@electron/osx-sign
Advanced tools
| #!/usr/bin/env node | ||
| // @ts-check | ||
| import fs from 'node:fs'; | ||
| import path from 'node:path'; | ||
| import { parseArgs } from 'node:util'; | ||
| import { flat } from '../dist/flat.js'; | ||
| const { values, positionals } = parseArgs({ | ||
| options: { | ||
| help: { | ||
| type: 'boolean', | ||
| default: false, | ||
| }, | ||
| }, | ||
| allowPositionals: true, | ||
| }); | ||
| const app = positionals.shift(); | ||
| if (!app || values.help || positionals.length > 0) { | ||
| const usage = fs | ||
| .readFileSync(path.join(import.meta.dirname, 'electron-osx-flat-usage.txt')) | ||
| .toString(); | ||
| console.log(usage); | ||
| process.exit(0); | ||
| } | ||
| try { | ||
| await flat({ app }); | ||
| // This is the default value inferred in the `flat` function. | ||
| console.log( | ||
| `Application flattened, saved to: ${path.join(path.dirname(app), path.basename(app, '.app') + '.pkg')}`, | ||
| ); | ||
| process.exit(0); | ||
| } catch (err) { | ||
| if (err) { | ||
| console.error('Flat failed:'); | ||
| if (err.message) console.error(err.message); | ||
| else if (err.stack) console.error(err.stack); | ||
| else console.log(err); | ||
| process.exit(1); | ||
| } | ||
| } |
| #!/usr/bin/env node | ||
| // @ts-check | ||
| import fs from 'node:fs'; | ||
| import path from 'node:path'; | ||
| import { parseArgs } from 'node:util'; | ||
| import { sign } from '../dist/sign.js'; | ||
| const { values, positionals } = parseArgs({ | ||
| options: { | ||
| 'signature-flags': { type: 'string' }, | ||
| help: { type: 'boolean' }, | ||
| 'pre-auto-entitlements': { type: 'boolean', default: true }, | ||
| 'pre-embed-provisioning-profile': { type: 'boolean', default: true }, | ||
| 'hardened-runtime': { type: 'boolean' }, | ||
| restrict: { type: 'boolean' }, | ||
| }, | ||
| allowPositionals: true, | ||
| }); | ||
| const app = positionals.shift(); | ||
| const binaries = positionals; | ||
| if (!app || values.help) { | ||
| const usage = fs | ||
| .readFileSync(path.join(import.meta.dirname, 'electron-osx-sign-usage.txt')) | ||
| .toString(); | ||
| console.log(usage); | ||
| process.exit(0); | ||
| } else { | ||
| try { | ||
| await sign({ app, binaries }); | ||
| console.log(`Application signed: ${app}`); | ||
| process.exit(0); | ||
| } catch (err) { | ||
| console.error('Sign failed:'); | ||
| if (err.message) console.error(err.message); | ||
| else if (err.stack) console.error(err.stack); | ||
| else console.log(err); | ||
| process.exit(1); | ||
| } | ||
| } |
| import type { FlatOptions } from './types.js'; | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| export declare function flat(_opts: FlatOptions): Promise<void>; |
+128
| import path from 'node:path'; | ||
| import { debugLog, debugWarn, execFileAsync, validateOptsApp, validateOptsPlatform, } from './util.js'; | ||
| import { findIdentities } from './util-identities.js'; | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| * @function | ||
| * @param {Object} opts - Options. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| async function validateFlatOpts(opts) { | ||
| await validateOptsApp(opts); | ||
| let pkg = opts.pkg; | ||
| if (pkg) { | ||
| if (typeof pkg !== 'string') | ||
| throw new Error('`pkg` must be a string.'); | ||
| if (path.extname(pkg) !== '.pkg') { | ||
| throw new Error('Extension of output package must be `.pkg`.'); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `pkg` passed in arguments, will fallback to default inferred from the given application.'); | ||
| pkg = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '.pkg'); | ||
| } | ||
| let install = opts.install; | ||
| if (install) { | ||
| if (typeof install !== 'string') { | ||
| return Promise.reject(new Error('`install` must be a string.')); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `install` passed in arguments, will fallback to default `/Applications`.'); | ||
| install = '/Applications'; | ||
| } | ||
| if (typeof opts.scripts === 'string' && opts.platform === 'mas') { | ||
| debugWarn('Mac App Store packages cannot have `scripts`, ignoring option.'); | ||
| } | ||
| return { | ||
| ...opts, | ||
| pkg, | ||
| install, | ||
| platform: await validateOptsPlatform(opts), | ||
| }; | ||
| } | ||
| /** | ||
| * This function returns a promise flattening the application. | ||
| * @param opts - Options for building the .pkg archive | ||
| */ | ||
| async function buildApplicationPkg(opts, identity) { | ||
| if (opts.platform === 'mas') { | ||
| const args = ['--component', opts.app, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| debugLog('Flattening Mac App Store package... ' + opts.app); | ||
| await execFileAsync('productbuild', args); | ||
| } | ||
| else { | ||
| const componentPkgPath = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '-component.pkg'); | ||
| const pkgbuildArgs = [ | ||
| '--install-location', | ||
| opts.install, | ||
| '--component', | ||
| opts.app, | ||
| componentPkgPath, | ||
| ]; | ||
| if (opts.scripts) { | ||
| pkgbuildArgs.unshift('--scripts', opts.scripts); | ||
| } | ||
| debugLog('Building component package... ' + opts.app); | ||
| await execFileAsync('pkgbuild', pkgbuildArgs); | ||
| const args = ['--package', componentPkgPath, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| debugLog('Flattening OS X Installer package... ' + opts.app); | ||
| await execFileAsync('productbuild', args); | ||
| await execFileAsync('rm', [componentPkgPath]); | ||
| } | ||
| } | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| export async function flat(_opts) { | ||
| const validatedOptions = await validateFlatOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| if (validatedOptions.identity) { | ||
| debugLog('`identity` passed in arguments.'); | ||
| if (validatedOptions.identityValidation === false) { | ||
| // Do nothing | ||
| } | ||
| else { | ||
| identities = await findIdentities(validatedOptions.keychain || null, validatedOptions.identity); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `identity` passed in arguments...'); | ||
| if (validatedOptions.platform === 'mas') { | ||
| debugLog('Finding `3rd Party Mac Developer Installer` certificate for flattening app distribution in the Mac App Store...'); | ||
| identities = await findIdentities(validatedOptions.keychain || null, '3rd Party Mac Developer Installer:'); | ||
| } | ||
| else { | ||
| debugLog('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await findIdentities(validatedOptions.keychain || null, 'Developer ID Installer:'); | ||
| } | ||
| } | ||
| if (identities.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (identities.length > 1) { | ||
| debugWarn('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| debugLog('Flattening application...', '\n', '> Application:', validatedOptions.app, '\n', '> Package output:', validatedOptions.pkg, '\n', '> Install path:', validatedOptions.install, '\n', '> Identity:', validatedOptions.identity, '\n', '> Scripts:', validatedOptions.scripts); | ||
| await buildApplicationPkg(validatedOptions, identityInUse); | ||
| debugLog('Application flattened.'); | ||
| } | ||
| //# sourceMappingURL=flat.js.map |
| {"version":3,"file":"flat.js","sourceRoot":"","sources":["../src/flat.ts"],"names":[],"mappings":"AAAA,OAAO,IAAI,MAAM,WAAW,CAAC;AAC7B,OAAO,EACL,QAAQ,EACR,SAAS,EACT,aAAa,EACb,eAAe,EACf,oBAAoB,GACrB,MAAM,WAAW,CAAC;AAEnB,OAAO,EAAY,cAAc,EAAE,MAAM,sBAAsB,CAAC;AAIhE;;;;;GAKG;AACH,KAAK,UAAU,gBAAgB,CAAC,IAAiB;IAC/C,MAAM,eAAe,CAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,GAAG,GAAG,IAAI,CAAC,GAAG,CAAC;IACnB,IAAI,GAAG,EAAE,CAAC;QACR,IAAI,OAAO,GAAG,KAAK,QAAQ;YAAE,MAAM,IAAI,KAAK,CAAC,yBAAyB,CAAC,CAAC;QACxE,IAAI,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE,CAAC;YACjC,MAAM,IAAI,KAAK,CAAC,6CAA6C,CAAC,CAAC;QACjE,CAAC;IACH,CAAC;SAAM,CAAC;QACN,SAAS,CACP,6FAA6F,CAC9F,CAAC;QACF,GAAG,GAAG,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,MAAM,CAAC,CAAC;IACpF,CAAC;IAED,IAAI,OAAO,GAAG,IAAI,CAAC,OAAO,CAAC;IAC3B,IAAI,OAAO,EAAE,CAAC;QACZ,IAAI,OAAO,OAAO,KAAK,QAAQ,EAAE,CAAC;YAChC,OAAO,OAAO,CAAC,MAAM,CAAC,IAAI,KAAK,CAAC,6BAA6B,CAAC,CAAC,CAAC;QAClE,CAAC;IACH,CAAC;SAAM,CAAC;QACN,SAAS,CAAC,6EAA6E,CAAC,CAAC;QACzF,OAAO,GAAG,eAAe,CAAC;IAC5B,CAAC;IAED,IAAI,OAAO,IAAI,CAAC,OAAO,KAAK,QAAQ,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE,CAAC;QAChE,SAAS,CAAC,gEAAgE,CAAC,CAAC;IAC9E,CAAC;IAED,OAAO;QACL,GAAG,IAAI;QACP,GAAG;QACH,OAAO;QACP,QAAQ,EAAE,MAAM,oBAAoB,CAAC,IAAI,CAAC;KAC3C,CAAC;AACJ,CAAC;AAED;;;GAGG;AACH,KAAK,UAAU,mBAAmB,CAAC,IAA0B,EAAE,QAAkB;IAC/E,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE,CAAC;QAC5B,MAAM,IAAI,GAAG,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QACxF,IAAI,IAAI,CAAC,QAAQ,EAAE,CAAC;YAClB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;QAC5C,CAAC;QAED,QAAQ,CAAC,sCAAsC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC5D,MAAM,aAAa,CAAC,cAAc,EAAE,IAAI,CAAC,CAAC;IAC5C,CAAC;SAAM,CAAC;QACN,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAChC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EACtB,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,gBAAgB,CACnD,CAAC;QACF,MAAM,YAAY,GAAG;YACnB,oBAAoB;YACpB,IAAI,CAAC,OAAO;YACZ,aAAa;YACb,IAAI,CAAC,GAAG;YACR,gBAAgB;SACjB,CAAC;QACF,IAAI,IAAI,CAAC,OAAO,EAAE,CAAC;YACjB,YAAY,CAAC,OAAO,CAAC,WAAW,EAAE,IAAI,CAAC,OAAO,CAAC,CAAC;QAClD,CAAC;QACD,QAAQ,CAAC,gCAAgC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QACtD,MAAM,aAAa,CAAC,UAAU,EAAE,YAAY,CAAC,CAAC;QAE9C,MAAM,IAAI,GAAG,CAAC,WAAW,EAAE,gBAAgB,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QAC9F,IAAI,IAAI,CAAC,QAAQ,EAAE,CAAC;YAClB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;QAC5C,CAAC;QAED,QAAQ,CAAC,uCAAuC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC7D,MAAM,aAAa,CAAC,cAAc,EAAE,IAAI,CAAC,CAAC;QAC1C,MAAM,aAAa,CAAC,IAAI,EAAE,CAAC,gBAAgB,CAAC,CAAC,CAAC;IAChD,CAAC;AACH,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,KAAK,UAAU,IAAI,CAAC,KAAkB;IAC3C,MAAM,gBAAgB,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACvD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,IAAI,gBAAgB,CAAC,QAAQ,EAAE,CAAC;QAC9B,QAAQ,CAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,gBAAgB,CAAC,kBAAkB,KAAK,KAAK,EAAE,CAAC;YAClD,aAAa;QACf,CAAC;aAAM,CAAC;YACN,UAAU,GAAG,MAAM,cAAc,CAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,gBAAgB,CAAC,QAAQ,CAC1B,CAAC;QACJ,CAAC;IACH,CAAC;SAAM,CAAC;QACN,SAAS,CAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,gBAAgB,CAAC,QAAQ,KAAK,KAAK,EAAE,CAAC;YACxC,QAAQ,CACN,iHAAiH,CAClH,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,oCAAoC,CACrC,CAAC;QACJ,CAAC;aAAM,CAAC;YACN,QAAQ,CACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,yBAAyB,CAC1B,CAAC;QACJ,CAAC;IACH,CAAC;IAED,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;QAC1B,gCAAgC;QAChC,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;YAC1B,SAAS,CAAC,2DAA2D,CAAC,CAAC;QACzE,CAAC;aAAM,CAAC;YACN,QAAQ,CAAC,mBAAmB,CAAC,CAAC;QAChC,CAAC;QACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;IAChC,CAAC;SAAM,CAAC;QACN,oBAAoB;QACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;IACpD,CAAC;IAED,QAAQ,CACN,2BAA2B,EAC3B,IAAI,EACJ,gBAAgB,EAChB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,mBAAmB,EACnB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,iBAAiB,EACjB,gBAAgB,CAAC,OAAO,EACxB,IAAI,EACJ,aAAa,EACb,gBAAgB,CAAC,QAAQ,EACzB,IAAI,EACJ,YAAY,EACZ,gBAAgB,CAAC,OAAO,CACzB,CAAC;IACF,MAAM,mBAAmB,CAAC,gBAAgB,EAAE,aAAa,CAAC,CAAC;IAE3D,QAAQ,CAAC,wBAAwB,CAAC,CAAC;AACrC,CAAC"} |
| import { sign } from './sign.js'; | ||
| import { flat } from './flat.js'; | ||
| import { walk } from './util.js'; | ||
| export { sign, flat, walk }; | ||
| export type * from './types.js'; |
| import { sign } from './sign.js'; | ||
| import { flat } from './flat.js'; | ||
| import { walk } from './util.js'; | ||
| export { sign, flat, walk }; | ||
| //# sourceMappingURL=index.js.map |
| {"version":3,"file":"index.js","sourceRoot":"","sources":["../src/index.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,IAAI,EAAE,MAAM,WAAW,CAAC;AACjC,OAAO,EAAE,IAAI,EAAE,MAAM,WAAW,CAAC;AACjC,OAAO,EAAE,IAAI,EAAE,MAAM,WAAW,CAAC;AAEjC,OAAO,EAAE,IAAI,EAAE,IAAI,EAAE,IAAI,EAAE,CAAC"} |
