClient({
|
||||||
|
level: "info",
|
||||||
|
message: `desktop update download progress: ${progress.event}`,
|
||||||
|
context: { kind: "desktop_update_progress", version: update.version, event: progress.event },
|
||||||
|
});
|
||||||
|
});
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
// A real update WAS found and accepted — this is a genuine install
|
// A real update WAS found and accepted — this is a genuine install
|
||||||
// failure (bad signature, corrupted download, disk/permission issue),
|
// failure (bad signature, corrupted download, disk/permission issue),
|
||||||
// not "offline". Surface it instead of silently reverting to the old
|
// not "offline". Surface it instead of silently reverting to the old
|
||||||
// version with no explanation.
|
// version with no explanation.
|
||||||
console.error("desktop update download/install failed:", err);
|
logClient({
|
||||||
|
level: "error",
|
||||||
|
message: `desktop update download/install failed: ${err instanceof Error ? err.message : String(err)}`,
|
||||||
|
stack: err instanceof Error ? err.stack : undefined,
|
||||||
|
context: { kind: "desktop_update_install_failed", version: update.version },
|
||||||
|
});
|
||||||
throw err;
|
throw err;
|
||||||
}
|
}
|
||||||
const { relaunch } = await import("@tauri-apps/plugin-process");
|
const { relaunch } = await import("@tauri-apps/plugin-process");
|
||||||
@@ -56,7 +78,13 @@ export async function checkForDesktopUpdate(
|
|||||||
} catch (err) {
|
} catch (err) {
|
||||||
// Offline / endpoint unreachable / no update server yet → ignore. The app
|
// Offline / endpoint unreachable / no update server yet → ignore. The app
|
||||||
// keeps running on the current version; checking again next launch. Still
|
// keeps running on the current version; checking again next launch. Still
|
||||||
// log it so a real install failure (rethrown above) isn't invisible.
|
// log it (info, not error — this path is expected/normal far more often
|
||||||
console.warn("desktop update check/apply skipped:", err);
|
// than it's a real problem) so a real install failure (rethrown above,
|
||||||
|
// logged as error) isn't lost among routine offline checks.
|
||||||
|
logClient({
|
||||||
|
level: "info",
|
||||||
|
message: `desktop update check/apply skipped: ${err instanceof Error ? err.message : String(err)}`,
|
||||||
|
context: { kind: "desktop_update_skipped" },
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -62,7 +62,13 @@ class TauriSocketAdapter implements PlatformSocket {
|
|||||||
try {
|
try {
|
||||||
const { default: TauriWebSocket } = await import("@tauri-apps/plugin-websocket");
|
const { default: TauriWebSocket } = await import("@tauri-apps/plugin-websocket");
|
||||||
if (this.#closed) return; // close() called before connect resolved
|
if (this.#closed) return; // close() called before connect resolved
|
||||||
const conn = await TauriWebSocket.connect(url);
|
// Runs on Tauri's native (Rust) side, NOT inside the webview page — there
|
||||||
|
// is no page context to auto-attach an Origin header the way a real
|
||||||
|
// browser WebSocket would. The server's anti-CSWSH check (routes/ws.ts)
|
||||||
|
// rejects any handshake with a missing/mismatched Origin, so it must be
|
||||||
|
// set explicitly here to match what WS_ALLOWED_ORIGINS expects
|
||||||
|
// (tauri://localhost — see apps/server/.env.example).
|
||||||
|
const conn = await TauriWebSocket.connect(url, { headers: { Origin: "tauri://localhost" } });
|
||||||
if (this.#closed) {
|
if (this.#closed) {
|
||||||
void conn.disconnect();
|
void conn.disconnect();
|
||||||
return;
|
return;
|
||||||
@@ -78,7 +84,8 @@ class TauriSocketAdapter implements PlatformSocket {
|
|||||||
// routes/ws.ts) — nothing else is expected.
|
// routes/ws.ts) — nothing else is expected.
