aboutsummaryrefslogtreecommitdiffstats
path: root/packaging
diff options
context:
space:
mode:
Diffstat (limited to 'packaging')
-rwxr-xr-xpackaging/build/build-node.sh57
-rw-r--r--packaging/win/build-node-runtime.ps159
2 files changed, 24 insertions, 92 deletions
diff --git a/packaging/build/build-node.sh b/packaging/build/build-node.sh
index fde67a5..b9d542c 100755
--- a/packaging/build/build-node.sh
+++ b/packaging/build/build-node.sh
@@ -45,55 +45,18 @@ ln -sf /opt/meshbay-common/venv/bin/meshbay-node "$ROOT/usr/bin/meshbay-node"
# --- Node-specific assets -------------------------------------------------
mkdir -p "$ROOT/opt/meshbay-node/share"
-# Default env with the shared TMDB token, read at build time. The daemon reads
-# it in place, beneath <config>/node.env, so it must be readable by whoever runs
-# the node -- 0600 root made it unreadable to every per-user node. It is the
-# same token in every copy of the package, so 0644 hides nothing.
-#
-# tmdb.py sends `Authorization: Bearer`, so this is the v4 *read access token*
-# (a JWT, "eyJ..."), not the 32-char v3 API key that sits beside it in the same
-# note file. Sources, in order: an explicit variable, an explicit file, the
-# KEY=VALUE form, then QE/tmdb.txt -- which is free-form prose, so the token is
-# matched by shape rather than by a label.
-extract_tmdb_token() {
- local file="$1" tok=""
- [ -f "$file" ] || return 0
- tok=$(sed -n 's/^[[:space:]]*MESHBAY_TMDB_DEFAULT_TOKEN[[:space:]]*=[[:space:]]*//p' \
- "$file" | head -1)
- [ -n "$tok" ] || tok=$(grep -oE '^eyJ[A-Za-z0-9._-]{40,}$' "$file" | head -1 || true)
- printf '%s' "$tok" | tr -d '"'"'"'\r'
-}
-
-TMDB_TOKEN="${MESHBAY_TMDB_TOKEN:-}"
-if [ -z "$TMDB_TOKEN" ] && [ -n "${MESHBAY_TMDB_TOKEN_FILE:-}" ]; then
- TMDB_TOKEN=$(extract_tmdb_token "$MESHBAY_TMDB_TOKEN_FILE")
-fi
-[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/node.env")
-[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/tmdb.txt")
-
-if [ -n "$TMDB_TOKEN" ]; then
- cat > "$ROOT/opt/meshbay-node/share/default.env" <<EOF
-# Default environment for meshbay-node.
-# Read by the daemon beneath <config>/node.env; set a value there to override it.
-
-# TMDB API token for the Videos app (read-only, shared across installations)
-MESHBAY_TMDB_DEFAULT_TOKEN=$TMDB_TOKEN
-EOF
- chmod 644 "$ROOT/opt/meshbay-node/share/default.env"
- echo " TMDB token baked into default.env (${#TMDB_TOKEN} chars)"
-elif [ "${MESHBAY_ALLOW_NO_TMDB:-0}" = "1" ]; then
- echo " !! no TMDB token; default.env left empty (MESHBAY_ALLOW_NO_TMDB=1)" >&2
- : > "$ROOT/opt/meshbay-node/share/default.env"
-else
- # Failing here is deliberate: an empty default.env is invisible until a user
- # opens the Videos app and finds no metadata, which is exactly how this
- # shipped empty on two platforms at once.
- echo "!! TMDB token not found. Looked at:" >&2
- echo " \$MESHBAY_TMDB_TOKEN, \$MESHBAY_TMDB_TOKEN_FILE," >&2
- echo " $REPO/QE/node.env, $REPO/QE/tmdb.txt" >&2
- echo " Set MESHBAY_ALLOW_NO_TMDB=1 to build without it." >&2
+# default.env: the shared TMDB token, copied as is from QE/default.env (never
+# versioned), one line: MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... The daemon reads it
+# beneath <config>/node.env and the operator's own token, so it is only the
+# fallback. 0644: a per-user node must read it, and it is the same token in
+# every copy of the package. No token, no build: an empty one goes unnoticed.