| import type { SignOptions } from './types.js'; | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| export declare function sign(_opts: SignOptions): Promise<void>; |
+326
| import os from 'node:os'; | ||
| import path from 'node:path'; | ||
| import util from 'node:util'; | ||
| import fs from 'graceful-fs'; | ||
| import plist from 'plist'; | ||
| import semver from 'semver'; | ||
| import { debugLog, debugWarn, getAppContentsPath, execFileAsync, validateOptsApp, validateOptsPlatform, walk, } from './util.js'; | ||
| import { Identity, findIdentities } from './util-identities.js'; | ||
| import { preEmbedProvisioningProfile, getProvisioningProfile, } from './util-provisioning-profiles.js'; | ||
| import { preAutoEntitlements } from './util-entitlements.js'; | ||
| const osRelease = os.release(); | ||
| /** | ||
| * This function returns a promise validating opts.binaries, the additional binaries to be signed along with the discovered enclosed components. | ||
| */ | ||
| async function validateOptsBinaries(opts) { | ||
| if (opts.binaries) { | ||
| if (!Array.isArray(opts.binaries)) { | ||
| throw new Error('Additional binaries should be an Array.'); | ||
| } | ||
| // TODO: Presence check for binary files, reject if any does not exist | ||
| } | ||
| } | ||
| function validateOptsIgnore(ignore) { | ||
| if (ignore && !(ignore instanceof Array)) { | ||
| return [ignore]; | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| */ | ||
| async function validateSignOpts(opts) { | ||
| await validateOptsBinaries(opts); | ||
| await validateOptsApp(opts); | ||
| if (opts.provisioningProfile && typeof opts.provisioningProfile !== 'string') { | ||
| throw new Error('Path to provisioning profile should be a string.'); | ||
| } | ||
| if (opts.type && opts.type !== 'development' && opts.type !== 'distribution') { | ||
| throw new Error('Type must be either `development` or `distribution`.'); | ||
| } | ||
| const platform = await validateOptsPlatform(opts); | ||
| const cloned = { | ||
| ...opts, | ||
| ignore: validateOptsIgnore(opts.ignore), | ||
| type: opts.type || 'distribution', | ||
| platform, | ||
| }; | ||
| return cloned; | ||
| } | ||
| /** | ||
| * This function returns a promise verifying the code sign of application bundle. | ||
| */ | ||
| async function verifySignApplication(opts) { | ||
| // Verify with codesign | ||
| debugLog('Verifying application bundle with codesign...'); | ||
| const strictVerify = opts.strictVerify !== undefined ? opts.strictVerify : true; | ||
| await execFileAsync('codesign', ['--verify', '--deep'].concat(strictVerify !== false && semver.gte(osRelease, '15.0.0') // Strict flag since darwin 15.0.0 --> OS X 10.11.0 El Capitan | ||
| ? ['--strict' + (strictVerify !== true ? '=' + strictVerify : '')] | ||
| : [], ['--verbose=2', opts.app])); | ||
| } | ||
| function defaultOptionsForFile(filePath, platform) { | ||
| const entitlementsFolder = path.resolve(import.meta.dirname, '..', 'entitlements'); | ||
| let entitlementsFile; | ||
| if (platform === 'darwin') { | ||
| // Default Entitlements | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/app-entitlements.plist | ||
| // Also include JIT for main process V8 | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plist'); | ||
| // Plugin helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-plugin-entitlements.plist | ||
| if (filePath.includes('(Plugin).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plugin.plist'); | ||
| // GPU Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-gpu-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(GPU).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.gpu.plist'); | ||
| // Renderer Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-renderer-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(Renderer).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.renderer.plist'); | ||
| } | ||
| } | ||
| else { | ||
| // Default entitlements | ||
| // TODO: Can these be more scoped like the non-mas variant? | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.plist'); | ||
| // If it is not the top level app bundle, we sign with inherit | ||
| if (filePath.includes('.app/')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.child.plist'); | ||
| } | ||
| } | ||
| return { | ||
| entitlements: entitlementsFile, | ||
| hardenedRuntime: true, | ||
| requirements: undefined, | ||
| signatureFlags: undefined, | ||
| timestamp: undefined, | ||
| additionalArguments: [], | ||
| }; | ||
| } | ||
| async function mergeOptionsForFile(opts, defaults) { | ||
| const mergedPerFileOptions = { ...defaults }; | ||
| if (opts) { | ||
| if (opts.entitlements !== undefined) { | ||
| if (Array.isArray(opts.entitlements)) { | ||
| const entitlements = opts.entitlements.reduce((dict, entitlementKey) => ({ | ||
| ...dict, | ||
| [entitlementKey]: true, | ||
| }), {}); | ||
| const dir = await fs.promises.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await util.promisify(fs.writeFile)(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| opts.entitlements = entitlementsPath; | ||
| } | ||
| mergedPerFileOptions.entitlements = opts.entitlements; | ||
| } | ||
| if (opts.hardenedRuntime !== undefined) { | ||
| mergedPerFileOptions.hardenedRuntime = opts.hardenedRuntime; | ||
| } | ||
| if (opts.requirements !== undefined) | ||
| mergedPerFileOptions.requirements = opts.requirements; | ||
| if (opts.signatureFlags !== undefined) { | ||
| mergedPerFileOptions.signatureFlags = opts.signatureFlags; | ||
| } | ||
| if (opts.timestamp !== undefined) | ||
| mergedPerFileOptions.timestamp = opts.timestamp; | ||
| if (opts.additionalArguments !== undefined) | ||
| mergedPerFileOptions.additionalArguments = opts.additionalArguments; | ||
| } | ||
| return mergedPerFileOptions; | ||
| } | ||
| /** | ||
| * This function returns a promise codesigning only. | ||
| */ | ||
| async function signApplication(opts, identity) { | ||
| function shouldIgnoreFilePath(filePath) { | ||
| if (opts.ignore) { | ||
| return opts.ignore.some(function (ignore) { | ||
| if (typeof ignore === 'function') { | ||
| return ignore(filePath); | ||
| } | ||
| return filePath.match(ignore); | ||
| }); | ||
| } | ||
| return false; | ||
| } | ||
| const children = await walk(getAppContentsPath(opts)); | ||
| if (opts.binaries) | ||
| children.push(...opts.binaries); | ||
| const args = ['--sign', identity.hash || identity.name, '--force']; | ||
| if (opts.keychain) { | ||
| args.push('--keychain', opts.keychain); | ||
| } | ||
| /** | ||
| * Sort the child paths by how deep they are in the file tree. Some arcane apple | ||
| * logic expects the deeper files to be signed first otherwise strange errors get | ||
| * thrown our way | ||
| */ | ||
| children.sort((a, b) => { | ||
| const aDepth = a.split(path.sep).length; | ||
| const bDepth = b.split(path.sep).length; | ||
| return bDepth - aDepth; | ||
| }); | ||
| for (const filePath of [...children, opts.app]) { | ||
| if (shouldIgnoreFilePath(filePath)) { | ||
| debugLog('Skipped... ' + filePath); | ||
| continue; | ||
| } | ||
| const perFileOptions = await mergeOptionsForFile(opts.optionsForFile ? opts.optionsForFile(filePath) : null, defaultOptionsForFile(filePath, opts.platform)); | ||
| // preAutoEntitlements should only be applied to the top level app bundle. | ||
| // Applying it other files will cause the app to crash and be rejected by Apple. | ||
| if (!filePath.includes('.app/')) { | ||
| if (opts.preAutoEntitlements === false) { | ||
| debugWarn('Pre-sign operation disabled for entitlements automation.'); | ||
| } | ||
| else { | ||
| debugLog('Pre-sign operation enabled for entitlements automation with versions >= `1.1.1`:', '\n', '* Disable by setting `pre-auto-entitlements` to `false`.'); | ||
| if (!opts.version || semver.gte(opts.version, '1.1.1')) { | ||
| // Enable Mac App Store sandboxing without using temporary-exception, introduced in Electron v1.1.1. Relates to electron#5601 | ||
| const newEntitlements = await preAutoEntitlements(opts, perFileOptions, { | ||
| identity, | ||
| provisioningProfile: opts.provisioningProfile | ||
| ? await getProvisioningProfile(opts.provisioningProfile, opts.keychain) | ||
| : undefined, | ||
| }); | ||
| // preAutoEntitlements may provide us new entitlements, if so we update our options | ||
| // and ensure that entitlements-loginhelper has a correct default value | ||
| if (newEntitlements) { | ||
| perFileOptions.entitlements = newEntitlements; | ||
| } | ||
| } | ||
| } | ||
| } | ||
| debugLog('Signing... ' + filePath); | ||
| const perFileArgs = [...args]; | ||
| if (perFileOptions.requirements) { | ||
| if (perFileOptions.requirements.charAt(0) === '=') { | ||
| perFileArgs.push(`-r${perFileOptions.requirements}`); | ||
| } | ||
| else { | ||
| perFileArgs.push('--requirements', perFileOptions.requirements); | ||
| } | ||
| } | ||
| if (perFileOptions.timestamp) { | ||
| perFileArgs.push('--timestamp=' + perFileOptions.timestamp); | ||
| } | ||
| else { | ||
| perFileArgs.push('--timestamp'); | ||
| } | ||
| let optionsArguments = []; | ||
| if (perFileOptions.signatureFlags) { | ||
| if (Array.isArray(perFileOptions.signatureFlags)) { | ||
| optionsArguments.push(...perFileOptions.signatureFlags); | ||
| } | ||
| else { | ||
| const flags = perFileOptions.signatureFlags.split(',').map(function (flag) { | ||
| return flag.trim(); | ||
| }); | ||
| optionsArguments.push(...flags); | ||
| } | ||
| } | ||
| if (perFileOptions.hardenedRuntime || optionsArguments.includes('runtime')) { | ||
| // Hardened runtime since darwin 17.7.0 --> macOS 10.13.6 | ||
| if (semver.gte(osRelease, '17.7.0')) { | ||
| optionsArguments.push('runtime'); | ||
| } | ||
| else { | ||
| // Remove runtime if passed in with --signature-flags | ||
| debugLog('Not enabling hardened runtime, current macOS version too low, requires 10.13.6 and higher'); | ||
| optionsArguments = optionsArguments.filter((arg) => { | ||
| return arg !== 'runtime'; | ||
| }); | ||
| } | ||
| } | ||
| if (optionsArguments.length) { | ||
| perFileArgs.push('--options', [...new Set(optionsArguments)].join(',')); | ||
| } | ||
| if (perFileOptions.additionalArguments) { | ||
| perFileArgs.push(...perFileOptions.additionalArguments); | ||
| } | ||
| await execFileAsync('codesign', perFileArgs.concat('--entitlements', perFileOptions.entitlements, filePath)); | ||
| } | ||
| // Verify code sign | ||
| debugLog('Verifying...'); | ||
| await verifySignApplication(opts); | ||
| debugLog('Verified.'); | ||
| // Check entitlements if applicable | ||
| debugLog('Displaying entitlements...'); | ||
| const result = await execFileAsync('codesign', [ | ||
| '--display', | ||
| '--entitlements', | ||
| ':-', // Write to standard output and strip off the blob header | ||
| opts.app, | ||
| ]); | ||
| debugLog('Entitlements:', '\n', result); | ||
| } | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| export async function sign(_opts) { | ||
| const validatedOpts = await validateSignOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| // Determine identity for signing | ||
| if (validatedOpts.identity) { | ||
| debugLog('`identity` passed in arguments.'); | ||
| if (validatedOpts.identityValidation === false) { | ||
| identityInUse = new Identity(validatedOpts.identity); | ||
| } | ||
| else { | ||
| identities = await findIdentities(validatedOpts.keychain || null, validatedOpts.identity); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `identity` passed in arguments...'); | ||
| if (validatedOpts.platform === 'mas') { | ||
| if (validatedOpts.type === 'distribution') { | ||
| debugLog('Finding `3rd Party Mac Developer Application` certificate for signing app distribution in the Mac App Store...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, '3rd Party Mac Developer Application:'); | ||
| } | ||
| else { | ||
| debugLog('Finding `Mac Developer` certificate for signing app in development for the Mac App Store signing...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, 'Mac Developer:'); | ||
| } | ||
| } | ||
| else { | ||
| debugLog('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, 'Developer ID Application:'); | ||
