aboutsummaryrefslogtreecommitdiffstats
path: root/packaging/build
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-04 14:33:33 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-04 14:33:33 +0200
commitc2eade6db582966fa7fc3dd037f952baf3ae1cb5 (patch)
treebac7089118c44c748593c20a7c36c3bba74ddbcd /packaging/build
parent40abf0979f93771ccfb58eecb8a6fcc5863ec604 (diff)
downloadmeshbay-c2eade6db582966fa7fc3dd037f952baf3ae1cb5.tar.gz
fix(packaging): actually ship the TMDB token, on Linux and Windows
default.env was empty in every build, for three independent reasons: 1. build-node.sh read QE/node.env, which does not exist. Even pointed at the real file it would have failed: its `grep MESHBAY_TMDB_DEFAULT_TOKEN=` cannot match QE/tmdb.txt, which is a free-form note, not KEY=VALUE. 2. Nothing consumed default.env. packaging/README.md and build-node.sh both claimed `meshbay-node init` copies it to <config>/node.env; grep found the name in exactly two places, the README and the script that writes it. No code implemented the copy, and `EnvironmentFile=-` hid the absence. 3. build-win.ps1 had no env handling at all, so Windows was empty for a different reason than Linux. Now: the build extracts the v4 read token -- tmdb.py sends `Authorization: Bearer`, so it is the JWT, not the 32-char v3 key beside it in the same file -- matching KEY=VALUE first and then by shape, from MESHBAY_TMDB_TOKEN, MESHBAY_TMDB_TOKEN_FILE, QE/node.env, QE/tmdb.txt. It writes default.env 0600 and *fails the build* if no token resolves; MESHBAY_ALLOW_NO_TMDB=1 opts out. An empty default.env is invisible until a user opens Videos and finds no metadata, which is how this shipped empty on two platforms at once. platform.py gains packaged_default_env()/install_node_env()/load_node_env(). init copies the packaged file once, never overwriting an existing node.env, and the daemon loads node.env itself at startup: systemd does this on Linux via EnvironmentFile, but Windows autostart is a Startup-folder .vbs with no equivalent. Already-set variables always win. Also fixes an UnboundLocalError in main(): `config_dir` was assigned at the top of the init branch, which made it function-local for all of main(), while the reset branch calls `config_dir()` as the imported function. init returns before that line, so `meshbay-node reset` could only ever raise. The local is now cfg_dir. Verified end to end on Linux: token baked (239 chars), init writes <config>/node.env 0600 with it. The PowerShell half is written but unrun -- no pwsh on this machine. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DtfG7z6wHWj8RKHCvxQtY1
Diffstat (limited to 'packaging/build')
-rwxr-xr-xpackaging/build/build-node.sh47
1 files changed, 37 insertions, 10 deletions
diff --git a/packaging/build/build-node.sh b/packaging/build/build-node.sh
index bd81096..8970176 100755
--- a/packaging/build/build-node.sh
+++ b/packaging/build/build-node.sh
@@ -45,26 +45,53 @@ ln -sf /opt/meshbay-common/venv/bin/meshbay-node "$ROOT/usr/bin/meshbay-node"
# --- Node-specific assets -------------------------------------------------
mkdir -p "$ROOT/opt/meshbay-node/share"
-# Default env with TMDB token (read at build time).
-# Override with MESHBAY_TMDB_TOKEN_FILE; falls back to QE/node.env (gitignored).
-TMDB_TOKEN_FILE="${MESHBAY_TMDB_TOKEN_FILE:-$REPO/QE/node.env}"
-TMDB_TOKEN=""
-if [ -f "$TMDB_TOKEN_FILE" ]; then
- TMDB_TOKEN=$(grep -oP 'MESHBAY_TMDB_DEFAULT_TOKEN=\K.*' "$TMDB_TOKEN_FILE" || true)
+# Default env with the shared TMDB token, read at build time and copied to
+# <config>/node.env by `meshbay-node init`.
+#
+# tmdb.py sends `Authorization: Bearer`, so this is the v4 *read access token*
+# (a JWT, "eyJ..."), not the 32-char v3 API key that sits beside it in the same
+# note file. Sources, in order: an explicit variable, an explicit file, the
+# KEY=VALUE form, then QE/tmdb.txt -- which is free-form prose, so the token is
+# matched by shape rather than by a label.
+extract_tmdb_token() {
+ local file="$1" tok=""
+ [ -f "$file" ] || return 0
+ tok=$(sed -n 's/^[[:space:]]*MESHBAY_TMDB_DEFAULT_TOKEN[[:space:]]*=[[:space:]]*//p' \
+ "$file" | head -1)
+ [ -n "$tok" ] || tok=$(grep -oE '^eyJ[A-Za-z0-9._-]{40,}$' "$file" | head -1 || true)
+ printf '%s' "$tok" | tr -d '"'"'"'\r'
+}
+
+TMDB_TOKEN="${MESHBAY_TMDB_TOKEN:-}"
+if [ -z "$TMDB_TOKEN" ] && [ -n "${MESHBAY_TMDB_TOKEN_FILE:-}" ]; then
+ TMDB_TOKEN=$(extract_tmdb_token "$MESHBAY_TMDB_TOKEN_FILE")
fi
+[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/node.env")
+[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/tmdb.txt")
+
if [ -n "$TMDB_TOKEN" ]; then
cat > "$ROOT/opt/meshbay-node/share/default.env" <<EOF
# Default environment for meshbay-node.
-# Copied to ~/.config/meshbay/node.env by 'meshbay-node init' if it does not exist.
+# Copied to <config>/node.env by 'meshbay-node init' if it does not exist.
# The operator may override any value there or in the systemd EnvironmentFile.
# TMDB API token for the Videos app (read-only, shared across installations)
MESHBAY_TMDB_DEFAULT_TOKEN=$TMDB_TOKEN
EOF
- echo " TMDB token baked into default.env"
+ chmod 600 "$ROOT/opt/meshbay-node/share/default.env"
+ echo " TMDB token baked into default.env (${#TMDB_TOKEN} chars)"
+elif [ "${MESHBAY_ALLOW_NO_TMDB:-0}" = "1" ]; then
+ echo " !! no TMDB token; default.env left empty (MESHBAY_ALLOW_NO_TMDB=1)" >&2
+ : > "$ROOT/opt/meshbay-node/share/default.env"
else
- echo " !! TMDB token not found in QE/node.env — default.env will be empty" >&2
- touch "$ROOT/opt/meshbay-node/share/default.env"
+ # Failing here is deliberate: an empty default.env is invisible until a user
+ # opens the Videos app and finds no metadata, which is exactly how this
+ # shipped empty on two platforms at once.
+ echo "!! TMDB token not found. Looked at:" >&2
+ echo " \$MESHBAY_TMDB_TOKEN, \$MESHBAY_TMDB_TOKEN_FILE," >&2
+ echo " $REPO/QE/node.env, $REPO/QE/tmdb.txt" >&2
+ echo " Set MESHBAY_ALLOW_NO_TMDB=1 to build without it." >&2
+ exit 1
fi
# --- Systemd units --------------------------------------------------------