+DEFAULT_ENV="$REPO/QE/default.env"
+if [ "$(head -c 30 "$DEFAULT_ENV" 2>/dev/null)" != "MESHBAY_TMDB_DEFAULT_TOKEN=eyJ" ]; then
+ echo "!! $DEFAULT_ENV missing, or not starting with MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... (no BOM)" >&2
exit 1
fi
+install -m 644 "$DEFAULT_ENV" "$ROOT/opt/meshbay-node/share/default.env"
+echo " default.env copied from QE/"
# --- Systemd units --------------------------------------------------------
mkdir -p "$ROOT/usr/lib/systemd/system"
diff --git a/packaging/win/build-node-runtime.ps1 b/packaging/win/build-node-runtime.ps1
index 1171146..42d1faa 100644
--- a/packaging/win/build-node-runtime.ps1
+++ b/packaging/win/build-node-runtime.ps1
@@ -135,52 +135,21 @@ else {
}
# --- 5. default.env (shared TMDB token) ------------------------------
-# Beside the exe, where platform.packaged_default_env() looks for it, and the
-# same placement ffmpeg gets above. The daemon reads it in place, beneath
-# %LOCALAPPDATA%\meshbay\node.env: Windows autostart is a Startup-folder .vbs,
-# with no systemd EnvironmentFile.
-function Get-TmdbToken([string]$File) {
- if (-not $File -or -not (Test-Path -LiteralPath $File)) { return "" }
- $lines = Get-Content -LiteralPath $File
- foreach ($line in $lines) {
- if ($line -match '^\s*MESHBAY_TMDB_DEFAULT_TOKEN\s*=\s*(.+)$') {
- return $Matches[1].Trim().Trim('"').Trim("'")
- }
- }
- # QE\tmdb.txt is free-form prose: match the v4 read token by shape. The
- # 32-char v3 API key in the same file is NOT what tmdb.py sends (Bearer).
- foreach ($line in $lines) {
- if ($line -match '^(eyJ[A-Za-z0-9._-]{40,})\s*$') { return $Matches[1] }
- }
- return ""
-}
-
-$tmdb = $env:MESHBAY_TMDB_TOKEN
-if (-not $tmdb) { $tmdb = Get-TmdbToken $env:MESHBAY_TMDB_TOKEN_FILE }
-if (-not $tmdb) { $tmdb = Get-TmdbToken (Join-Path $Repo "QE\node.env") }
-if (-not $tmdb) { $tmdb = Get-TmdbToken (Join-Path $Repo "QE\tmdb.txt") }
-
-$envFile = Join-Path $frozen "default.env"
-$noBom = New-Object System.Text.UTF8Encoding $false # a BOM would break parsing
-if ($tmdb) {
- $body = @(
- "# Default environment for meshbay-node.",
- "# Read by the daemon beneath <config>\node.env; set a value there to override it.",
- "",
- "# TMDB API token for the Videos app (read-only, shared across installations)",
- "MESHBAY_TMDB_DEFAULT_TOKEN=$tmdb"
- ) -join "`n"
- [System.IO.File]::WriteAllText($envFile, $body + "`n", $noBom)
- Step ("TMDB token baked into default.env ({0} chars)" -f $tmdb.Length)
-}
-elseif ($env:MESHBAY_ALLOW_NO_TMDB -eq "1") {
- [System.IO.File]::WriteAllText($envFile, "", $noBom)
- Write-Host " !! no TMDB token; default.env left empty (MESHBAY_ALLOW_NO_TMDB=1)" -ForegroundColor Yellow
-}
-else {
- throw ("TMDB token not found (MESHBAY_TMDB_TOKEN, MESHBAY_TMDB_TOKEN_FILE, " +
- "QE\node.env, QE\tmdb.txt). Set MESHBAY_ALLOW_NO_TMDB=1 to build without it.")
+# Copied as is from QE\default.env (never versioned), one line:
+# MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... Beside the exe, where
+# platform.packaged_default_env() looks for it. The daemon reads it beneath
+# %LOCALAPPDATA%\meshbay\node.env and the operator's own token, so it is only
+# the fallback. No token, no build: an empty one goes unnoticed. The check is
+# on the raw bytes, so a BOM (which would break the daemon's parsing) fails too.
+$defaultEnv = Join-Path $Repo "QE\default.env"
+$text = if (Test-Path -LiteralPath $defaultEnv) {
+ [System.Text.Encoding]::ASCII.GetString([System.IO.File]::ReadAllBytes($defaultEnv))
+} else { "" }
+if (-not $text.StartsWith("MESHBAY_TMDB_DEFAULT_TOKEN=eyJ")) {
+ throw "$defaultEnv missing, or not starting with MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... (no BOM)"
}
+Copy-Item -LiteralPath $defaultEnv (Join-Path $frozen "default.env")
+Step "default.env copied from QE\"
# --- 6. publish ----------------------------------------------------
Move-Item $frozen $OutDir