| } | ||
| } | ||
| if (!identityInUse) { | ||
| if (identities.length > 0) { | ||
| // Identity(/ies) found | ||
| if (identities.length > 1) { | ||
| debugWarn('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| } | ||
| // Pre-sign operations | ||
| if (validatedOpts.preEmbedProvisioningProfile === false) { | ||
| debugWarn('Pre-sign operation disabled for provisioning profile embedding:', '\n', '* Enable by setting `pre-embed-provisioning-profile` to `true`.'); | ||
| } | ||
| else { | ||
| debugLog('Pre-sign operation enabled for provisioning profile:', '\n', '* Disable by setting `pre-embed-provisioning-profile` to `false`.'); | ||
| await preEmbedProvisioningProfile(validatedOpts, validatedOpts.provisioningProfile | ||
| ? await getProvisioningProfile(validatedOpts.provisioningProfile, validatedOpts.keychain) | ||
| : null); | ||
| } | ||
| debugLog('Signing application...', '\n', '> Application:', validatedOpts.app, '\n', '> Platform:', validatedOpts.platform, '\n', '> Additional binaries:', validatedOpts.binaries, '\n', '> Identity:', validatedOpts.identity); | ||
| await signApplication(validatedOpts, identityInUse); | ||
| // Post-sign operations | ||
| debugLog('Application signed.'); | ||
| } | ||
| //# sourceMappingURL=sign.js.map |
| {"version":3,"file":"sign.js","sourceRoot":"","sources":["../src/sign.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,MAAM,SAAS,CAAC;AACzB,OAAO,IAAI,MAAM,WAAW,CAAC;AAC7B,OAAO,IAAI,MAAM,WAAW,CAAC;AAE7B,OAAO,EAAE,MAAM,aAAa,CAAC;AAC7B,OAAO,KAAK,MAAM,OAAO,CAAC;AAC1B,OAAO,MAAM,MAAM,QAAQ,CAAC;AAE5B,OAAO,EACL,QAAQ,EACR,SAAS,EACT,kBAAkB,EAClB,aAAa,EACb,eAAe,EACf,oBAAoB,EACpB,IAAI,GACL,MAAM,WAAW,CAAC;AACnB,OAAO,EAAE,QAAQ,EAAE,cAAc,EAAE,MAAM,sBAAsB,CAAC;AAChE,OAAO,EACL,2BAA2B,EAC3B,sBAAsB,GACvB,MAAM,iCAAiC,CAAC;AACzC,OAAO,EAAE,mBAAmB,EAAE,MAAM,wBAAwB,CAAC;AAQ7D,MAAM,SAAS,GAAG,EAAE,CAAC,OAAO,EAAE,CAAC;AAE/B;;GAEG;AACH,KAAK,UAAU,oBAAoB,CAAC,IAAiB;IACnD,IAAI,IAAI,CAAC,QAAQ,EAAE,CAAC;QAClB,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,EAAE,CAAC;YAClC,MAAM,IAAI,KAAK,CAAC,yCAAyC,CAAC,CAAC;QAC7D,CAAC;QACD,sEAAsE;IACxE,CAAC;AACH,CAAC;AAED,SAAS,kBAAkB,CAAC,MAA6B;IACvD,IAAI,MAAM,IAAI,CAAC,CAAC,MAAM,YAAY,KAAK,CAAC,EAAE,CAAC;QACzC,OAAO,CAAC,MAAM,CAAC,CAAC;IAClB,CAAC;AACH,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,gBAAgB,CAAC,IAAiB;IAC/C,MAAM,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACjC,MAAM,eAAe,CAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,IAAI,CAAC,mBAAmB,IAAI,OAAO,IAAI,CAAC,mBAAmB,KAAK,QAAQ,EAAE,CAAC;QAC7E,MAAM,IAAI,KAAK,CAAC,kDAAkD,CAAC,CAAC;IACtE,CAAC;IAED,IAAI,IAAI,CAAC,IAAI,IAAI,IAAI,CAAC,IAAI,KAAK,aAAa,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc,EAAE,CAAC;QAC7E,MAAM,IAAI,KAAK,CAAC,sDAAsD,CAAC,CAAC;IAC1E,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,oBAAoB,CAAC,IAAI,CAAC,CAAC;IAClD,MAAM,MAAM,GAAyB;QACnC,GAAG,IAAI;QACP,MAAM,EAAE,kBAAkB,CAAC,IAAI,CAAC,MAAM,CAAC;QACvC,IAAI,EAAE,IAAI,CAAC,IAAI,IAAI,cAAc;QACjC,QAAQ;KACT,CAAC;IACF,OAAO,MAAM,CAAC;AAChB,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,qBAAqB,CAAC,IAA0B;IAC7D,uBAAuB;IACvB,QAAQ,CAAC,+CAA+C,CAAC,CAAC;IAE1D,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,KAAK,SAAS,CAAC,CAAC,CAAC,IAAI,CAAC,YAAY,CAAC,CAAC,CAAC,IAAI,CAAC;IAChF,MAAM,aAAa,CACjB,UAAU,EACV,CAAC,UAAU,EAAE,QAAQ,CAAC,CAAC,MAAM,CAC3B,YAAY,KAAK,KAAK,IAAI,MAAM,CAAC,GAAG,CAAC,SAAS,EAAE,QAAQ,CAAC,CAAC,8DAA8D;QACtH,CAAC,CAAC,CAAC,UAAU,GAAG,CAAC,YAAY,KAAK,IAAI,CAAC,CAAC,CAAC,GAAG,GAAG,YAAY,CAAC,CAAC,CAAC,EAAE,CAAC,CAAC;QAClE,CAAC,CAAC,EAAE,EACN,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,CAAC,CAC1B,CACF,CAAC;AACJ,CAAC;AAED,SAAS,qBAAqB,CAAC,QAAgB,EAAE,QAA6B;IAC5E,MAAM,kBAAkB,GAAG,IAAI,CAAC,OAAO,CAAC,MAAM,CAAC,IAAI,CAAC,OAAO,EAAE,IAAI,EAAE,cAAc,CAAC,CAAC;IAEnF,IAAI,gBAAwB,CAAC;IAC7B,IAAI,QAAQ,KAAK,QAAQ,EAAE,CAAC;QAC1B,uBAAuB;QACvB,kGAAkG;QAClG,uCAAuC;QACvC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,sBAAsB,CAAC,CAAC;QAC5E,gBAAgB;QAChB,4GAA4G;QAC5G,IAAI,QAAQ,CAAC,QAAQ,CAAC,cAAc,CAAC,EAAE,CAAC;YACtC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,6BAA6B,CAAC,CAAC;YACnF,aAAa;YACb,yGAAyG;QAC3G,CAAC;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,WAAW,CAAC,EAAE,CAAC;YAC1C,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,0BAA0B,CAAC,CAAC;YAChF,kBAAkB;YAClB,8GAA8G;QAChH,CAAC;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,gBAAgB,CAAC,EAAE,CAAC;YAC/C,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,+BAA+B,CAAC,CAAC;QACvF,CAAC;IACH,CAAC;SAAM,CAAC;QACN,uBAAuB;QACvB,2DAA2D;QAC3D,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,mBAAmB,CAAC,CAAC;QAEzE,8DAA8D;QAC9D,IAAI,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE,CAAC;YAC/B,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,yBAAyB,CAAC,CAAC;QACjF,CAAC;IACH,CAAC;IAED,OAAO;QACL,YAAY,EAAE,gBAAgB;QAC9B,eAAe,EAAE,IAAI;QACrB,YAAY,EAAE,SAA+B;QAC7C,cAAc,EAAE,SAA0C;QAC1D,SAAS,EAAE,SAA+B;QAC1C,mBAAmB,EAAE,EAA0B;KAChD,CAAC;AACJ,CAAC;AAED,KAAK,UAAU,mBAAmB,CAChC,IAA+B,EAC/B,QAAkD;IAElD,MAAM,oBAAoB,GAAG,EAAE,GAAG,QAAQ,EAAE,CAAC;IAC7C,IAAI,IAAI,EAAE,CAAC;QACT,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS,EAAE,CAAC;YACpC,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,YAAY,CAAC,EAAE,CAAC;gBACrC,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC,MAAM,CAC3C,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,CAAC;oBACzB,GAAG,IAAI;oBACP,CAAC,cAAc,CAAC,EAAE,IAAI;iBACvB,CAAC,EACF,EAAE,CACH,CAAC;gBACF,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;gBACtF,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;gBAC9D,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,SAAS,CAAC,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;gBACxF,IAAI,CAAC,YAAY,GAAG,gBAAgB,CAAC;YACvC,CAAC;YACD,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;QACxD,CAAC;QACD,IAAI,IAAI,CAAC,eAAe,KAAK,SAAS,EAAE,CAAC;YACvC,oBAAoB,CAAC,eAAe,GAAG,IAAI,CAAC,eAAe,CAAC;QAC9D,CAAC;QACD,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS;YAAE,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;QAC3F,IAAI,IAAI,CAAC,cAAc,KAAK,SAAS,EAAE,CAAC;YACtC,oBAAoB,CAAC,cAAc,GAAG,IAAI,CAAC,cAAc,CAAC;QAC5D,CAAC;QACD,IAAI,IAAI,CAAC,SAAS,KAAK,SAAS;YAAE,oBAAoB,CAAC,SAAS,GAAG,IAAI,CAAC,SAAS,CAAC;QAClF,IAAI,IAAI,CAAC,mBAAmB,KAAK,SAAS;YACxC,oBAAoB,CAAC,mBAAmB,GAAG,IAAI,CAAC,mBAAmB,CAAC;IACxE,CAAC;IACD,OAAO,oBAAoB,CAAC;AAC9B,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,eAAe,CAAC,IAA0B,EAAE,QAAkB;IAC3E,SAAS,oBAAoB,CAAC,QAAgB;QAC5C,IAAI,IAAI,CAAC,MAAM,EAAE,CAAC;YAChB,OAAO,IAAI,CAAC,MAAM,CAAC,IAAI,CAAC,UAAU,MAAM;gBACtC,IAAI,OAAO,MAAM,KAAK,UAAU,EAAE,CAAC;oBACjC,OAAO,MAAM,CAAC,QAAQ,CAAC,CAAC;gBAC1B,CAAC;gBACD,OAAO,QAAQ,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC;YAChC,CAAC,CAAC,CAAC;QACL,CAAC;QACD,OAAO,KAAK,CAAC;IACf,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,CAAC,CAAC;IAEtD,IAAI,IAAI,CAAC,QAAQ;QAAE,QAAQ,CAAC,IAAI,CAAC,GAAG,IAAI,CAAC,QAAQ,CAAC,CAAC;IAEnD,MAAM,IAAI,GAAG,CAAC,QAAQ,EAAE,QAAQ,CAAC,IAAI,IAAI,QAAQ,CAAC,IAAI,EAAE,SAAS,CAAC,CAAC;IACnE,IAAI,IAAI,CAAC,QAAQ,EAAE,CAAC;QAClB,IAAI,CAAC,IAAI,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;IACzC,CAAC;IAED;;;;OAIG;IACH,QAAQ,CAAC,IAAI,CAAC,CAAC,CAAC,EAAE,CAAC,EAAE,EAAE;QACrB,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,OAAO,MAAM,GAAG,MAAM,CAAC;IACzB,CAAC,CAAC,CAAC;IAEH,KAAK,MAAM,QAAQ,IAAI,CAAC,GAAG,QAAQ,EAAE,IAAI,CAAC,GAAG,CAAC,EAAE,CAAC;QAC/C,IAAI,oBAAoB,CAAC,QAAQ,CAAC,EAAE,CAAC;YACnC,QAAQ,CAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;YACnC,SAAS;QACX,CAAC;QAED,MAAM,cAAc,GAAG,MAAM,mBAAmB,CAC9C,IAAI,CAAC,cAAc,CAAC,CAAC,CAAC,IAAI,CAAC,cAAc,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,IAAI,EAC1D,qBAAqB,CAAC,QAAQ,EAAE,IAAI,CAAC,QAAQ,CAAC,CAC/C,CAAC;QAEF,0EAA0E;QAC1E,gFAAgF;QAChF,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE,CAAC;YAChC,IAAI,IAAI,CAAC,mBAAmB,KAAK,KAAK,EAAE,CAAC;gBACvC,SAAS,CAAC,0DAA0D,CAAC,CAAC;YACxE,CAAC;iBAAM,CAAC;gBACN,QAAQ,CACN,kFAAkF,EAClF,IAAI,EACJ,0DAA0D,CAC3D,CAAC;gBACF,IAAI,CAAC,IAAI,CAAC,OAAO,IAAI,MAAM,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,OAAO,CAAC,EAAE,CAAC;oBACvD,6HAA6H;oBAC7H,MAAM,eAAe,GAAG,MAAM,mBAAmB,CAAC,IAAI,EAAE,cAAc,EAAE;wBACtE,QAAQ;wBACR,mBAAmB,EAAE,IAAI,CAAC,mBAAmB;4BAC3C,CAAC,CAAC,MAAM,sBAAsB,CAAC,IAAI,CAAC,mBAAmB,EAAE,IAAI,CAAC,QAAQ,CAAC;4BACvE,CAAC,CAAC,SAAS;qBACd,CAAC,CAAC;oBAEH,mFAAmF;oBACnF,uEAAuE;oBACvE,IAAI,eAAe,EAAE,CAAC;wBACpB,cAAc,CAAC,YAAY,GAAG,eAAe,CAAC;oBAChD,CAAC;gBACH,CAAC;YACH,CAAC;QACH,CAAC;QAED,QAAQ,CAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;QAEnC,MAAM,WAAW,GAAG,CAAC,GAAG,IAAI,CAAC,CAAC;QAE9B,IAAI,cAAc,CAAC,YAAY,EAAE,CAAC;YAChC,IAAI,cAAc,CAAC,YAAY,CAAC,MAAM,CAAC,CAAC,CAAC,KAAK,GAAG,EAAE,CAAC;gBAClD,WAAW,CAAC,IAAI,CAAC,KAAK,cAAc,CAAC,YAAY,EAAE,CAAC,CAAC;YACvD,CAAC;iBAAM,CAAC;gBACN,WAAW,CAAC,IAAI,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,CAAC,CAAC;YAClE,CAAC;QACH,CAAC;QACD,IAAI,cAAc,CAAC,SAAS,EAAE,CAAC;YAC7B,WAAW,CAAC,IAAI,CAAC,cAAc,GAAG,cAAc,CAAC,SAAS,CAAC,CAAC;QAC9D,CAAC;aAAM,CAAC;YACN,WAAW,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;QAClC,CAAC;QAED,IAAI,gBAAgB,GAAa,EAAE,CAAC;QAEpC,IAAI,cAAc,CAAC,cAAc,EAAE,CAAC;YAClC,IAAI,KAAK,CAAC,OAAO,CAAC,cAAc,CAAC,cAAc,CAAC,EAAE,CAAC;gBACjD,gBAAgB,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,cAAc,CAAC,CAAC;YAC1D,CAAC;iBAAM,CAAC;gBACN,MAAM,KAAK,GAAG,cAAc,CAAC,cAAc,CAAC,KAAK,CAAC,GAAG,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;oBACvE,OAAO,IAAI,CAAC,IAAI,EAAE,CAAC;gBACrB,CAAC,CAAC,CAAC;gBACH,gBAAgB,CAAC,IAAI,CAAC,GAAG,KAAK,CAAC,CAAC;YAClC,CAAC;QACH,CAAC;QAED,IAAI,cAAc,CAAC,eAAe,IAAI,gBAAgB,CAAC,QAAQ,CAAC,SAAS,CAAC,EAAE,CAAC;YAC3E,yDAAyD;YACzD,IAAI,MAAM,CAAC,GAAG,CAAC,SAAS,EAAE,QAAQ,CAAC,EAAE,CAAC;gBACpC,gBAAgB,CAAC,IAAI,CAAC,SAAS,CAAC,CAAC;YACnC,CAAC;iBAAM,CAAC;gBACN,qDAAqD;gBACrD,QAAQ,CACN,2FAA2F,CAC5F,CAAC;gBACF,gBAAgB,GAAG,gBAAgB,CAAC,MAAM,CAAC,CAAC,GAAG,EAAE,EAAE;oBACjD,OAAO,GAAG,KAAK,SAAS,CAAC;gBAC3B,CAAC,CAAC,CAAC;YACL,CAAC;QACH,CAAC;QAED,IAAI,gBAAgB,CAAC,MAAM,EAAE,CAAC;YAC5B,WAAW,CAAC,IAAI,CAAC,WAAW,EAAE,CAAC,GAAG,IAAI,GAAG,CAAC,gBAAgB,CAAC,CAAC,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC;QAC1E,CAAC;QAED,IAAI,cAAc,CAAC,mBAAmB,EAAE,CAAC;YACvC,WAAW,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,mBAAmB,CAAC,CAAC;QAC1D,CAAC;QAED,MAAM,aAAa,CACjB,UAAU,EACV,WAAW,CAAC,MAAM,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,EAAE,QAAQ,CAAC,CAC5E,CAAC;IACJ,CAAC;IAED,mBAAmB;IACnB,QAAQ,CAAC,cAAc,CAAC,CAAC;IACzB,MAAM,qBAAqB,CAAC,IAAI,CAAC,CAAC;IAClC,QAAQ,CAAC,WAAW,CAAC,CAAC;IAEtB,mCAAmC;IACnC,QAAQ,CAAC,4BAA4B,CAAC,CAAC;IACvC,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE;QAC7C,WAAW;QACX,gBAAgB;QAChB,IAAI,EAAE,yDAAyD;QAC/D,IAAI,CAAC,GAAG;KACT,CAAC,CAAC;IAEH,QAAQ,CAAC,eAAe,EAAE,IAAI,EAAE,MAAM,CAAC,CAAC;AAC1C,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,KAAK,UAAU,IAAI,CAAC,KAAkB;IAC3C,MAAM,aAAa,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACpD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,iCAAiC;IACjC,IAAI,aAAa,CAAC,QAAQ,EAAE,CAAC;QAC3B,QAAQ,CAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,aAAa,CAAC,kBAAkB,KAAK,KAAK,EAAE,CAAC;YAC/C,aAAa,GAAG,IAAI,QAAQ,CAAC,aAAa,CAAC,QAAQ,CAAC,CAAC;QACvD,CAAC;aAAM,CAAC;YACN,UAAU,GAAG,MAAM,cAAc,CAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,aAAa,CAAC,QAAQ,CAAC,CAAC;QAC5F,CAAC;IACH,CAAC;SAAM,CAAC;QACN,SAAS,CAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,aAAa,CAAC,QAAQ,KAAK,KAAK,EAAE,CAAC;YACrC,IAAI,aAAa,CAAC,IAAI,KAAK,cAAc,EAAE,CAAC;gBAC1C,QAAQ,CACN,gHAAgH,CACjH,CAAC;gBACF,UAAU,GAAG,MAAM,cAAc,CAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,sCAAsC,CACvC,CAAC;YACJ,CAAC;iBAAM,CAAC;gBACN,QAAQ,CACN,qGAAqG,CACtG,CAAC;gBACF,UAAU,GAAG,MAAM,cAAc,CAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,gBAAgB,CAAC,CAAC;YACtF,CAAC;QACH,CAAC;aAAM,CAAC;YACN,QAAQ,CACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,2BAA2B,CAC5B,CAAC;QACJ,CAAC;IACH,CAAC;IAED,IAAI,CAAC,aAAa,EAAE,CAAC;QACnB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;YAC1B,uBAAuB;YACvB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;gBAC1B,SAAS,CAAC,2DAA2D,CAAC,CAAC;YACzE,CAAC;iBAAM,CAAC;gBACN,QAAQ,CAAC,mBAAmB,CAAC,CAAC;YAChC,CAAC;YACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;QAChC,CAAC;aAAM,CAAC;YACN,oBAAoB;YACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;QACpD,CAAC;IACH,CAAC;IAED,sBAAsB;IACtB,IAAI,aAAa,CAAC,2BAA2B,KAAK,KAAK,EAAE,CAAC;QACxD,SAAS,CACP,iEAAiE,EACjE,IAAI,EACJ,iEAAiE,CAClE,CAAC;IACJ,CAAC;SAAM,CAAC;QACN,QAAQ,CACN,sDAAsD,EACtD,IAAI,EACJ,mEAAmE,CACpE,CAAC;QACF,MAAM,2BAA2B,CAC/B,aAAa,EACb,aAAa,CAAC,mBAAmB;YAC/B,CAAC,CAAC,MAAM,sBAAsB,CAAC,aAAa,CAAC,mBAAmB,EAAE,aAAa,CAAC,QAAQ,CAAC;YACzF,CAAC,CAAC,IAAI,CACT,CAAC;IACJ,CAAC;IAED,QAAQ,CACN,wBAAwB,EACxB,IAAI,EACJ,gBAAgB,EAChB,aAAa,CAAC,GAAG,EACjB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,wBAAwB,EACxB,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,CACvB,CAAC;IACF,MAAM,eAAe,CAAC,aAAa,EAAE,aAAa,CAAC,CAAC;IAEpD,uBAAuB;IACvB,QAAQ,CAAC,qBAAqB,CAAC,CAAC;AAClC,CAAC"} |
