Skip to content

feat(release): verify embedded Web UI pin - #9

Merged
zijiren233 merged 3 commits into
synctv-org:mainfrom
zijiren233:feat/web-ui-pin-validation
Aug 23, 2026
Merged

zijiren233 merged 3 commits into
synctv-org:mainfrom
zijiren233:feat/web-ui-pin-validation

Conversation

@zijiren233

Copy link
Copy Markdown
Contributor

Summary

  • verify that a release backend's synctv-web-ui/web-ui.toml uses the manifest's App repository and full commit
  • require the production Git revision to equal the pinned commit, preventing floating branch or tag inputs in release builds
  • add focused Ruby tests, syntax checks, operator documentation, and the pin check to release preflight

Verification

  • make validate
  • make actionlint
  • real GitHub preflight against backend PR 433 and App PR 52 commits, including component versions, workflow presence, and Web UI pin identity

Backend PR: synctv-org/synctv#433

App PR: synctv-org/synctv-app#52

zijiren233 added a commit to synctv-org/synctv that referenced this pull request Aug 23, 2026
## Summary

- add a versioned playback client profile for browser/runtime protocol,
container, codec, header, proxy, insecure-media, and P2P-loader
capabilities
- generate compatible direct and proxy resources inside each provider
and return a structured incompatibility error when route policy leaves
no viable result
- force provider proxy delivery for browser-forbidden headers, including
affected Bilibili variants, while preserving explicit direct-only
failures
- keep legacy clients compatible and isolate capability-aware playback
cache entries
- serve `/oauth2/callback` through the same Flutter SPA entry point and
keep public discovery anonymous

## Reproducible Web UI

- move Flutter acquisition/build, source configuration, asset manifests,
Brotli/gzip compression, and compile-time embedding into the independent
`synctv-web-ui` crate
- support prebuilt distributions, local projects, and Git sources pinned
to an immutable full commit, with an ignored local override
- fingerprint source, Flutter version, build arguments, dart-defines,
builder generation, output, and compression settings
- validate cached Git repository/revision/commit identity, support
offline cache reuse, and rebuild only when relevant inputs change
- pin and checksum the Flutter SDK in the Docker Web asset stage;
backend-only builds require no Flutter, Git fetch, or network
- serve embedded assets with ETags, compression negotiation, CSP, cache
policy, Origin/CORS handling, and SPA fallback outside API/media routes

## Verification

- `cargo fmt --all -- --check`
- workspace `cargo check`, test/doc-test, and all-targets Clippy with
warnings denied
- provider tests: 200 passed, 1 ignored
- OAuth core/API tests: 72 + 16 passed
- `synctv-web-ui`: 10 passed
- `synctv-api-http --features web-ui`: 12 passed
- default Git source cold build from the pinned App commit, followed by
offline hot-cache reuse in about 1.1 seconds
- `cargo check -p synctv --features web-ui` and `docker buildx build
--check .`
- real Chrome playback, P2P, OAuth/Casdoor, multi-user sync, chat,
media, playlist, upload, settings, and playback-history flows

Companion frontend PR: synctv-org/synctv-app#52

Release pin validation:
synctv-org/synctv-release#9
@zijiren233
zijiren233 merged commit 202bce9 into synctv-org:main Aug 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant