From 45d9afd347fd0b8dc0fc4fb780a29efdd5913c06 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Thu, 1 Oct 2026 15:59:09 -0700 Subject: [PATCH] Document Windows release publishing from a staged checkout [skip ci] --- aesel/windows/README.md | 10 ++++++++-- aesel/windows/publish.mjs | 2 +- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/aesel/windows/README.md b/aesel/windows/README.md index 2bef8a06e7..41fc4b34ff 100644 --- a/aesel/windows/README.md +++ b/aesel/windows/README.md @@ -36,8 +36,11 @@ pwsh -File aesel/windows/package.ps1 `package.ps1` publishes the self-contained x64 app, runs it on Windows with an isolated profile and mocked account/inference/upload traffic, captures the workspace/sign-in screens, then builds the per-user installer and SHA-256 feed. +The installer includes Microsoft's signature-verified WebView2 bootstrapper and +installs the runtime if needed. The installed app is tested again after setup. The smoke checks generation, upload, preview, escaping, persistence, thread -switching, sign-out, account isolation, callback boundaries and Windows DPAPI. +switching, sign-out, account isolation, callback boundaries, Windows DPAPI, +and serialized refresh-token rotation. It does not certify real-user OAuth or provider billing. The existing AppVeyor project builds the `aesel-windows` branch using its @@ -46,7 +49,10 @@ the account billing lock is cleared. Inspect both screenshots and the test result before publication; never publish a compile-only artifact. Release artifacts go under `releases.aesthetic.computer/aesel/windows/`. -Upload the immutable installer first and `latest.json` last. The manifest records +Run `node aesel/windows/publish.mjs ARTIFACT_DIR` with the existing Spaces +credentials in the environment. When running this script from a staged copy, +set `AESEL_SOURCE_REPO` to the canonical checkout used for ancestry checks. +It uploads the immutable installer first and `latest.json` last. The manifest records the build revision, hash, architecture, beta channel, and unsigned status. Only a revision preserved on knot `main` may be published. The website links through `/api/download?app=aesel&file=aesel-VERSION-windows-x64-setup.exe` so diff --git a/aesel/windows/publish.mjs b/aesel/windows/publish.mjs index 31c6f41e86..167b85cef6 100644 --- a/aesel/windows/publish.mjs +++ b/aesel/windows/publish.mjs @@ -5,7 +5,7 @@ import {resolve,dirname,basename} from 'node:path'; import {fileURLToPath} from 'node:url'; import {createHash} from 'node:crypto'; import {execFileSync,spawnSync} from 'node:child_process'; -const root=resolve(dirname(fileURLToPath(import.meta.url)),'../..'); +const root=process.env.AESEL_SOURCE_REPO || resolve(dirname(fileURLToPath(import.meta.url)),'../..'); const dir=resolve(process.argv[2] || 'aesel/windows/dist'); const manifest=JSON.parse(await readFile(resolve(dir,'latest.json'),'utf8')); const result=JSON.parse(await readFile(resolve(dir,'result.json'),'utf8').catch(()=>readFile(resolve(dir,'smoke/result.json'),'utf8'))); -- 2.51.2