+258
| /** | ||
| * macOS applications can be distributed via the Mac App Store (MAS) or directly | ||
| * downloaded from the developer's website. @electron/osx-sign distinguishes between | ||
| * MAS apps (`mas`) or non-MAS apps (`darwin`). | ||
| * @category Utility | ||
| */ | ||
| export type ElectronMacPlatform = 'darwin' | 'mas'; | ||
| /** | ||
| * MAS apps can be signed using Development or Distribution certificates. | ||
| * See [Apple Documentation](https://developer.apple.com/help/account/create-certificates/certificates-overview/) for more info. | ||
| * @category Utility | ||
| */ | ||
| export type SigningDistributionType = 'development' | 'distribution'; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type BaseSignOptions = Readonly<{ | ||
| /** | ||
| * Path to the application package. | ||
| * Needs to end with the file extension `.app`. | ||
| */ | ||
| app: string; | ||
| /** | ||
| * The keychain name. | ||
| * | ||
| * @defaultValue `login` | ||
| */ | ||
| keychain?: string; | ||
| /** | ||
| * Build platform of your Electron app. | ||
| * Allowed values: `darwin` (Direct Download App), `mas` (Mac App Store). | ||
| * | ||
| * @defaultValue Determined by presence of `Squirrel.framework` within the application bundle, | ||
| * which is used for non-MAS apps. | ||
| */ | ||
| platform?: ElectronMacPlatform; | ||
| /** | ||
| * Name of the certificate to use when signing. | ||
| * | ||
| * @defaultValue Selected with respect to {@link SignOptions.provisioningProfile | provisioningProfile} | ||
| * and {@link SignOptions.platform | platform} from the selected {@link SignOptions.keychain | keychain}. | ||
| * * `mas` will look for `3rd Party Mac Developer Application: * (*)` | ||
| * * `darwin` will look for `Developer ID Application: * (*)` by default. | ||
| */ | ||
| identity?: string; | ||
| }>; | ||
| type OnlyValidatedBaseSignOptions = { | ||
| platform: ElectronMacPlatform; | ||
| }; | ||
| /** | ||
| * A set of signing options that can be overriden on a per-file basis. | ||
| * Any missing options will use the default values, and providing a partial structure | ||
| * will shallow merge with the default values. | ||
| * @interface | ||
| * @category Codesign | ||
| */ | ||
| export type PerFileSignOptions = { | ||
| /** | ||
| * String specifying the path to an `entitlements.plist` file. | ||
| * Can also be an array of entitlement keys that osx-sign will write to an entitlements file for you. | ||
| * | ||
| * @defaultValue `@electron/osx-sign`'s built-in entitlements files. | ||
| */ | ||
| entitlements?: string | string[]; | ||
| /** | ||
| * Whether to enable [Hardened Runtime](https://developer.apple.com/documentation/security/hardened_runtime) | ||
| * for this file. | ||
| * | ||
| * Note: Hardened Runtime is a pre-requisite for notarization, which is mandatory for apps running on macOS 10.15 and above. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| hardenedRuntime?: boolean; | ||
| /** | ||
| * Either a string beginning with `=` which specifies in plain text the | ||
| * [signing requirements](https://developer.apple.com/library/mac/documentation/Security/Conceptual/CodeSigningGuide/RequirementLang/RequirementLang.html) | ||
| * that you recommend to be used to evaluate the code signature, or a string specifying a path to a text or | ||
| * properly encoded `.rqset` file which contains those requirements. | ||
| */ | ||
| requirements?: string; | ||
| /** | ||
| * When signing, a set of option flags can be specified to change the behavior of the system when using the signed code. | ||
| * Accepts an array of strings or a comma-separated string. | ||
| * | ||
| * See --options of the `codesign` command. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTION_FLAGS | ||
| */ | ||
| signatureFlags?: string | string[]; | ||
| /** | ||
| * String specifying the URL of the timestamp authority server. | ||
| * Please note that this default server may not support signatures not furnished by Apple. | ||
| * Disable the timestamp service with `none`. | ||
| * | ||
| * @defaultValue Uses the Apple-provided timestamp server. | ||
| */ | ||
| timestamp?: string; | ||
| /** | ||
| * Additional raw arguments to pass to the `codesign` command. | ||
| * | ||
| * These can be things like `--deep` for instance when code signing specific resources that may | ||
| * require such arguments. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTIONS | ||
| */ | ||
| additionalArguments?: string[]; | ||
| }; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type OnlySignOptions = { | ||
| /** | ||
| * Array of paths to additional binaries that will be signed along with built-ins of Electron. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| binaries?: string[]; | ||
| /** | ||
| * Function that receives the path to a file and can return the entitlements to use for that file to override the default behavior. The | ||
| * object this function returns can include any of the following optional keys. Any properties that are returned **override** the default | ||
| * values that `@electron/osx-sign` generates. Any properties not returned use the default value. | ||
| * | ||
| * @param filePath Path to file | ||
| * @returns Override signing options | ||
| */ | ||
| optionsForFile?: (filePath: string) => PerFileSignOptions; | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link SignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Defines files that will be skipped during the code signing process. | ||
| * This property accepts a regex, function or an array of regexes and functions. | ||
| * Elements of other types are treated as `RegExp`. | ||
| * | ||
| * File paths matching a regex or returning a `true` value from a function will be ignored. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| ignore?: string | string[] | ((file: string) => boolean); | ||
| /** | ||
| * Flag to enable/disable entitlements automation tasks necessary for code signing most Electron apps. | ||
| * * Adds [`com.apple.security.application-groups`](https://developer.apple.com/documentation/bundleresources/entitlements/com_apple_security_application-groups) to the entitlements file | ||
| * * Fills in the `ElectronTeamID` property in `Info.plist` with the provisioning profile's Team Identifier or by parsing the identity name. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preAutoEntitlements?: boolean; | ||
| /** | ||
| * Flag to enable/disable the embedding of a provisioning profile into the app's `Contents` folder. | ||
| * Will use the profile from {@link OnlySignOptions.provisioningProfile} if provided. Otherwise, it | ||
| * searches for a `.provisionprofile` file in the current working directory. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preEmbedProvisioningProfile?: boolean; | ||
| /** | ||
| * Path to a provisioning profile, which can be used to grant restricted entitlements to your app. | ||
| * | ||
| * See [Apple Documentation](https://developer.apple.com/documentation/technotes/tn3125-inside-code-signing-provisioning-profiles) for more details. | ||
| */ | ||
| provisioningProfile?: string; | ||
| /** | ||
| * Flag to enable/disable the `--strict` flag when verifying the signed application bundle. | ||
| * Also supports string values to specify which strict restrictions to use, see codesign man page for supported values. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| strictVerify?: boolean | string; | ||
| /** | ||
| * Type of certificate to use when signing a MAS app. | ||
| * @defaultValue `"distribution"` | ||
| */ | ||
| type?: SigningDistributionType; | ||
| /** | ||
| * Build version of Electron. Values may be like: `1.1.1`, `1.2.0`. For use for signing legacy versions | ||
| * of Electron to ensure backwards compatibility. | ||
| */ | ||
| version?: string; | ||
| }; | ||
| type OnlyValidatedSignOptions = { | ||
| ignore?: (string | ((file: string) => boolean))[]; | ||
| type: SigningDistributionType; | ||
| }; | ||
| type OnlyFlatOptions = { | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link BaseSignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Path to install the bundle. | ||
| * @defaultValue `"/Applications"` | ||
| */ | ||
| install?: string; | ||
| /** | ||
| * Output path for the flattened installer package. | ||
| * Needs file extension `.pkg`. | ||
| * | ||
| * @defaultValue Inferred from the app name passed into `opts.app`. | ||
| */ | ||
| pkg?: string; | ||
| /** | ||
| * Path to a directory containing `preinstall.sh` or `postinstall.sh` scripts. | ||
| * These must be executable and will run on pre/postinstall depending on the file | ||
| * name. | ||
| * | ||
| * This option is only valid if {@link FlatOptions.platform} is set to `darwin`. | ||
| */ | ||
| scripts?: string; | ||
| }; | ||
| type OnlyValidatedFlatOptions = { | ||
| install: string; | ||
| pkg: string; | ||
| }; | ||
| /** | ||
| * Utility type that represents an `UnValidated` type after validation, | ||
| * replacing any properties in the unvalidated type that also exist in the | ||
| * `Validated` type with the validated versions. | ||
| * | ||
| * @template UnValidated - The type representing the unvalidated form. | ||
| * @template Validated - The type representing the validated form. | ||
| */ | ||
| type ValidatedForm<UnValidated, Validated> = Omit<UnValidated, keyof Validated> & Validated; | ||
| type ValidatedBaseSignOptions = Readonly<ValidatedForm<BaseSignOptions, OnlyValidatedBaseSignOptions>>; | ||
| type _SignOptions = Readonly<OnlySignOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for codesigning a packaged `.app` bundle. | ||
| * @category Codesign | ||
| */ | ||
| export interface SignOptions extends _SignOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedSignOptions = Readonly<ValidatedForm<OnlySignOptions, OnlyValidatedSignOptions> & ValidatedBaseSignOptions>; | ||
| type _FlatOptions = Readonly<OnlyFlatOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for creating a flat `.pkg` installer. | ||
| * @category Flat | ||
| */ | ||
| export interface FlatOptions extends _FlatOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedFlatOptions = Readonly<ValidatedForm<OnlyFlatOptions, OnlyValidatedFlatOptions> & ValidatedBaseSignOptions>; | ||
| export {}; |
| export {}; | ||
| //# sourceMappingURL=types.js.map |
| {"version":3,"file":"types.js","sourceRoot":"","sources":["../src/types.ts"],"names":[],"mappings":""} |
| import type { PerFileSignOptions, ValidatedSignOptions } from './types.js'; | ||
| import type { Identity } from './util-identities.js'; | ||
| import type { ProvisioningProfile } from './util-provisioning-profiles.js'; | ||
| type ComputedOptions = { | ||
| identity: Identity; | ||
| provisioningProfile?: ProvisioningProfile; | ||
| }; | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| export declare function preAutoEntitlements(opts: ValidatedSignOptions, perFileOpts: PerFileSignOptions, computed: ComputedOptions): Promise<void | string>; | ||
| export {}; |
| import os from 'node:os'; | ||
| import path from 'node:path'; | ||
| import util from 'node:util'; | ||
| import fs from 'graceful-fs'; | ||
| import plist from 'plist'; | ||
| import { debugLog, getAppContentsPath } from './util.js'; | ||
| const preAuthMemo = new Map(); | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| export async function preAutoEntitlements(opts, perFileOpts, computed) { | ||
