From 74941aae5451c03a296413710fe888b1924e8c27 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Fri, 4 Sep 2026 15:36:53 +0200 Subject: feat(packaging): offer one elevated firewall step instead of two dialogs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Installing used to mean clicking through two separate Windows "Allow access" prompts later — one for MeshBay.exe, one for meshbay-node.exe — each confusing on its own and worse before the exe carried a version resource. Adding a firewall rule needs admin, and the installer is deliberately per-user with no elevation, so this can only ever be opt-in. packaging/win/firewall.ps1 (new, shipped as an extraResource at resources\firewall.ps1): idempotent add/remove of the two inbound UDP rules ("MeshBay", "MeshBay Node"), grouped, logged to %TEMP%\meshbay-firewall.log. Locates both executables from its own path, no arguments needed beyond the action. build/installer.nsh: customInstall asks "Allow MeshBay through Windows Firewall now?" and runs firewall.ps1 via NSIS ExecShellWait "runas" — one UAC prompt — only when not ${Silent}; declining or dismissing UAC falls back to Windows' own per-process prompts, unchanged. customUnInstall offers the same in reverse, defaulted to No (a stale rule for a deleted exe is inert, so this should not nag on the way out) and skipped for a silent uninstall. Verified: rebuilt MeshBay-Setup-0.1.0.exe (electron-builder compiles the new LogicLib.nsh / ExecShellWait NSIS successfully); firewall.ps1 run unelevated fails cleanly into its log ("Access is denied") rather than silently doing nothing, confirming the fallback path. Node suite 835 pass / 25 skip. Co-Authored-By: Claude Sonnet 5 --- packages/meshbay-client/package.json | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'packages/meshbay-client/package.json') diff --git a/packages/meshbay-client/package.json b/packages/meshbay-client/package.json index 57acff8..7f5afcb 100644 --- a/packages/meshbay-client/package.json +++ b/packages/meshbay-client/package.json @@ -33,6 +33,10 @@ "from": "node-runtime", "to": "node-runtime", "filter": ["**/*"] + }, + { + "from": "../../packaging/win/firewall.ps1", + "to": "firewall.ps1" } ] }, -- cgit v1.2.3