|
||||||
});
|
});
|
||||||
this.onopen?.();
|
this.onopen?.();
|
||||||
} catch {
|
} catch (err) {
|
||||||
|
console.error("Tauri WebSocket connect failed:", url, err);
|
||||||
this.onerror?.();
|
this.onerror?.();
|
||||||
this.onclose?.();
|
this.onclose?.();
|
||||||
}
|
}
|
||||||
|
|||||||
+10
-4
@@ -49,10 +49,13 @@ REGISTRY=git.infra.msai.al/mca/parking_solution
|
|||||||
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
|
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
|
||||||
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
|
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
|
||||||
# exists as the pointer; we deploy the sha, not the mover.
|
# exists as the pointer; we deploy the sha, not the mover.
|
||||||
TAG=stage-28bd838
|
TAG=stage-7317042
|
||||||
COOKIE_SECURE=0
|
COOKIE_SECURE=0
|
||||||
VISION_ENABLED=1
|
VISION_ENABLED=1
|
||||||
WS_ALLOWED_ORIGINS=
|
# Desktop app WS handshake: Origin is tauri://localhost (set explicitly by
|
||||||
|
# platform-ws.ts, since the native WS plugin has no page context to auto-attach
|
||||||
|
# one). Linux may also send http://tauri.localhost. See routes/ws.ts anti-CSWSH check.
|
||||||
|
WS_ALLOWED_ORIGINS=tauri://localhost,http://tauri.localhost
|
||||||
JWT_SECRET=[[park_buzi_jwt_secret]]
|
JWT_SECRET=[[park_buzi_jwt_secret]]
|
||||||
EVENT_SIGNING_KEY=[[park_buzi_event_signing_key]]
|
EVENT_SIGNING_KEY=[[park_buzi_event_signing_key]]
|
||||||
BACKUP_KEY=[[park_buzi_backup_key]]
|
BACKUP_KEY=[[park_buzi_backup_key]]
|
||||||
@@ -79,10 +82,13 @@ REGISTRY=git.infra.msai.al/mca/parking_solution
|
|||||||
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
|
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
|
||||||
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
|
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
|
||||||
# exists as the pointer; we deploy the sha, not the mover.
|
# exists as the pointer; we deploy the sha, not the mover.
|
||||||
TAG=stage-28bd838
|
TAG=stage-7317042
|
||||||
COOKIE_SECURE=0
|
COOKIE_SECURE=0
|
||||||
VISION_ENABLED=1
|
VISION_ENABLED=1
|
||||||
WS_ALLOWED_ORIGINS=
|
# Desktop app WS handshake: Origin is tauri://localhost (set explicitly by
|
||||||
|
# platform-ws.ts, since the native WS plugin has no page context to auto-attach
|
||||||
|
# one). Linux may also send http://tauri.localhost. See routes/ws.ts anti-CSWSH check.
|
||||||
|
WS_ALLOWED_ORIGINS=tauri://localhost,http://tauri.localhost
|
||||||
JWT_SECRET=[[park_2_jwt_secret]]
|
JWT_SECRET=[[park_2_jwt_secret]]
|
||||||
EVENT_SIGNING_KEY=[[park_2_event_signing_key]]
|
EVENT_SIGNING_KEY=[[park_2_event_signing_key]]
|
||||||
BACKUP_KEY=[[park_2_backup_key]]
|
BACKUP_KEY=[[park_2_backup_key]]
|
||||||
|
|||||||
@@ -164,6 +164,20 @@ Per the user's choices — the operator **keeps OS access** (no fullscreen lockd
|
|||||||
- `logger.ts`'s `flushBeacon()` (page-hide `navigator.sendBeacon`) is a native browser API with no
|
- `logger.ts`'s `flushBeacon()` (page-hide `navigator.sendBeacon`) is a native browser API with no
|
||||||
Tauri equivalent — it still drops silently in the desktop shell on unload. Accepted: the regular
|
Tauri equivalent — it still drops silently in the desktop shell on unload. Accepted: the regular
|
||||||
4s-interval flush (now fixed, routes through `platformFetch`) covers the common case.
|
4s-interval flush (now fixed, routes through `platformFetch`) covers the common case.
|
||||||
|
- **Gotcha (found immediately after shipping the above): the native WS plugin sends no `Origin`
|
||||||
|
header.** `tauri-plugin-websocket`'s `connect()` runs on Tauri's Rust side, not inside the
|
||||||
|
webview page — there's no page context to auto-attach `Origin: tauri://localhost` the way a real
|
||||||
|
browser `WebSocket` would. The server's anti-CSWSH check (`routes/ws.ts`, `isAllowedOrigin`)
|
||||||
|
treats a missing Origin as untrusted and 403s the handshake before touching auth — the live feed
|
||||||
|
showed **"JASHTË LINJË"** (offline) in the desktop app while the browser showed **"LIVE"**, same
|
||||||
|
server, same moment. **Fix (two parts, both needed):** `platform-ws.ts`'s `connect()` call now
|
||||||
|
passes `{ headers: { Origin: "tauri://localhost" } }` explicitly; separately, `komodo/
|
||||||
|
resources.toml`'s booth Stacks had `WS_ALLOWED_ORIGINS=` **empty** in production (despite
|
||||||
|
`.env.example` documenting `tauri://localhost,http://tauri.localhost` as required) — even a
|
||||||
|
correct Origin header is useless if the server's allowlist doesn't include it. Both fixed
|
||||||
|
together; a `resources.toml` change still needs a Komodo sync + Stack redeploy to take effect on
|
||||||
|
a live booth, it isn't automatic from a git push alone — and see [[fleet-deployment-komodo]] for
|
||||||
|
a real ResourceSync-branch gotcha this exact fix ran into.