| if (!perFileOpts.entitlements) | ||
| return; | ||
| const memoKey = [opts.app, perFileOpts.entitlements].join('---'); | ||
| if (preAuthMemo.has(memoKey)) | ||
| return preAuthMemo.get(memoKey); | ||
| // If entitlements file not provided, default will be used. Fixes #41 | ||
| const appInfoPath = path.join(getAppContentsPath(opts), 'Info.plist'); | ||
| debugLog('Automating entitlement app group...', '\n', '> Info.plist:', appInfoPath, '\n'); | ||
| let entitlements; | ||
| if (typeof perFileOpts.entitlements === 'string') { | ||
| const entitlementsContents = await util.promisify(fs.readFile)(perFileOpts.entitlements, 'utf8'); | ||
| entitlements = plist.parse(entitlementsContents); | ||
| } | ||
| else { | ||
| entitlements = perFileOpts.entitlements.reduce((dict, entitlementKey) => ({ | ||
| ...dict, | ||
| [entitlementKey]: true, | ||
| }), {}); | ||
| } | ||
| if (!entitlements['com.apple.security.app-sandbox']) { | ||
| // Only automate when app sandbox enabled by user | ||
| return; | ||
| } | ||
| const appInfoContents = await util.promisify(fs.readFile)(appInfoPath, 'utf8'); | ||
| const appInfo = plist.parse(appInfoContents); | ||
| // Use ElectronTeamID in Info.plist if already specified | ||
| if (appInfo.ElectronTeamID) { | ||
| debugLog('`ElectronTeamID` found in `Info.plist`: ' + appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| // The team identifier in signing identity should not be trusted | ||
| if (computed.provisioningProfile) { | ||
| appInfo.ElectronTeamID = | ||
| computed.provisioningProfile.message.Entitlements['com.apple.developer.team-identifier']; | ||
| debugLog('`ElectronTeamID` not found in `Info.plist`, use parsed from provisioning profile: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| const teamID = /^.+\((.+?)\)$/g.exec(computed.identity.name)?.[1]; | ||
| if (!teamID) { | ||
| throw new Error(`Could not automatically determine ElectronTeamID from identity: ${computed.identity.name}`); | ||
| } | ||
| appInfo.ElectronTeamID = teamID; | ||
| debugLog('`ElectronTeamID` not found in `Info.plist`, use parsed from signing identity: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| await util.promisify(fs.writeFile)(appInfoPath, plist.build(appInfo), 'utf8'); | ||
| debugLog('`Info.plist` updated:', '\n', '> Info.plist:', appInfoPath); | ||
| } | ||
| const appIdentifier = appInfo.ElectronTeamID + '.' + appInfo.CFBundleIdentifier; | ||
| // Insert application identifier if not exists | ||
| if (entitlements['com.apple.application-identifier']) { | ||
| debugLog('`com.apple.application-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.application-identifier']); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.application-identifier` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.application-identifier'] = appIdentifier; | ||
| } | ||
| // Insert developer team identifier if not exists | ||
| if (entitlements['com.apple.developer.team-identifier']) { | ||
| debugLog('`com.apple.developer.team-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.developer.team-identifier']); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.developer.team-identifier` not found in entitlements file, new inserted: ' + | ||
| appInfo.ElectronTeamID); | ||
| entitlements['com.apple.developer.team-identifier'] = appInfo.ElectronTeamID; | ||
| } | ||
| // Init entitlements app group key to array if not exists | ||
| if (!entitlements['com.apple.security.application-groups']) { | ||
| entitlements['com.apple.security.application-groups'] = []; | ||
| } | ||
| // Insert app group if not exists | ||
| if (Array.isArray(entitlements['com.apple.security.application-groups']) && | ||
| entitlements['com.apple.security.application-groups'].indexOf(appIdentifier) === -1) { | ||
| debugLog('`com.apple.security.application-groups` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.security.application-groups'].push(appIdentifier); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.security.application-groups` found in entitlements file: ' + appIdentifier); | ||
| } | ||
| // Create temporary entitlements file | ||
| const dir = await fs.promises.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await util.promisify(fs.writeFile)(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| debugLog('Entitlements file updated:', '\n', '> Entitlements:', entitlementsPath); | ||
| preAuthMemo.set(memoKey, entitlementsPath); | ||
| return entitlementsPath; | ||
| } | ||
| //# sourceMappingURL=util-entitlements.js.map |
| {"version":3,"file":"util-entitlements.js","sourceRoot":"","sources":["../src/util-entitlements.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,MAAM,SAAS,CAAC;AACzB,OAAO,IAAI,MAAM,WAAW,CAAC;AAC7B,OAAO,IAAI,MAAM,WAAW,CAAC;AAE7B,OAAO,EAAE,MAAM,aAAa,CAAC;AAC7B,OAAO,KAAK,MAAM,OAAO,CAAC;AAG1B,OAAO,EAAE,QAAQ,EAAE,kBAAkB,EAAE,MAAM,WAAW,CAAC;AASzD,MAAM,WAAW,GAAG,IAAI,GAAG,EAAkB,CAAC;AAE9C;;;;;;;GAOG;AACH,MAAM,CAAC,KAAK,UAAU,mBAAmB,CACvC,IAA0B,EAC1B,WAA+B,EAC/B,QAAyB;IAEzB,IAAI,CAAC,WAAW,CAAC,YAAY;QAAE,OAAO;IAEtC,MAAM,OAAO,GAAG,CAAC,IAAI,CAAC,GAAG,EAAE,WAAW,CAAC,YAAY,CAAC,CAAC,IAAI,CAAC,KAAK,CAAC,CAAC;IACjE,IAAI,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC;QAAE,OAAO,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC,CAAC;IAE9D,qEAAqE;IACrE,MAAM,WAAW,GAAG,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;IAEtE,QAAQ,CAAC,qCAAqC,EAAE,IAAI,EAAE,eAAe,EAAE,WAAW,EAAE,IAAI,CAAC,CAAC;IAC1F,IAAI,YAAiC,CAAC;IACtC,IAAI,OAAO,WAAW,CAAC,YAAY,KAAK,QAAQ,EAAE,CAAC;QACjD,MAAM,oBAAoB,GAAG,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,QAAQ,CAAC,CAC5D,WAAW,CAAC,YAAY,EACxB,MAAM,CACP,CAAC;QACF,YAAY,GAAG,KAAK,CAAC,KAAK,CAAC,oBAAoB,CAAwB,CAAC;IAC1E,CAAC;SAAM,CAAC;QACN,YAAY,GAAG,WAAW,CAAC,YAAY,CAAC,MAAM,CAC5C,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,CAAC;YACzB,GAAG,IAAI;YACP,CAAC,cAAc,CAAC,EAAE,IAAI;SACvB,CAAC,EACF,EAAE,CACH,CAAC;IACJ,CAAC;IACD,IAAI,CAAC,YAAY,CAAC,gCAAgC,CAAC,EAAE,CAAC;QACpD,iDAAiD;QACjD,OAAO;IACT,CAAC;IAED,MAAM,eAAe,GAAG,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,QAAQ,CAAC,CAAC,WAAW,EAAE,MAAM,CAAC,CAAC;IAC/E,MAAM,OAAO,GAAG,KAAK,CAAC,KAAK,CAAC,eAAe,CAAwB,CAAC;IACpE,wDAAwD;IACxD,IAAI,OAAO,CAAC,cAAc,EAAE,CAAC;QAC3B,QAAQ,CAAC,0CAA0C,GAAG,OAAO,CAAC,cAAc,CAAC,CAAC;IAChF,CAAC;SAAM,CAAC;QACN,gEAAgE;QAChE,IAAI,QAAQ,CAAC,mBAAmB,EAAE,CAAC;YACjC,OAAO,CAAC,cAAc;gBACpB,QAAQ,CAAC,mBAAmB,CAAC,OAAO,CAAC,YAAY,CAAC,qCAAqC,CAAC,CAAC;YAC3F,QAAQ,CACN,oFAAoF;gBAClF,OAAO,CAAC,cAAc,CACzB,CAAC;QACJ,CAAC;aAAM,CAAC;YACN,MAAM,MAAM,GAAG,gBAAgB,CAAC,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,IAAI,CAAC,EAAE,CAAC,CAAC,CAAC,CAAC;YAClE,IAAI,CAAC,MAAM,EAAE,CAAC;gBACZ,MAAM,IAAI,KAAK,CACb,mEAAmE,QAAQ,CAAC,QAAQ,CAAC,IAAI,EAAE,CAC5F,CAAC;YACJ,CAAC;YACD,OAAO,CAAC,cAAc,GAAG,MAAM,CAAC;YAChC,QAAQ,CACN,gFAAgF;gBAC9E,OAAO,CAAC,cAAc,CACzB,CAAC;QACJ,CAAC;QACD,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,SAAS,CAAC,CAAC,WAAW,EAAE,KAAK,CAAC,KAAK,CAAC,OAAO,CAAC,EAAE,MAAM,CAAC,CAAC;QAE9E,QAAQ,CAAC,uBAAuB,EAAE,IAAI,EAAE,eAAe,EAAE,WAAW,CAAC,CAAC;IACxE,CAAC;IAED,MAAM,aAAa,GAAG,OAAO,CAAC,cAAc,GAAG,GAAG,GAAG,OAAO,CAAC,kBAAkB,CAAC;IAChF,8CAA8C;IAC9C,IAAI,YAAY,CAAC,kCAAkC,CAAC,EAAE,CAAC;QACrD,QAAQ,CACN,iEAAiE;YAC/D,YAAY,CAAC,kCAAkC,CAAC,CACnD,CAAC;IACJ,CAAC;SAAM,CAAC;QACN,QAAQ,CACN,mFAAmF;YACjF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,kCAAkC,CAAC,GAAG,aAAa,CAAC;IACnE,CAAC;IACD,iDAAiD;IACjD,IAAI,YAAY,CAAC,qCAAqC,CAAC,EAAE,CAAC;QACxD,QAAQ,CACN,oEAAoE;YAClE,YAAY,CAAC,qCAAqC,CAAC,CACtD,CAAC;IACJ,CAAC;SAAM,CAAC;QACN,QAAQ,CACN,sFAAsF;YACpF,OAAO,CAAC,cAAc,CACzB,CAAC;QACF,YAAY,CAAC,qCAAqC,CAAC,GAAG,OAAO,CAAC,cAAc,CAAC;IAC/E,CAAC;IACD,yDAAyD;IACzD,IAAI,CAAC,YAAY,CAAC,uCAAuC,CAAC,EAAE,CAAC;QAC3D,YAAY,CAAC,uCAAuC,CAAC,GAAG,EAAE,CAAC;IAC7D,CAAC;IACD,iCAAiC;IACjC,IACE,KAAK,CAAC,OAAO,CAAC,YAAY,CAAC,uCAAuC,CAAC,CAAC;QACpE,YAAY,CAAC,uCAAuC,CAAC,CAAC,OAAO,CAAC,aAAa,CAAC,KAAK,CAAC,CAAC,EACnF,CAAC;QACD,QAAQ,CACN,wFAAwF;YACtF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,uCAAuC,CAAC,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;IAC5E,CAAC;SAAM,CAAC;QACN,QAAQ,CACN,sEAAsE,GAAG,aAAa,CACvF,CAAC;IACJ,CAAC;IACD,qCAAqC;IACrC,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;IACtF,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;IAC9D,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,SAAS,CAAC,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;IACxF,QAAQ,CAAC,4BAA4B,EAAE,IAAI,EAAE,iBAAiB,EAAE,gBAAgB,CAAC,CAAC;IAElF,WAAW,CAAC,GAAG,CAAC,OAAO,EAAE,gBAAgB,CAAC,CAAC;IAC3C,OAAO,gBAAgB,CAAC;AAC1B,CAAC"} |
| export declare class Identity { | ||
| name: string; | ||
| hash?: string | undefined; | ||
| constructor(name: string, hash?: string | undefined); | ||
| } | ||
| export declare function findIdentities(keychain: string | null, identity: string): Promise<Identity[]>; |
| import { debugLog, compactFlattenedList, execFileAsync } from './util.js'; | ||
| export class Identity { | ||
| name; | ||
| hash; | ||
| constructor(name, hash) { | ||
| this.name = name; | ||
| this.hash = hash; | ||
| } | ||
| } | ||
| export async function findIdentities(keychain, identity) { | ||
| // Only to look for valid identities, excluding those flagged with | ||
| // CSSMERR_TP_CERT_EXPIRED or CSSMERR_TP_NOT_TRUSTED. Fixes #9 | ||
| const args = ['find-identity', '-v']; | ||
| if (keychain) { | ||
| args.push(keychain); | ||
| } | ||
| const result = await execFileAsync('security', args); | ||
| const identities = result.split('\n').map(function (line) { | ||
| if (line.indexOf(identity) >= 0) { | ||
| const identityFound = line.substring(line.indexOf('"') + 1, line.lastIndexOf('"')); | ||
| const identityHashFound = line.substring(line.indexOf(')') + 2, line.indexOf('"') - 1); | ||
| debugLog('Identity:', '\n', '> Name:', identityFound, '\n', '> Hash:', identityHashFound); | ||
| return new Identity(identityFound, identityHashFound); | ||
| } | ||
| return null; | ||
| }); | ||
| return compactFlattenedList(identities); | ||
| } | ||
| //# sourceMappingURL=util-identities.js.map |
| {"version":3,"file":"util-identities.js","sourceRoot":"","sources":["../src/util-identities.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,QAAQ,EAAE,oBAAoB,EAAE,aAAa,EAAE,MAAM,WAAW,CAAC;AAE1E,MAAM,OAAO,QAAQ;IAEV;IACA;IAFT,YACS,IAAY,EACZ,IAAa;QADb,SAAI,GAAJ,IAAI,CAAQ;QACZ,SAAI,GAAJ,IAAI,CAAS;IACnB,CAAC;CACL;AAED,MAAM,CAAC,KAAK,UAAU,cAAc,CAAC,QAAuB,EAAE,QAAgB;IAC5E,kEAAkE;IAClE,8DAA8D;IAE9D,MAAM,IAAI,GAAG,CAAC,eAAe,EAAE,IAAI,CAAC,CAAC;IACrC,IAAI,QAAQ,EAAE,CAAC;QACb,IAAI,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;IACtB,CAAC;IAED,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE,IAAI,CAAC,CAAC;IACrD,MAAM,UAAU,GAAG,MAAM,CAAC,KAAK,CAAC,IAAI,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;QACtD,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,IAAI,CAAC,EAAE,CAAC;YAChC,MAAM,aAAa,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,WAAW,CAAC,GAAG,CAAC,CAAC,CAAC;YACnF,MAAM,iBAAiB,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,CAAC,CAAC;YACvF,QAAQ,CAAC,WAAW,EAAE,IAAI,EAAE,SAAS,EAAE,aAAa,EAAE,IAAI,EAAE,SAAS,EAAE,iBAAiB,CAAC,CAAC;YAC1F,OAAO,IAAI,QAAQ,CAAC,aAAa,EAAE,iBAAiB,CAAC,CAAC;QACxD,CAAC;QAED,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CAAC;IAEH,OAAO,oBAAoB,CAAC,UAAU,CAAC,CAAC;AAC1C,CAAC"} |
| import type { ElectronMacPlatform, ValidatedSignOptions } from './types.js'; | ||
| export declare class ProvisioningProfile { | ||
| filePath: string; | ||
| message: any; | ||
| constructor(filePath: string, message: any); | ||
| get name(): string; | ||
| get platforms(): ElectronMacPlatform[]; | ||
| get type(): "development" | "distribution"; | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| export declare function getProvisioningProfile(filePath: string, keychain?: string | null): Promise<ProvisioningProfile>; | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| export declare function findProvisioningProfiles(opts: ValidatedSignOptions): Promise<ProvisioningProfile[]>; | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| export declare function preEmbedProvisioningProfile(opts: ValidatedSignOptions, profile: ProvisioningProfile | null): Promise<void>; |
| import path from 'node:path'; | ||
