feat(web): make settings an inline route and add the capability pages… #5
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Desktop Release | |
| on: | |
| push: | |
| tags: ['desktop-v*'] | |
| workflow_dispatch: {} | |
| permissions: | |
| contents: write | |
| concurrency: | |
| group: desktop-release-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| mac: | |
| runs-on: macos-15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # pinned from v4 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: true | |
| - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # pinned from v6 | |
| - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # pinned from v6 | |
| with: | |
| node-version-file: .nvmrc | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Stamp desktop version for tag builds | |
| if: startsWith(github.ref, 'refs/tags/desktop-v') | |
| env: | |
| TAG_NAME: ${{ github.ref_name }} | |
| run: | | |
| export DESKTOP_VERSION="${TAG_NAME#desktop-v}" | |
| node -e 'const fs = require("node:fs"); const path = "apps/desktop/package.json"; const packageJson = JSON.parse(fs.readFileSync(path, "utf8")); packageJson.version = process.env.DESKTOP_VERSION; fs.writeFileSync(path, `${JSON.stringify(packageJson, null, 2)}\n`);' | |
| - name: Build workspace | |
| run: pnpm --workspace-root run build | |
| - name: Stage desktop runtime | |
| working-directory: apps/desktop | |
| run: node --import tsx scripts/stage-runtime.ts | |
| # On a desktop-v* tag, --publish always creates or updates the release | |
| # in pythinker-desktop-releases with the GitHub App token below. | |
| # Without Developer ID signing secrets, electron-builder publishes an | |
| # ad-hoc/self-signed app. macOS auto-update will not accept unsigned updates, | |
| # but this still proves packaging and the feed shape. | |
| # An unset GitHub secret interpolates to an empty string, and | |
| # electron-builder resolves an empty CSC_LINK as a certificate path | |
| # (path.resolve(appDir, '') === appDir), failing with "not a file". | |
| # Export only the variables that carry a value. | |
| - name: Resolve macOS signing credentials | |
| shell: bash | |
| env: | |
| IN_CSC_LINK: ${{ secrets.MAC_CSC_LINK }} | |
| IN_CSC_KEY_PASSWORD: ${{ secrets.MAC_CSC_KEY_PASSWORD }} | |
| IN_APPLE_ID: ${{ secrets.APPLE_ID }} | |
| IN_APPLE_APP_SPECIFIC_PASSWORD: ${{ secrets.APPLE_APP_SPECIFIC_PASSWORD }} | |
| IN_APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} | |
| run: | | |
| for name in CSC_LINK CSC_KEY_PASSWORD APPLE_ID APPLE_APP_SPECIFIC_PASSWORD APPLE_TEAM_ID; do | |
| input="IN_${name}" | |
| value="${!input:-}" | |
| if [ -n "$value" ]; then printf '%s<<__EOF__\n%s\n__EOF__\n' "$name" "$value" >> "$GITHUB_ENV"; fi | |
| done | |
| if [ -z "${IN_CSC_LINK:-}" ]; then | |
| echo 'CSC_IDENTITY_AUTO_DISCOVERY=false' >> "$GITHUB_ENV" | |
| echo 'No macOS signing certificate configured; building unsigned.' | |
| fi | |
| - name: Mint releases-repo token | |
| id: releases_token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # pinned from v3.2.0 | |
| with: | |
| app-id: ${{ secrets.DESKTOP_RELEASES_APP_ID }} | |
| private-key: ${{ secrets.DESKTOP_RELEASES_APP_PRIVATE_KEY }} | |
| owner: PyModel | |
| repositories: pythinker-desktop-releases | |
| - name: Package and publish desktop release | |
| working-directory: apps/desktop | |
| run: pnpm exec electron-builder --mac dmg zip --publish always | |
| env: | |
| GH_TOKEN: ${{ steps.releases_token.outputs.token }} | |
| - name: Verify macOS packaged update configuration | |
| shell: bash | |
| run: | | |
| app_bundle="$(find apps/desktop/dist -maxdepth 2 -type d -name '*.app' -print -quit)" | |
| if [ -z "$app_bundle" ]; then | |
| echo 'macOS application bundle not found' >&2 | |
| exit 1 | |
| fi | |
| test -f "$app_bundle/Contents/Resources/app-update.yml" | |
| - name: Upload macOS artifacts for manual runs | |
