aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-client/build/installer.nsh
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-client/build/installer.nsh')
-rw-r--r--packages/meshbay-client/build/installer.nsh30
1 files changed, 17 insertions, 13 deletions
diff --git a/packages/meshbay-client/build/installer.nsh b/packages/meshbay-client/build/installer.nsh
index ef9c82a..2337088 100644
--- a/packages/meshbay-client/build/installer.nsh
+++ b/packages/meshbay-client/build/installer.nsh
@@ -24,8 +24,8 @@
; task when service mode is chosen; their own single elevation otherwise.
; One UAC prompt for an install, never two, never zero;
; - cleanup of whichever of those is outside $INSTDIR on the way out (the
-; Startup .vbs; the scheduled task and firewall rules, together, if the
-; user opts in at uninstall time).
+; Startup .vbs; the scheduled task and firewall rules, together, in one
+; elevation asked for only when one of them is still there).
;
; Deliberately NOT touched:
; - %LOCALAPPDATA%\meshbay\ (node.toml, keystore.enc, unlock.key, data/) --
@@ -268,22 +268,26 @@ Var pid
WriteRegExpandStr HKCU "Environment" "Path" "$1"
SendMessage ${HWND_BROADCAST} ${WM_WININICHANGE} 0 "STR:Environment" /TIMEOUT=5000
- ; Offer to take the firewall rules, and the service task if one was set up,
- ; back out together (needs admin again -- one prompt for both, same as
- ; install). Both underlying removes are no-ops when there is nothing to
- ; remove, so this is safe to run unconditionally regardless of which mode
- ; was chosen. Stale rules/tasks are inert if left, so this is opt-in and
- ; default-No; a silent uninstall skips it entirely. customUnInstall runs
- ; before the files are removed, so service-mode.ps1 is still there.
+ ; The firewall rules, and the service task if one was set up, go too: one
+ ; elevation for both, the UAC prompt alone, no question before it. There
+ ; used to be a Yes/No asking first, default No, so an uninstall left them
+ ; behind unless the person thought to say yes. Both are read unelevated
+ ; first, so a machine where neither is left sees no prompt at all. A
+ ; silent uninstall skips it (it may not raise UI); so does an upgrade,
+ ; whose install keeps both. customUnInstall runs before the files are
+ ; removed, so the scripts are still there.
${IfNot} ${Silent}
${AndIfNot} ${isUpdated}
- MessageBox MB_YESNO|MB_ICONQUESTION \
- "Remove MeshBay's Windows Firewall rules and its boot-time service task, if you set one up? This needs one administrator confirmation. Both are harmless if left." \
- /SD IDNO IDNO mb_keep_privileged
+ nsExec::Exec 'schtasks /query /tn "MeshBay Node"'
+ Pop $R0 ; 0 = the boot task exists
+ nsExec::Exec '"${MB_PWSH}" -NoProfile -ExecutionPolicy Bypass -File "$INSTDIR\resources\firewall.ps1" any'
+ Pop $R1 ; 0 = at least one rule exists
+ ${If} $R0 == 0
+ ${OrIf} $R1 == 0
ExecShellWait "runas" "${MB_PWSH}" \
'-NoProfile -ExecutionPolicy Bypass -File "$INSTDIR\resources\service-mode.ps1" -Action uninstall' \
SW_HIDE
- mb_keep_privileged:
+ ${EndIf}
${EndIf}
; meshbay_node.platform.autostart_install() -- if the user picked "at sign-in"