| import util from 'node:util'; | ||
| import fs from 'graceful-fs'; | ||
| import plist from 'plist'; | ||
| import { debugLog, debugWarn, getAppContentsPath, compactFlattenedList, execFileAsync, } from './util.js'; | ||
| export class ProvisioningProfile { | ||
| filePath; | ||
| message; | ||
| constructor(filePath, message) { | ||
| this.filePath = filePath; | ||
| this.message = message; | ||
| } | ||
| get name() { | ||
| return this.message.Name; | ||
| } | ||
| get platforms() { | ||
| if ('ProvisionsAllDevices' in this.message) | ||
| return ['darwin']; | ||
| // Developer ID | ||
| else if (this.type === 'distribution') | ||
| return ['mas']; | ||
| // Mac App Store | ||
| else | ||
| return ['darwin', 'mas']; // Mac App Development | ||
| } | ||
| get type() { | ||
| if ('ProvisionedDevices' in this.message) | ||
| return 'development'; | ||
| // Mac App Development | ||
| else | ||
| return 'distribution'; // Developer ID or Mac App Store | ||
| } | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| export async function getProvisioningProfile(filePath, keychain = null) { | ||
| const securityArgs = [ | ||
| 'cms', | ||
| '-D', // Decode a CMS message | ||
| '-i', | ||
| filePath, // Use infile as source of data | ||
| ]; | ||
| if (keychain) { | ||
| securityArgs.push('-k', keychain); | ||
| } | ||
| const result = await execFileAsync('security', securityArgs); | ||
| const provisioningProfile = new ProvisioningProfile(filePath, plist.parse(result)); | ||
| debugLog('Provisioning profile:', '\n', '> Name:', provisioningProfile.name, '\n', '> Platforms:', provisioningProfile.platforms, '\n', '> Type:', provisioningProfile.type, '\n', '> Path:', provisioningProfile.filePath, '\n', '> Message:', provisioningProfile.message); | ||
| return provisioningProfile; | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| export async function findProvisioningProfiles(opts) { | ||
| const cwd = process.cwd(); | ||
| const children = await util.promisify(fs.readdir)(cwd); | ||
| const foundProfiles = compactFlattenedList(await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(cwd, child); | ||
| const stat = await fs.promises.stat(filePath); | ||
| if (stat.isFile() && path.extname(filePath) === '.provisionprofile') { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| }))); | ||
| return compactFlattenedList(await Promise.all(foundProfiles.map(async (filePath) => { | ||
| const profile = await getProvisioningProfile(filePath); | ||
| if (profile.platforms.indexOf(opts.platform) >= 0 && profile.type === opts.type) { | ||
| return profile; | ||
| } | ||
| debugWarn('Provisioning profile above ignored, not for ' + opts.platform + ' ' + opts.type + '.'); | ||
| return null; | ||
| }))); | ||
| } | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| export async function preEmbedProvisioningProfile(opts, profile) { | ||
| async function embedProvisioningProfile(profile) { | ||
| debugLog('Looking for existing provisioning profile...'); | ||
| const embeddedFilePath = path.join(getAppContentsPath(opts), 'embedded.provisionprofile'); | ||
| if (fs.existsSync(embeddedFilePath)) { | ||
| debugLog('Found embedded provisioning profile:', '\n', '* Please manually remove the existing file if not wanted.', '\n', '* Current file at:', embeddedFilePath); | ||
| } | ||
| else { | ||
| debugLog('Embedding provisioning profile...'); | ||
| await util.promisify(fs.copyFile)(profile.filePath, embeddedFilePath); | ||
| } | ||
| } | ||
| if (profile) { | ||
| // User input provisioning profile | ||
| return await embedProvisioningProfile(profile); | ||
| } | ||
| else { | ||
| // Discover provisioning profile | ||
| debugLog('No `provisioning-profile` passed in arguments, will find in current working directory and in user library...'); | ||
| const profiles = await findProvisioningProfiles(opts); | ||
| if (profiles.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (profiles.length > 1) { | ||
| debugLog('Multiple provisioning profiles found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 provisioning profile.'); | ||
| } | ||
| await embedProvisioningProfile(profiles[0]); | ||
| } | ||
| else { | ||
| // No provisioning profile found | ||
| debugLog('No provisioning profile found, will not embed profile in app contents.'); | ||
| } | ||
| } | ||
| } | ||
| //# sourceMappingURL=util-provisioning-profiles.js.map |
| {"version":3,"file":"util-provisioning-profiles.js","sourceRoot":"","sources":["../src/util-provisioning-profiles.ts"],"names":[],"mappings":"AAAA,OAAO,IAAI,MAAM,WAAW,CAAC;AAC7B,OAAO,IAAI,MAAM,WAAW,CAAC;AAE7B,OAAO,EAAE,MAAM,aAAa,CAAC;AAC7B,OAAO,KAAK,MAAM,OAAO,CAAC;AAG1B,OAAO,EACL,QAAQ,EACR,SAAS,EACT,kBAAkB,EAClB,oBAAoB,EACpB,aAAa,GACd,MAAM,WAAW,CAAC;AAEnB,MAAM,OAAO,mBAAmB;IAErB;IACA;IAFT,YACS,QAAgB,EAChB,OAAY;QADZ,aAAQ,GAAR,QAAQ,CAAQ;QAChB,YAAO,GAAP,OAAO,CAAK;IAClB,CAAC;IAEJ,IAAI,IAAI;QACN,OAAO,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC;IAC3B,CAAC;IAED,IAAI,SAAS;QACX,IAAI,sBAAsB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,CAAC,QAAQ,CAAC,CAAC;QAC9D,eAAe;aACV,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc;YAAE,OAAO,CAAC,KAAK,CAAC,CAAC;QACtD,gBAAgB;;YACX,OAAO,CAAC,QAAQ,EAAE,KAAK,CAAC,CAAC,CAAC,sBAAsB;IACvD,CAAC;IAED,IAAI,IAAI;QACN,IAAI,oBAAoB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,aAAa,CAAC;QAC/D,sBAAsB;;YACjB,OAAO,cAAc,CAAC,CAAC,gCAAgC;IAC9D,CAAC;CACF;AAED;;;;;;GAMG;AACH,MAAM,CAAC,KAAK,UAAU,sBAAsB,CAAC,QAAgB,EAAE,WAA0B,IAAI;IAC3F,MAAM,YAAY,GAAG;QACnB,KAAK;QACL,IAAI,EAAE,uBAAuB;QAC7B,IAAI;QACJ,QAAQ,EAAE,+BAA+B;KAC1C,CAAC;IAEF,IAAI,QAAQ,EAAE,CAAC;QACb,YAAY,CAAC,IAAI,CAAC,IAAI,EAAE,QAAQ,CAAC,CAAC;IACpC,CAAC;IAED,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE,YAAY,CAAC,CAAC;IAC7D,MAAM,mBAAmB,GAAG,IAAI,mBAAmB,CAAC,QAAQ,EAAE,KAAK,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC,CAAC;IACnF,QAAQ,CACN,uBAAuB,EACvB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,cAAc,EACd,mBAAmB,CAAC,SAAS,EAC7B,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,QAAQ,EAC5B,IAAI,EACJ,YAAY,EACZ,mBAAmB,CAAC,OAAO,CAC5B,CAAC;IACF,OAAO,mBAAmB,CAAC;AAC7B,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,wBAAwB,CAAC,IAA0B;IACvE,MAAM,GAAG,GAAG,OAAO,CAAC,GAAG,EAAE,CAAC;IAC1B,MAAM,QAAQ,GAAG,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,OAAO,CAAC,CAAC,GAAG,CAAC,CAAC;IACvD,MAAM,aAAa,GAAG,oBAAoB,CACxC,MAAM,OAAO,CAAC,GAAG,CACf,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;QAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,GAAG,EAAE,KAAK,CAAC,CAAC;QAC1C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;QAC9C,IAAI,IAAI,CAAC,MAAM,EAAE,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,KAAK,mBAAmB,EAAE,CAAC;YACpE,OAAO,QAAQ,CAAC;QAClB,CAAC;QACD,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;IAEF,OAAO,oBAAoB,CACzB,MAAM,OAAO,CAAC,GAAG,CACf,aAAa,CAAC,GAAG,CAAC,KAAK,EAAE,QAAQ,EAAE,EAAE;QACnC,MAAM,OAAO,GAAG,MAAM,sBAAsB,CAAC,QAAQ,CAAC,CAAC;QACvD,IAAI,OAAO,CAAC,SAAS,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,IAAI,OAAO,CAAC,IAAI,KAAK,IAAI,CAAC,IAAI,EAAE,CAAC;YAChF,OAAO,OAAO,CAAC;QACjB,CAAC;QACD,SAAS,CACP,8CAA8C,GAAG,IAAI,CAAC,QAAQ,GAAG,GAAG,GAAG,IAAI,CAAC,IAAI,GAAG,GAAG,CACvF,CAAC;QACF,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;AACJ,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,2BAA2B,CAC/C,IAA0B,EAC1B,OAAmC;IAEnC,KAAK,UAAU,wBAAwB,CAAC,OAA4B;QAClE,QAAQ,CAAC,8CAA8C,CAAC,CAAC;QACzD,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,2BAA2B,CAAC,CAAC;QAE1F,IAAI,EAAE,CAAC,UAAU,CAAC,gBAAgB,CAAC,EAAE,CAAC;YACpC,QAAQ,CACN,sCAAsC,EACtC,IAAI,EACJ,2DAA2D,EAC3D,IAAI,EACJ,oBAAoB,EACpB,gBAAgB,CACjB,CAAC;QACJ,CAAC;aAAM,CAAC;YACN,QAAQ,CAAC,mCAAmC,CAAC,CAAC;YAC9C,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,QAAQ,CAAC,CAAC,OAAO,CAAC,QAAQ,EAAE,gBAAgB,CAAC,CAAC;QACxE,CAAC;IACH,CAAC;IAED,IAAI,OAAO,EAAE,CAAC;QACZ,kCAAkC;QAClC,OAAO,MAAM,wBAAwB,CAAC,OAAO,CAAC,CAAC;IACjD,CAAC;SAAM,CAAC;QACN,gCAAgC;QAChC,QAAQ,CACN,8GAA8G,CAC/G,CAAC;QACF,MAAM,QAAQ,GAAG,MAAM,wBAAwB,CAAC,IAAI,CAAC,CAAC;QACtD,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;YACxB,gCAAgC;YAChC,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;gBACxB,QAAQ,CAAC,sEAAsE,CAAC,CAAC;YACnF,CAAC;iBAAM,CAAC;gBACN,QAAQ,CAAC,+BAA+B,CAAC,CAAC;YAC5C,CAAC;YACD,MAAM,wBAAwB,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,CAAC;QAC9C,CAAC;aAAM,CAAC;YACN,gCAAgC;YAChC,QAAQ,CAAC,wEAAwE,CAAC,CAAC;QACrF,CAAC;IACH,CAAC;AACH,CAAC"} |
| /// <reference types="node" resolution-mode="require"/> | ||
| import child from 'node:child_process'; | ||
| import debug from 'debug'; | ||
| import type { BaseSignOptions, ElectronMacPlatform } from './types.js'; | ||
| export declare const debugLog: debug.Debugger; | ||
| export declare const debugWarn: debug.Debugger; | ||
| export declare function execFileAsync(file: string, args: string[], options?: child.ExecFileOptions): Promise<string>; | ||
| type DeepListItem<T> = null | T | DeepListItem<T>[]; | ||
| type DeepList<T> = DeepListItem<T>[]; | ||
| export declare function compactFlattenedList<T>(list: DeepList<T>): T[]; | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| export declare function getAppContentsPath(opts: BaseSignOptions): string; | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| export declare function getAppFrameworksPath(opts: BaseSignOptions): string; | ||
| export declare function detectElectronPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| export declare function validateOptsApp(opts: BaseSignOptions): Promise<void>; | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| export declare function validateOptsPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| export declare function walk(dirPath: string): Promise<string[]>; | ||
| export {}; |
+147
| import child from 'node:child_process'; | ||
| import path from 'node:path'; | ||
| import util from 'node:util'; | ||
| import fs from 'graceful-fs'; | ||
| import { isBinaryFile } from 'isbinaryfile'; | ||
| import debug from 'debug'; | ||
| export const debugLog = debug('electron-osx-sign'); | ||
| debugLog.log = console.log.bind(console); | ||
| export const debugWarn = debug('electron-osx-sign:warn'); | ||
| debugWarn.log = console.warn.bind(console); | ||
| const removePassword = function (input) { | ||
| return input.replace(/(-P |pass:|\/p|-pass )([^ ]+)/, function (_, p1) { | ||
| return `${p1}***`; | ||
| }); | ||
| }; | ||
| export async function execFileAsync(file, args, options = {}) { | ||
| if (debugLog.enabled) { | ||
| debugLog('Executing...', file, args && Array.isArray(args) ? removePassword(args.join(' ')) : ''); | ||
| } | ||
| return new Promise(function (resolve, reject) { | ||
| child.execFile(file, args, options, function (err, stdout, stderr) { | ||
| if (err) { | ||
| debugLog('Error executing file:', '\n', '> Stdout:', stdout, '\n', '> Stderr:', stderr); | ||
| reject(err); | ||
| return; | ||
| } | ||
| resolve(stdout); | ||
| }); | ||
| }); | ||
| } | ||
| export function compactFlattenedList(list) { | ||
| const result = []; | ||
| function populateResult(list) { | ||
| if (!Array.isArray(list)) { | ||
| if (list) | ||
| result.push(list); | ||
| } | ||
| else if (list.length > 0) { | ||
| for (const item of list) | ||
| if (item) | ||
| populateResult(item); | ||
| } | ||
| } | ||
| populateResult(list); | ||
| return result; | ||
| } | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| export function getAppContentsPath(opts) { | ||
| return path.join(opts.app, 'Contents'); | ||
| } | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| export function getAppFrameworksPath(opts) { | ||
| return path.join(getAppContentsPath(opts), 'Frameworks'); | ||
| } | ||
| export async function detectElectronPlatform(opts) { | ||
| const appFrameworksPath = getAppFrameworksPath(opts); | ||
| if (fs.existsSync(path.resolve(appFrameworksPath, 'Squirrel.framework'))) { | ||
| return 'darwin'; | ||
| } | ||
| else { | ||
| return 'mas'; | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise resolving the file path if file binary. | ||
| */ | ||
| async function getFilePathIfBinary(filePath) { | ||