| if: github.event_name == 'workflow_dispatch' | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # pinned from v7 | |
| with: | |
| name: desktop-macos | |
| path: | | |
| apps/desktop/dist/*.dmg | |
| apps/desktop/dist/*.zip | |
| apps/desktop/dist/latest-mac.yml | |
| if-no-files-found: error | |
| windows: | |
| runs-on: windows-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # pinned from v4 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: true | |
| - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # pinned from v6 | |
| - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # pinned from v6 | |
| with: | |
| node-version-file: .nvmrc | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Stamp desktop version for tag builds | |
| if: startsWith(github.ref, 'refs/tags/desktop-v') | |
| shell: bash | |
| env: | |
| TAG_NAME: ${{ github.ref_name }} | |
| run: | | |
| export DESKTOP_VERSION="${TAG_NAME#desktop-v}" | |
| node -e 'const fs = require("node:fs"); const path = "apps/desktop/package.json"; const packageJson = JSON.parse(fs.readFileSync(path, "utf8")); packageJson.version = process.env.DESKTOP_VERSION; fs.writeFileSync(path, `${JSON.stringify(packageJson, null, 2)}\n`);' | |
| - name: Build workspace | |
| run: pnpm --workspace-root run build | |
| - name: Stage desktop runtime | |
| working-directory: apps/desktop | |
| run: node --import tsx scripts/stage-runtime.ts | |
| # Only non-empty WIN_CSC_* signing secrets are exported. Without them, | |
| # Windows artifacts are unsigned and installers trigger a SmartScreen | |
| # warning on first run. | |
| - name: Resolve Windows signing credentials | |
| shell: bash | |
| env: | |
| IN_WIN_CSC_LINK: ${{ secrets.WIN_CSC_LINK }} | |
| IN_WIN_CSC_KEY_PASSWORD: ${{ secrets.WIN_CSC_KEY_PASSWORD }} | |
| run: | | |
| for name in WIN_CSC_LINK WIN_CSC_KEY_PASSWORD; do | |
| input="IN_${name}" | |
| value="${!input:-}" | |
| if [ -n "$value" ]; then printf '%s<<__EOF__\n%s\n__EOF__\n' "$name" "$value" >> "$GITHUB_ENV"; fi | |
| done | |
| - name: Resolve Azure signing configuration | |
| shell: bash | |
| env: | |
| IN_AZURE_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }} | |
| IN_AZURE_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }} | |
| IN_AZURE_CLIENT_SECRET: ${{ secrets.AZURE_CLIENT_SECRET }} | |
| IN_AZURE_SIGNING_ENDPOINT: ${{ secrets.AZURE_SIGNING_ENDPOINT }} | |
| IN_AZURE_SIGNING_ACCOUNT: ${{ secrets.AZURE_SIGNING_ACCOUNT }} | |
| IN_AZURE_SIGNING_CERT_PROFILE: ${{ secrets.AZURE_SIGNING_CERT_PROFILE }} | |
| IN_AZURE_SIGNING_PUBLISHER_NAME: ${{ secrets.AZURE_SIGNING_PUBLISHER_NAME }} | |
| run: | | |
| for name in AZURE_TENANT_ID AZURE_CLIENT_ID AZURE_CLIENT_SECRET AZURE_SIGNING_ENDPOINT AZURE_SIGNING_ACCOUNT AZURE_SIGNING_CERT_PROFILE AZURE_SIGNING_PUBLISHER_NAME; do | |
| input="IN_${name}" | |
| value="${!input:-}" | |
| if [ -n "$value" ]; then printf '%s<<__EOF__\n%s\n__EOF__\n' "$name" "$value" >> "$GITHUB_ENV"; fi | |
| done | |
| - name: Mint releases-repo token | |
| id: releases_token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # pinned from v3.2.0 | |
| with: | |
| app-id: ${{ secrets.DESKTOP_RELEASES_APP_ID }} | |
| private-key: ${{ secrets.DESKTOP_RELEASES_APP_PRIVATE_KEY }} | |
| owner: PyModel | |
| repositories: pythinker-desktop-releases | |
| - name: Package and publish desktop release | |
| working-directory: apps/desktop | |
| run: node --import tsx scripts/package-win.ts --publish always | |
| env: | |
| GH_TOKEN: ${{ steps.releases_token.outputs.token }} | |
| - name: Verify Windows packaged update configuration | |
| shell: bash | |
| run: test -f apps/desktop/dist/win-unpacked/resources/app-update.yml | |
| - name: Upload Windows artifacts for manual runs | |
| if: github.event_name == 'workflow_dispatch' | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # pinned from v7 | |
| with: | |
| name: desktop-windows | |
| path: | | |
| apps/desktop/dist/*.exe | |
| apps/desktop/dist/latest.yml | |
| if-no-files-found: error |