|
||||||
- **`VITE_API_BASE` — desktop vs. browser (regression found + fixed 2026-09-03):**
|
- **`VITE_API_BASE` — desktop vs. browser (regression found + fixed 2026-09-03):**
|
||||||
`apps/web/.env.production` (committed, shared by both builds) sets `VITE_API_BASE=` (empty) — this
|
`apps/web/.env.production` (committed, shared by both builds) sets `VITE_API_BASE=` (empty) — this
|
||||||
is correct for the **browser/booth** build (Fastify same-origin, stays relative) since commit
|
is correct for the **browser/booth** build (Fastify same-origin, stays relative) since commit
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
type: decision
|
type: decision
|
||||||
tags: [parking, deployment, fleet, komodo, netbird, offline-first, threat-model]
|
tags: [parking, deployment, fleet, komodo, netbird, offline-first, threat-model]
|
||||||
sources: []
|
sources: []
|
||||||
updated: 2026-07-07
|
updated: 2026-09-03
|
||||||
status: settled
|
status: settled
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -192,3 +192,32 @@ FILE is read from, each stack's `branch` picks its compose files, `TAG` picks th
|
|||||||
secrets even in the lab (blast radius). The lab box earned its keep immediately: it caught the
|
secrets even in the lab (blast radius). The lab box earned its keep immediately: it caught the
|
||||||
USB close-cancel truncation, the printer/controller wizard gate, and the Periphery v2.2.0
|
USB close-cancel truncation, the printer/controller wizard gate, and the Periphery v2.2.0
|
||||||
root_directory default before any of them reached a real booth ([[appliance-provisioning]] §7a).
|
root_directory default before any of them reached a real booth ([[appliance-provisioning]] §7a).
|
||||||
|
|
||||||
|
## ResourceSync branch drift — the exact gotcha this page already warned about (2026-09-03)
|
||||||
|
|
||||||
|
This page's own §"park-lab" note (2026-07-07) already spelled it out: *"the ResourceSync's own
|
||||||
|
branch only governs where the FILE is read from"* — independent of any `[[stack]]`'s own `branch`
|
||||||
|
field. It bit anyway. `resource-sync-park-systems` in Komodo Core was pointed at **`dev`**, while
|
||||||
|
`park-buzi` and `park-2` are `stage`-tier Stacks (`branch = "stage"`, pinned `TAG=stage-<sha>`, per
|
||||||
|
the promotion-tiers model above). `resources.toml` had been byte-identical on `dev` and `stage`
|
||||||
|
since park-buzi's Stack was first written, so this had **zero observable effect for months** — until
|
||||||
|
a desktop-app debugging session (see [[desktop-shell-tauri]]) landed 9 real commits on `dev`
|
||||||
|
(including a `WS_ALLOWED_ORIGINS` fix) that were never merged to `stage`, creating the first genuine
|
||||||
|
divergence between the two branches.
|
||||||
|
|
||||||
|
**Symptom:** merged `dev` → `stage`, pushed, bumped `TAG` in `resources.toml` on `stage`, committed,
|
||||||
|
pushed — then destroyed + recreated the `park-2` Stack in Komodo Core and it STILL came back running
|
||||||
|
the old image. Every sync was silently re-reading `resources.toml` from `dev` (which still had the
|
||||||
|
stale `TAG`), overwriting the correct value just committed on `stage`. No error, no warning — the
|
||||||
|
sync just quietly did what it was configured to do, from the wrong branch.
|
||||||
|
|
||||||
|
**Fix:** pointed `resource-sync-park-systems` at `stage` in Komodo Core's UI (Sync config → branch
|
||||||
|
field), then re-synced + redeployed `park-2` — confirmed via `/api/version` (previously 404,
|
||||||
|
proving a stale image; correctly 401-auth-gated after the fix, proving the new image + route exist).