| if (await isBinaryFile(filePath)) { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| } | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| export async function validateOptsApp(opts) { | ||
| if (!opts.app) { | ||
| throw new Error('Path to application must be specified.'); | ||
| } | ||
| if (path.extname(opts.app) !== '.app') { | ||
| throw new Error('Extension of application must be `.app`.'); | ||
| } | ||
| if (!fs.existsSync(opts.app)) { | ||
| throw new Error(`Application at path "${opts.app}" could not be found`); | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| export async function validateOptsPlatform(opts) { | ||
| if (opts.platform) { | ||
| if (opts.platform === 'mas' || opts.platform === 'darwin') { | ||
| return opts.platform; | ||
| } | ||
| else { | ||
| debugWarn('`platform` passed in arguments not supported, checking Electron platform...'); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `platform` passed in arguments, checking Electron platform...'); | ||
| } | ||
| return await detectElectronPlatform(opts); | ||
| } | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| export async function walk(dirPath) { | ||
| debugLog('Walking... ' + dirPath); | ||
| async function _walkAsync(dirPath) { | ||
| const children = await util.promisify(fs.readdir)(dirPath); | ||
| return await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(dirPath, child); | ||
| const stat = await fs.promises.stat(filePath); | ||
| if (stat.isFile()) { | ||
| switch (path.extname(filePath)) { | ||
| case '.cstemp': // Temporary file generated from past codesign | ||
| debugLog('Removing... ' + filePath); | ||
| await fs.promises.rm(filePath, { recursive: true, force: true }); | ||
| return null; | ||
| default: | ||
| return await getFilePathIfBinary(filePath); | ||
| } | ||
| } | ||
| else if (stat.isDirectory() && !stat.isSymbolicLink()) { | ||
| const walkResult = await _walkAsync(filePath); | ||
| switch (path.extname(filePath)) { | ||
| case '.app': // Application | ||
| case '.framework': // Framework | ||
| walkResult.push(filePath); | ||
| } | ||
| return walkResult; | ||
| } | ||
| return null; | ||
| })); | ||
| } | ||
| const allPaths = await _walkAsync(dirPath); | ||
| return compactFlattenedList(allPaths); | ||
| } | ||
| //# sourceMappingURL=util.js.map |
| {"version":3,"file":"util.js","sourceRoot":"","sources":["../src/util.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,MAAM,oBAAoB,CAAC;AACvC,OAAO,IAAI,MAAM,WAAW,CAAC;AAC7B,OAAO,IAAI,MAAM,WAAW,CAAC;AAE7B,OAAO,EAAE,MAAM,aAAa,CAAC;AAC7B,OAAO,EAAE,YAAY,EAAE,MAAM,cAAc,CAAC;AAE5C,OAAO,KAAK,MAAM,OAAO,CAAC;AAG1B,MAAM,CAAC,MAAM,QAAQ,GAAG,KAAK,CAAC,mBAAmB,CAAC,CAAC;AACnD,QAAQ,CAAC,GAAG,GAAG,OAAO,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAEzC,MAAM,CAAC,MAAM,SAAS,GAAG,KAAK,CAAC,wBAAwB,CAAC,CAAC;AACzD,SAAS,CAAC,GAAG,GAAG,OAAO,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAE3C,MAAM,cAAc,GAAG,UAAU,KAAa;IAC5C,OAAO,KAAK,CAAC,OAAO,CAAC,+BAA+B,EAAE,UAAU,CAAC,EAAE,EAAE;QACnE,OAAO,GAAG,EAAE,KAAK,CAAC;IACpB,CAAC,CAAC,CAAC;AACL,CAAC,CAAC;AAEF,MAAM,CAAC,KAAK,UAAU,aAAa,CACjC,IAAY,EACZ,IAAc,EACd,UAAiC,EAAE;IAEnC,IAAI,QAAQ,CAAC,OAAO,EAAE,CAAC;QACrB,QAAQ,CACN,cAAc,EACd,IAAI,EACJ,IAAI,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,CAAC,CAAC,CAAC,cAAc,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC,CAAC,CAAC,EAAE,CAClE,CAAC;IACJ,CAAC;IAED,OAAO,IAAI,OAAO,CAAC,UAAU,OAAO,EAAE,MAAM;QAC1C,KAAK,CAAC,QAAQ,CAAC,IAAI,EAAE,IAAI,EAAE,OAAO,EAAE,UAAU,GAAG,EAAE,MAAM,EAAE,MAAM;YAC/D,IAAI,GAAG,EAAE,CAAC;gBACR,QAAQ,CAAC,uBAAuB,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,CAAC,CAAC;gBACxF,MAAM,CAAC,GAAG,CAAC,CAAC;gBACZ,OAAO;YACT,CAAC;YACD,OAAO,CAAC,MAAM,CAAC,CAAC;QAClB,CAAC,CAAC,CAAC;IACL,CAAC,CAAC,CAAC;AACL,CAAC;AAKD,MAAM,UAAU,oBAAoB,CAAI,IAAiB;IACvD,MAAM,MAAM,GAAQ,EAAE,CAAC;IAEvB,SAAS,cAAc,CAAC,IAAqB;QAC3C,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,EAAE,CAAC;YACzB,IAAI,IAAI;gBAAE,MAAM,CAAC,IAAI,CAAC,IAAI,CAAC,CAAC;QAC9B,CAAC;aAAM,IAAI,IAAI,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;YAC3B,KAAK,MAAM,IAAI,IAAI,IAAI;gBAAE,IAAI,IAAI;oBAAE,cAAc,CAAC,IAAI,CAAC,CAAC;QAC1D,CAAC;IACH,CAAC;IAED,cAAc,CAAC,IAAI,CAAC,CAAC;IACrB,OAAO,MAAM,CAAC;AAChB,CAAC;AAED;;GAEG;AACH,MAAM,UAAU,kBAAkB,CAAC,IAAqB;IACtD,OAAO,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,UAAU,CAAC,CAAC;AACzC,CAAC;AAED;;GAEG;AACH,MAAM,UAAU,oBAAoB,CAAC,IAAqB;IACxD,OAAO,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;AAC3D,CAAC;AAED,MAAM,CAAC,KAAK,UAAU,sBAAsB,CAAC,IAAqB;IAChE,MAAM,iBAAiB,GAAG,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACrD,IAAI,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,OAAO,CAAC,iBAAiB,EAAE,oBAAoB,CAAC,CAAC,EAAE,CAAC;QACzE,OAAO,QAAQ,CAAC;IAClB,CAAC;SAAM,CAAC;QACN,OAAO,KAAK,CAAC;IACf,CAAC;AACH,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,mBAAmB,CAAC,QAAgB;IACjD,IAAI,MAAM,YAAY,CAAC,QAAQ,CAAC,EAAE,CAAC;QACjC,OAAO,QAAQ,CAAC;IAClB,CAAC;IACD,OAAO,IAAI,CAAC;AACd,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,eAAe,CAAC,IAAqB;IACzD,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,CAAC;QACd,MAAM,IAAI,KAAK,CAAC,wCAAwC,CAAC,CAAC;IAC5D,CAAC;IACD,IAAI,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE,CAAC;QACtC,MAAM,IAAI,KAAK,CAAC,0CAA0C,CAAC,CAAC;IAC9D,CAAC;IACD,IAAI,CAAC,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,CAAC;QAC7B,MAAM,IAAI,KAAK,CAAC,wBAAwB,IAAI,CAAC,GAAG,sBAAsB,CAAC,CAAC;IAC1E,CAAC;AACH,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,oBAAoB,CAAC,IAAqB;IAC9D,IAAI,IAAI,CAAC,QAAQ,EAAE,CAAC;QAClB,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,IAAI,IAAI,CAAC,QAAQ,KAAK,QAAQ,EAAE,CAAC;YAC1D,OAAO,IAAI,CAAC,QAAQ,CAAC;QACvB,CAAC;aAAM,CAAC;YACN,SAAS,CAAC,6EAA6E,CAAC,CAAC;QAC3F,CAAC;IACH,CAAC;SAAM,CAAC;QACN,SAAS,CAAC,kEAAkE,CAAC,CAAC;IAChF,CAAC;IAED,OAAO,MAAM,sBAAsB,CAAC,IAAI,CAAC,CAAC;AAC5C,CAAC;AAED;;;;;;GAMG;AACH,MAAM,CAAC,KAAK,UAAU,IAAI,CAAC,OAAe;IACxC,QAAQ,CAAC,aAAa,GAAG,OAAO,CAAC,CAAC;IAElC,KAAK,UAAU,UAAU,CAAC,OAAe;QACvC,MAAM,QAAQ,GAAG,MAAM,IAAI,CAAC,SAAS,CAAC,EAAE,CAAC,OAAO,CAAC,CAAC,OAAO,CAAC,CAAC;QAC3D,OAAO,MAAM,OAAO,CAAC,GAAG,CACtB,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;YAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,OAAO,EAAE,KAAK,CAAC,CAAC;YAE9C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;YAC9C,IAAI,IAAI,CAAC,MAAM,EAAE,EAAE,CAAC;gBAClB,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE,CAAC;oBAC/B,KAAK,SAAS,EAAE,8CAA8C;wBAC5D,QAAQ,CAAC,cAAc,GAAG,QAAQ,CAAC,CAAC;wBACpC,MAAM,EAAE,CAAC,QAAQ,CAAC,EAAE,CAAC,QAAQ,EAAE,EAAE,SAAS,EAAE,IAAI,EAAE,KAAK,EAAE,IAAI,EAAE,CAAC,CAAC;wBACjE,OAAO,IAAI,CAAC;oBACd;wBACE,OAAO,MAAM,mBAAmB,CAAC,QAAQ,CAAC,CAAC;gBAC/C,CAAC;YACH,CAAC;iBAAM,IAAI,IAAI,CAAC,WAAW,EAAE,IAAI,CAAC,IAAI,CAAC,cAAc,EAAE,EAAE,CAAC;gBACxD,MAAM,UAAU,GAAG,MAAM,UAAU,CAAC,QAAQ,CAAC,CAAC;gBAC9C,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE,CAAC;oBAC/B,KAAK,MAAM,CAAC,CAAC,cAAc;oBAC3B,KAAK,YAAY,EAAE,YAAY;wBAC7B,UAAU,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;gBAC9B,CAAC;gBACD,OAAO,UAAU,CAAC;YACpB,CAAC;YACD,OAAO,IAAI,CAAC;QACd,CAAC,CAAC,CACH,CAAC;IACJ,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,UAAU,CAAC,OAAO,CAAC,CAAC;IAC3C,OAAO,oBAAoB,CAAC,QAAQ,CAAC,CAAC;AACxC,CAAC"} |
+37
-37
| { | ||
| "name": "@electron/osx-sign", | ||
| "version": "1.3.3", | ||
| "version": "2.0.0", | ||
| "description": "Codesign Electron macOS apps", | ||
| "main": "dist/cjs/index.js", | ||
| "module": "dist/esm/index.js", | ||
| "type": "module", | ||
| "exports": "./dist/index.js", | ||
| "files": [ | ||
@@ -15,4 +15,4 @@ "dist", | ||
| "bin": { | ||
| "electron-osx-flat": "bin/electron-osx-flat.js", | ||
| "electron-osx-sign": "bin/electron-osx-sign.js" | ||
| "electron-osx-flat": "bin/electron-osx-flat.mjs", | ||
| "electron-osx-sign": "bin/electron-osx-sign.mjs" | ||
| }, | ||
@@ -33,21 +33,21 @@ "repository": { | ||
| "dependencies": { | ||
| "compare-version": "^0.1.2", | ||
| "@types/graceful-fs": "^4.1.9", | ||
| "debug": "^4.3.4", | ||
| "fs-extra": "^10.0.0", | ||
| "graceful-fs": "^4.2.11", | ||
| "isbinaryfile": "^4.0.8", | ||
| "minimist": "^1.2.6", | ||
| "plist": "^3.0.5" | ||
| "plist": "^3.0.5", | ||
| "semver": "^7.7.1" | ||
| }, | ||
| "devDependencies": { | ||
| "@electron/get": "^2.0.2", | ||
| "@types/compare-version": "^0.1.31", | ||
| "@electron/get": "^4.0.0", | ||
| "@tsconfig/node22": "^22.0.0", | ||
| "@types/debug": "^4.1.7", | ||
| "@types/fs-extra": "^9.0.13", | ||
| "@types/node": "^16.11.6", | ||
| "@types/node": "~22.10.7", | ||
| "@types/plist": "^3.0.2", | ||
| "@typescript-eslint/eslint-plugin": "^5.45.0", | ||
| "@typescript-eslint/parser": "^5.45.0", | ||
| "eslint": "^8.29.0", | ||
| "eslint-config-eslint": "^7.0.0", | ||
| "eslint-config-standard": "^17.0.0", | ||
| "@types/semver": "^7.5.8", | ||
| "@typescript-eslint/eslint-plugin": "^8.27.0", | ||
| "@typescript-eslint/parser": "^8.27.0", | ||
| "eslint": "^8.57.0", | ||
| "eslint-config-prettier": "^10.1.1", | ||
| "eslint-import-resolver-typescript": "^4.2.2", | ||
| "eslint-plugin-import": "^2.26.0", | ||
@@ -57,27 +57,27 @@ "eslint-plugin-node": "^11.1.0", | ||
| "extract-zip": "^2.0.1", | ||
| "mkdirp": "^1.0.4", | ||
| "rimraf": "^3.0.2", | ||
| "run-series": "^1.1.9", | ||
| "run-waterfall": "^1.1.7", | ||
| "standard": "^17.0.0", | ||
| "tape": "^4.7.1", | ||
| "husky": "^9.1.7", | ||
| "prettier": "^3.5.3", | ||
| "typedoc": "~0.25.13", | ||
| "typescript": "^4.9.3" | ||
| "typescript": "~5.4.5", | ||
| "vitest": "^3.0.9" | ||
| }, | ||
| "scripts": { | ||
| "build": "tsc && tsc -p tsconfig.esm.json", | ||
| "docs:build": "npx typedoc", | ||
| "lint": "eslint --ext .ts,.js src bin test", | ||
| "pretest": "rimraf test/work", | ||
| "test": "yarn lint && tape test", | ||
| "prepublishOnly": "yarn build" | ||
| "build": "tsc", | ||
| "build:docs": "npx typedoc", | ||
| "lint": "prettier --check **/*.{ts,mjs} && eslint --ext .ts,.mjs src bin spec", | ||
| "pretest": "node -e 'fs.rmSync(\"spec/work\", { recursive: true, force: true })'", | ||
| "test": "vitest run", | ||
| "prepublishOnly": "yarn build", | ||
| "prepare": "husky" | ||
| }, | ||
| "standard": { | ||
| "ignore": [ | ||
| "test/work" | ||
| "engines": { | ||
| "node": ">=22.12.0" | ||
| }, | ||
| "lint-staged": { | ||
| "*.{json}": "prettier --write", | ||
| "*.{js,ts}": [ | ||
| "prettier --write", | ||
| "eslint --fix" | ||
| ] | ||
| }, | ||
| "engines": { | ||
| "node": ">=12.0.0" | ||
| } | ||
| } |
+13
-60
@@ -72,7 +72,7 @@ # @electron/osx-sign [![npm][npm_img]][npm_url] [![Test][gha_img]][gha_url] | ||
| ```javascript | ||
| const { signAsync } = require('@electron/osx-sign') | ||
| import { sign } = from '@electron/osx-sign' | ||
| const opts = { | ||
| app: 'path/to/my.app' | ||
| }; | ||
| signAsync(opts) | ||
| sign(opts) | ||
| .then(function () { | ||
@@ -86,3 +86,3 @@ // Application signed | ||
| The only mandatory option for `signAsync` is a path to your `.app` package. | ||
| The only mandatory option for `sign` is a path to your `.app` package. | ||
| Configuration for most Electron apps should work out of the box. | ||
@@ -96,3 +96,3 @@ For full configuration options, see the [API documentation]. | ||
| ```javascript | ||
| const { signAsync } = require('@electron/osx-sign') | ||
| import { sign } from '@electron/osx-sign' | ||
| const opts = { | ||
@@ -106,3 +106,3 @@ app: 'path/to/my.app', | ||
| }; | ||
| signAsync(opts) | ||
| sign(opts) | ||
| .then(function () { | ||
@@ -141,3 +141,3 @@ // Application signed | ||
| ```javascript | ||
| signAsync({ | ||
| sign({ | ||
| app: 'path/to/my.app', | ||
@@ -168,3 +168,3 @@ optionsForFile: (filePath) => { | ||
| ```javascript | ||
| signAsync({ | ||
| sign({ | ||
| app: 'path/to/my.app', | ||
@@ -188,4 +188,4 @@ version: '0.34.0', | ||
| ```javascript | ||
| const { flatAsync } = require('@electron/osx-sign') | ||
| flatAsync({ | ||
| import { flat } = '@electron/osx-sign' | ||
| flat({ | ||
| app: 'path/to/my.app' | ||
@@ -201,3 +201,3 @@ }) | ||
| The only mandatory option for `flatAsync` is a path to your `.app` package. | ||
| The only mandatory option for `flat` is a path to your `.app` package. | ||
| For full configuration options, see the [API documentation]. | ||
@@ -233,54 +233,7 @@ | ||
