Files
tessera-ctl/apps/api/src/desktop/desktop.service.ts
T
schalli ae8fecb538 feat(18-01): Task 1 — Linux-Paket bis zum Download aus der API (Durchstich)
Die duenne Strecke Skript -> Abbild -> API beweisen (D-08, D-10):

- desktop-collect.sh sammelt AppImage/exe ein, schreibt manifest.json
  (Version, Kanal, Commit, Groesse, SHA-256) ohne Secrets
- apps/api/src/desktop/: neues Modul mit GET /desktop/latest und
  GET /desktop/download/:platform, beide @Public(); Plattform-Whitelist
  vor jedem Dateisystemzugriff, Dateiname ausschliesslich aus dem
  Manifest (T-18-01, T-18-02)
- packages/shared: DesktopPlatform/-Manifest(File)/-Latest(Response)
  Typen
- Dockerfile kopiert desktop-dist/ in die runner-Stufe; desktop-dist/
  per .gitkeep + .gitignore versioniert (leeres Verzeichnis, Pakete
  bleiben ungetrackt)
- HTTP-Durchstich-Spec (8 Tests) via NestFactory, kein fs-Mock; echtes
  Temp-Verzeichnis + unabhaengig berechneter SHA-256

Abweichung: DesktopController braucht @Inject(DesktopService) explizit
— Vitest transpiliert ueber esbuild, das emitDecoratorMetadata nicht
abbildet, sonst bleibt desktopService bei einem echten NestFactory-Bau
undefined (Rule 3, Blocker).

Lokal bewiesen: neu gebautes API-Abbild liefert /desktop/latest (200)
und /desktop/download/linux (200, attachment) aus, auch ueber
/api-proxy/ des Web-Containers.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 16:05:55 +02:00

126 lines
4.4 KiB
TypeScript

import { BadRequestException, Injectable, Logger, NotFoundException } from '@nestjs/common';
import type {
DesktopLatestResponse,
DesktopManifest,
DesktopManifestFile,
DesktopPlatform,
} from '@tessera/shared';
import * as fs from 'fs';
import * as path from 'path';
/**
* Wertevorrat der Plattformen (Phase 18, D-10). Geschlossen -- eine dritte
* Plattform waere eine bewusste Erweiterung hier UND am Typ `DesktopPlatform`
* in packages/shared/src/index.ts.
*/
const PLATFORMS = ['windows', 'linux'] as const;
@Injectable()
export class DesktopService {
private readonly logger = new Logger(DesktopService.name);
/** Resolved path to desktop-dist/ (monorepo root, or /app/desktop-dist im Abbild). */
private readonly desktopDistDir: string;
constructor() {
const envDir = process.env.DESKTOP_DIST_DIR?.trim();
this.desktopDistDir =
envDir && envDir.length > 0
? envDir
: // __dirname at runtime = apps/api/dist/desktop/ -- go up 4 levels to monorepo root
path.resolve(__dirname, '..', '..', '..', '..', 'desktop-dist');
}
/**
* Liest manifest.json. Gibt `null` zurueck (nie werfen) wenn die Datei
* fehlt, nicht parsebar ist, oder die Grundform nicht stimmt (version kein
* String, files kein Objekt) -- D-10: "fehlt das Verzeichnis/Manifest: 404
* mit klarer Meldung".
*/
getManifest(): DesktopManifest | null {
const manifestPath = path.join(this.desktopDistDir, 'manifest.json');
if (!fs.existsSync(manifestPath)) {
return null;
}
try {
const raw = fs.readFileSync(manifestPath, 'utf-8');
const parsed = JSON.parse(raw) as DesktopManifest;
if (typeof parsed.version !== 'string' || typeof parsed.files !== 'object' || parsed.files === null) {
this.logger.warn(`manifest.json unter ${manifestPath} hat unerwartete Form`);
return null;
}
return parsed;
} catch (error) {
this.logger.warn(`manifest.json unter ${manifestPath} konnte nicht gelesen werden: ${error}`);
return null;
}
}
/**
* `GET /desktop/latest` (D-10): Kopf-Felder aus dem Manifest, je
* vorhandener Plattform eine relative Download-URL ergaenzt (Client stellt
* die API-Basis davor, siehe Objective-Abschnitt "Vom Client aus ...").
*/
getLatest(): DesktopLatestResponse {
const manifest = this.getManifest();
if (!manifest) {
throw new NotFoundException('Desktop packages are not available on this server');
}
const files: DesktopLatestResponse['files'] = {};
for (const platform of PLATFORMS) {
const entry = manifest.files[platform];
if (entry) {
files[platform] = { ...entry, url: `/desktop/download/${platform}` };
}
}
return {
version: manifest.version,
channel: manifest.channel,
commit: manifest.commit,
buildTime: manifest.buildTime,
files,
};
}
/**
* `GET /desktop/download/:platform` (D-10, T-18-01): Reihenfolge ist die
* Sicherheitseigenschaft -- Whitelist VOR jedem Dateisystemzugriff, der
* Dateiname kommt ausschliesslich aus manifest.json, nie aus der Anfrage.
*/
getPackage(platform: string): { stream: fs.ReadStream; entry: DesktopManifestFile } {
// (1) Whitelist -- vor jedem Dateisystemzugriff.
if (!PLATFORMS.includes(platform as DesktopPlatform)) {
throw new BadRequestException('Unknown platform');
}
const knownPlatform = platform as DesktopPlatform;
// (2) Manifest holen.
const manifest = this.getManifest();
if (!manifest) {
throw new NotFoundException('Desktop packages are not available on this server');
}
// (3) Eintrag fuer diese Plattform muss existieren.
const entry = manifest.files[knownPlatform];
if (!entry) {
throw new NotFoundException(`No package for platform: ${knownPlatform}`);
}
// (4) Verteidigung in der Tiefe (T-18-02): auch ein manipuliertes
// Manifest darf nicht aus dem Ordner hinausfuehren.
if (!/^[A-Za-z0-9._-]+$/.test(entry.name)) {
throw new NotFoundException(`No package for platform: ${knownPlatform}`);
}
// (5) Datei muss existieren.
const filePath = path.join(this.desktopDistDir, entry.name);
if (!fs.existsSync(filePath)) {
throw new NotFoundException(`Package file missing: ${entry.name}`);
}
// (6) Stream zurueckgeben -- kein Puffern der ganzen Datei (Installer
// sind deutlich groesser als DKV-Exporte).
return { stream: fs.createReadStream(filePath), entry };
}
}