|
||||||
|
|
||||||
|
**Standing lesson, now written twice:** a `[[stack]]`'s promotion tier (which branch its own
|
||||||
|
`branch`/`TAG` fields track) and the ResourceSync resource's own git branch are **two independently
|
||||||
|
configured settings in Komodo Core — nothing enforces they agree**, and a mismatch is invisible
|
||||||
|
until the two branches' `resources.toml` actually diverge. **Check this FIRST** whenever a
|
||||||
|
redeploy doesn't pick up an expected `resources.toml` change, before assuming the change itself,
|
||||||
|
the CI build, or the deploy step is broken.
|
||||||
|
|||||||
+29
@@ -2779,3 +2779,32 @@ HTTP/WS client instead of the webview's own: tauri-plugin-http (a genuine fetch(
|
|||||||
into api.ts/logger.ts via a new platformFetch() in origin.ts) and tauri-plugin-websocket (NOT a
|
into api.ts/logger.ts via a new platformFetch() in origin.ts) and tauri-plugin-websocket (NOT a
|
||||||
drop-in — async/listener API — adapted behind a native-WebSocket-shaped interface in the new
|
drop-in — async/listener API — adapted behind a native-WebSocket-shaped interface in the new
|
||||||
platform-ws.ts so use-live-feed.ts needed no changes). Full detail on [[desktop-shell-tauri]].
|
platform-ws.ts so use-live-feed.ts needed no changes). Full detail on [[desktop-shell-tauri]].
|
||||||
|
|
||||||
|
## [2026-09-03] fix | Desktop live feed offline: native WS plugin sends no Origin, prod allowlist was empty
|
||||||
|
|
||||||
|
Login worked after the mixed-content fix, but the live feed showed offline in the desktop app while
|
||||||
|
the browser showed LIVE, same server. tauri-plugin-websocket's connect() runs on Tauri's Rust side,
|
||||||
|
not inside the webview page, so it never auto-attaches an Origin header — routes/ws.ts's anti-CSWSH
|
||||||
|
check treats a missing Origin as untrusted and 403s before auth. Compounded by a second, independent
|
||||||
|
gap: komodo/resources.toml's booth Stacks had WS_ALLOWED_ORIGINS= empty in production, despite
|
||||||
|
.env.example documenting tauri://localhost as required for the desktop app. Fixed both: platform-ws.ts
|
||||||
|
now passes Origin: tauri://localhost explicitly in connect()'s headers; resources.toml's two Stacks
|
||||||
|
get the real allowlist. Needs a Komodo sync + redeploy to reach a live booth, not just a git push.
|
||||||
|
Also confirmed the "update downloads then nothing happens" report was an older pre-fix build (v0.1.2)
|
||||||
|
self-updating — expected, not a new bug; v0.1.3 carries the error-logging fix from the mixed-content
|
||||||
|
commit and should surface a real error going forward. Full detail on [[desktop-shell-tauri]].
|
||||||
|
|
||||||
|
## [2026-09-03] fix | Update failures were invisible: console-forward gate blocked the error logging
|
||||||
|
|
||||||
|
The desktop-updater.ts error logging added earlier this session used console.error/console.warn,
|
||||||
|
but logger.ts only forwards console output to the server when the client log level is debug/trace
|
||||||
|
(default: info) — so the "fix" never actually surfaced anything, and a real v0.1.3→v0.1.4 update
|
||||||
|
failure showed zero logs anywhere, sending debugging in circles (a WebKit remote-inspector attempt
|
||||||
|
via WEBKIT_INSPECTOR_SERVER also dead-ended — this build doesn't answer standard discovery
|
||||||
|
endpoints). Fixed by calling logClient() directly in desktop-updater.ts, unconditionally, bypassing
|
||||||
|
the console-forward gate entirely — a genuine post-accept install failure now always reaches
|
||||||
|
app_logs regardless of client log level. Also added download-progress logging. Separately: found
|
||||||
|
and fixed a real, pre-existing Komodo ResourceSync misconfig (resource-sync-park-systems pointed at
|
||||||
|
`dev`, not `stage`, silently reading resources.toml from the wrong branch for months with zero
|
||||||
|
effect until dev/stage first diverged today) — full writeup on [[fleet-deployment-komodo]], which
|
||||||
|
had already warned about exactly this gotcha back in 2026-07-07 and it happened anyway.
|
||||||
|
|||||||
Reference in New Issue
Block a user