From a4aabd1d33770d6199a8cb7bc87f639668617bc9 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Fri, 4 Sep 2026 16:08:06 +0200 Subject: fix(packaging): re-running setup no longer re-prompts for firewall access Every run of customInstall showed the "Allow MeshBay through Windows Firewall?" question and, on Yes, a fresh UAC prompt -- an upgrade or repair install would ask again even with all four rules already in place. customInstall now checks first: firewall.ps1 check, unelevated (Get-NetFirewallRule needs no admin, only New/Remove do), exits 0 if every rule already exists. Only a nonzero result reaches the MessageBox and the elevated add. A second run of setup on an already-configured machine now asks nothing. Verified unelevated: check exits 1 and logs which rules are missing on a machine with none of them (the fresh-install case); electron-builder compiles the nsExec::Exec / Pop $0 / ${If} wiring. Node suite 837 pass / 25 skip. Co-Authored-By: Claude Sonnet 5 --- packaging/win/README.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'packaging/win/README.md') diff --git a/packaging/win/README.md b/packaging/win/README.md index 5130e60..01c8d1a 100644 --- a/packaging/win/README.md +++ b/packaging/win/README.md @@ -109,8 +109,12 @@ Linux packaging solves with a broad `1024-65535/udp` range since those two are fixed and known — matching `packaging/firewall/*/meshbay-cast.xml` exactly. -Say yes and every prompt you'd otherwise hit mid-use — connecting, or the -first cast — is gone. Say no, or the UAC prompt is dismissed, and Windows +Setup checks first, **unelevated** (`firewall.ps1 check` — reading rules needs +no admin, only creating them does), so running the installer again — an +upgrade, a repair install — asks nothing and never pops UAC a second time once +the rules are in place. Say yes the first time and every prompt you'd +otherwise hit mid-use — connecting, or the first cast — is gone. Say no, or +the UAC prompt is dismissed, and Windows falls back to its own **"Allow access"** dialog the first time each program/port combination is used — tick **both Private and Public** then (a libvirt/VM adapter, and sometimes a plain Ethernet one, registers as Public; a -- cgit v1.2.3