| The project's configured to run automated tests on CircleCI. | ||
| The project's configured to run automated tests on GitHub Actions. | ||
| If you wish to manually test the module, first comment out `opts.identity` in `test/basic.js` to enable | ||
| auto discovery. Then run the command `npm test` from the dev directory. | ||
| If you wish to manually test the module, you need to first generate a self-signed certificate | ||
| via the `spec/ci/generate-identity.sh` script. | ||
| When this command is run for the first time: `@electron/get` will download macOS Electron releases defined | ||
| in `test/config.json`, and save to `~/.electron/`, which might take up less than 1GB of disk space. | ||
| A successful testing should look something like: | ||
| ``` | ||
| $ npm test | ||
| > electron-osx-sign@0.4.17 pretest electron-osx-sign | ||
| > rimraf test/work | ||
| > electron-osx-sign@0.4.17 test electron-osx-sign | ||
| > standard && tape test | ||
| Calling @electron/get before running tests... | ||
| Running tests... | ||
| TAP version 13 | ||
| # setup | ||
| # defaults-test:v7.0.0-beta.3-darwin-x64 | ||
| ok 1 app signed | ||
| # defaults-test:v7.0.0-beta.3-mas-x64 | ||
| ok 2 app signed | ||
| # defaults-test:v6.0.3-darwin-x64 | ||
| ok 3 app signed | ||
| # defaults-test:v6.0.3-mas-x64 | ||
| ok 4 app signed | ||
| # defaults-test:v5.0.10-darwin-x64 | ||
| ok 5 app signed | ||
| # defaults-test:v5.0.10-mas-x64 | ||
| ok 6 app signed | ||
| # defaults-test:v4.2.9-darwin-x64 | ||
| ok 7 app signed | ||
| # defaults-test:v4.2.9-mas-x64 | ||
| ok 8 app signed | ||
| # defaults-test:v3.1.2-darwin-x64 | ||
| ok 9 app signed | ||
| # defaults-test:v3.1.2-mas-x64 | ||
| ok 10 app signed | ||
| # teardown | ||
| 1..10 | ||
| # tests 10 | ||
| # pass 10 | ||
| # ok | ||
| ``` | ||
| [Electron]: https://github.com/electron/electron | ||
@@ -287,0 +240,0 @@ [electron-osx-sign]: https://github.com/electron/osx-sign |
| #!/usr/bin/env node | ||
| const fs = require('fs'); | ||
| const path = require('path'); | ||
| const args = require('minimist')(process.argv.slice(2), { | ||
| boolean: [ | ||
| 'help' | ||
| ] | ||
| }); | ||
| const usage = fs.readFileSync(path.join(__dirname, 'electron-osx-flat-usage.txt')).toString(); | ||
| const flat = require('../').flat; | ||
| args.app = args._.shift(); | ||
| if (!args.app || args.help) { | ||
| console.log(usage); | ||
| process.exit(0); | ||
| } | ||
| // Remove excess arguments | ||
| delete args._; | ||
| delete args.help; | ||
| flat(args, function done (err) { | ||
| if (err) { | ||
| console.error('Flat failed:'); | ||
| if (err.message) console.error(err.message); | ||
| else if (err.stack) console.error(err.stack); | ||
| else console.log(err); | ||
| process.exit(1); | ||
| } | ||
| console.log('Application flattened, saved to:', args.pkg); | ||
| process.exit(0); | ||
| }); |
| #!/usr/bin/env node | ||
| const fs = require('fs'); | ||
| const path = require('path'); | ||
| const args = require('minimist')(process.argv.slice(2), { | ||
| string: [ | ||
| 'signature-flags' | ||
| ], | ||
| boolean: [ | ||
| 'help', | ||
| 'pre-auto-entitlements', | ||
| 'pre-embed-provisioning-profile', | ||
| 'hardened-runtime', | ||
| 'restrict' | ||
| ], | ||
| default: { | ||
| 'pre-auto-entitlements': true, | ||
| 'pre-embed-provisioning-profile': true | ||
| } | ||
| }); | ||
| const usage = fs.readFileSync(path.join(__dirname, 'electron-osx-sign-usage.txt')).toString(); | ||
| const sign = require('../').sign; | ||
| args.app = args._.shift(); | ||
| args.binaries = args._; | ||
| if (!args.app || args.help) { | ||
| console.log(usage); | ||
| process.exit(0); | ||
| } | ||
| // Remove excess arguments | ||
| delete args._; | ||
| delete args.help; | ||
| sign(args, function done (err) { | ||
| if (err) { | ||
| console.error('Sign failed:'); | ||
| if (err.message) console.error(err.message); | ||
| else if (err.stack) console.error(err.stack); | ||
| else console.log(err); | ||
| process.exit(1); | ||
| } | ||
| console.log('Application signed:', args.app); | ||
| process.exit(0); | ||
| }); |
| import { FlatOptions } from './types'; | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| export declare function buildPkg(_opts: FlatOptions): Promise<void>; | ||
| /** | ||
| * This function is exported with normal callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link flatAsync} method instead. | ||
| * @category Flat | ||
| */ | ||
| export declare const flat: (opts: FlatOptions, cb?: ((error?: Error) => void) | undefined) => void; |
-179
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { | ||
| Object.defineProperty(o, "default", { enumerable: true, value: v }); | ||
| }) : function(o, v) { | ||
| o["default"] = v; | ||
| }); | ||
| var __importStar = (this && this.__importStar) || function (mod) { | ||
| if (mod && mod.__esModule) return mod; | ||
| var result = {}; | ||
| if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k); | ||
| __setModuleDefault(result, mod); | ||
| return result; | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.flat = exports.buildPkg = void 0; | ||
| const path = __importStar(require("path")); | ||
| const util_1 = require("./util"); | ||
| const util_identities_1 = require("./util-identities"); | ||
| const pkgVersion = require('../../package.json').version; | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| * @function | ||
| * @param {Object} opts - Options. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| async function validateFlatOpts(opts) { | ||
| await (0, util_1.validateOptsApp)(opts); | ||
| let pkg = opts.pkg; | ||
| if (pkg) { | ||
| if (typeof pkg !== 'string') | ||
| throw new Error('`pkg` must be a string.'); | ||
| if (path.extname(pkg) !== '.pkg') { | ||
| throw new Error('Extension of output package must be `.pkg`.'); | ||
| } | ||
| } | ||
| else { | ||
| (0, util_1.debugWarn)('No `pkg` passed in arguments, will fallback to default inferred from the given application.'); | ||
| pkg = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '.pkg'); | ||
| } | ||
| let install = opts.install; | ||
| if (install) { | ||
| if (typeof install !== 'string') { | ||
| return Promise.reject(new Error('`install` must be a string.')); | ||
| } | ||
| } | ||
| else { | ||
| (0, util_1.debugWarn)('No `install` passed in arguments, will fallback to default `/Applications`.'); | ||
| install = '/Applications'; | ||
| } | ||
| if (typeof opts.scripts === 'string' && opts.platform === 'mas') { | ||
| (0, util_1.debugWarn)('Mac App Store packages cannot have `scripts`, ignoring option.'); | ||
| } | ||
| return Object.assign(Object.assign({}, opts), { pkg, | ||
| install, platform: await (0, util_1.validateOptsPlatform)(opts) }); | ||
| } | ||
| /** | ||
| * This function returns a promise flattening the application. | ||
| * @param opts - Options for building the .pkg archive | ||
| */ | ||
| async function buildApplicationPkg(opts, identity) { | ||
| if (opts.platform === 'mas') { | ||
| const args = ['--component', opts.app, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| (0, util_1.debugLog)('Flattening Mac App Store package... ' + opts.app); | ||
| await (0, util_1.execFileAsync)('productbuild', args); | ||
| } | ||
| else { | ||
| const componentPkgPath = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '-component.pkg'); | ||
| const pkgbuildArgs = [ | ||
| '--install-location', | ||
| opts.install, | ||
| '--component', | ||
| opts.app, | ||
| componentPkgPath | ||
| ]; | ||
| if (opts.scripts) { | ||
| pkgbuildArgs.unshift('--scripts', opts.scripts); | ||
| } | ||
| (0, util_1.debugLog)('Building component package... ' + opts.app); | ||
| await (0, util_1.execFileAsync)('pkgbuild', pkgbuildArgs); | ||
| const args = ['--package', componentPkgPath, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| (0, util_1.debugLog)('Flattening OS X Installer package... ' + opts.app); | ||
| await (0, util_1.execFileAsync)('productbuild', args); | ||
| await (0, util_1.execFileAsync)('rm', [componentPkgPath]); | ||
| } | ||
| } | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| async function buildPkg(_opts) { | ||
| (0, util_1.debugLog)('@electron/osx-sign@%s', pkgVersion); | ||
| const validatedOptions = await validateFlatOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| if (validatedOptions.identity) { | ||
| (0, util_1.debugLog)('`identity` passed in arguments.'); | ||
| if (validatedOptions.identityValidation === false) { | ||
| // Do nothing | ||
| } | ||
| else { | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOptions.keychain || null, validatedOptions.identity); | ||
| } | ||
| } | ||
| else { | ||
| (0, util_1.debugWarn)('No `identity` passed in arguments...'); | ||
| if (validatedOptions.platform === 'mas') { | ||
| (0, util_1.debugLog)('Finding `3rd Party Mac Developer Installer` certificate for flattening app distribution in the Mac App Store...'); | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOptions.keychain || null, '3rd Party Mac Developer Installer:'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOptions.keychain || null, 'Developer ID Installer:'); | ||
| } | ||
| } | ||
| if (identities.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (identities.length > 1) { | ||
| (0, util_1.debugWarn)('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| (0, util_1.debugLog)('Flattening application...', '\n', '> Application:', validatedOptions.app, '\n', '> Package output:', validatedOptions.pkg, '\n', '> Install path:', validatedOptions.install, '\n', '> Identity:', validatedOptions.identity, '\n', '> Scripts:', validatedOptions.scripts); | ||
| await buildApplicationPkg(validatedOptions, identityInUse); | ||
| (0, util_1.debugLog)('Application flattened.'); | ||
| } | ||
| exports.buildPkg = buildPkg; | ||
| /** | ||
| * This function is exported with normal callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link flatAsync} method instead. | ||
| * @category Flat | ||
| */ | ||
| const flat = (opts, cb) => { | ||
| buildPkg(opts) | ||
| .then(() => { | ||
| (0, util_1.debugLog)('Application flattened, saved to: ' + opts.app); | ||
| if (cb) | ||
| cb(); | ||
| }) | ||
| .catch((err) => { | ||
| (0, util_1.debugLog)('Flat failed:'); | ||
| if (err.message) | ||
| (0, util_1.debugLog)(err.message); | ||
| else if (err.stack) | ||
| (0, util_1.debugLog)(err.stack); | ||
| else | ||
| (0, util_1.debugLog)(err); | ||
| if (cb) | ||
| cb(err); | ||
| }); | ||
| }; | ||
| exports.flat = flat; | ||
| //# sourceMappingURL=flat.js.map |
| {"version":3,"file":"flat.js","sourceRoot":"","sources":["../../src/flat.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;AAAA,2CAA6B;AAC7B,iCAAmG;AAEnG,uDAA6D;AAI7D,MAAM,UAAU,GAAG,OAAO,CAAC,oBAAoB,CAAC,CAAC,OAAiB,CAAC;AAEnE;;;;;GAKG;AACH,KAAK,UAAU,gBAAgB,CAAE,IAAiB;IAChD,MAAM,IAAA,sBAAe,EAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,GAAG,GAAG,IAAI,CAAC,GAAG,CAAC;IACnB,IAAI,GAAG,EAAE;QACP,IAAI,OAAO,GAAG,KAAK,QAAQ;YAAE,MAAM,IAAI,KAAK,CAAC,yBAAyB,CAAC,CAAC;QACxE,IAAI,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE;YAChC,MAAM,IAAI,KAAK,CAAC,6CAA6C,CAAC,CAAC;SAChE;KACF;SAAM;QACL,IAAA,gBAAS,EACP,6FAA6F,CAC9F,CAAC;QACF,GAAG,GAAG,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,MAAM,CAAC,CAAC;KACnF;IAED,IAAI,OAAO,GAAG,IAAI,CAAC,OAAO,CAAC;IAC3B,IAAI,OAAO,EAAE;QACX,IAAI,OAAO,OAAO,KAAK,QAAQ,EAAE;YAC/B,OAAO,OAAO,CAAC,MAAM,CAAC,IAAI,KAAK,CAAC,6BAA6B,CAAC,CAAC,CAAC;SACjE;KACF;SAAM;QACL,IAAA,gBAAS,EAAC,6EAA6E,CAAC,CAAC;QACzF,OAAO,GAAG,eAAe,CAAC;KAC3B;IAED,IAAI,OAAO,IAAI,CAAC,OAAO,KAAK,QAAQ,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE;QAC/D,IAAA,gBAAS,EAAC,gEAAgE,CAAC,CAAC;KAC7E;IAED,uCACK,IAAI,KACP,GAAG;QACH,OAAO,EACP,QAAQ,EAAE,MAAM,IAAA,2BAAoB,EAAC,IAAI,CAAC,IAC1C;AACJ,CAAC;AAED;;;GAGG;AACH,KAAK,UAAU,mBAAmB,CAAE,IAA0B,EAAE,QAAkB;IAChF,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE;QAC3B,MAAM,IAAI,GAAG,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QACxF,IAAI,IAAI,CAAC,QAAQ,EAAE;YACjB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;SAC3C;QAED,IAAA,eAAQ,EAAC,sCAAsC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC5D,MAAM,IAAA,oBAAa,EAAC,cAAc,EAAE,IAAI,CAAC,CAAC;KAC3C;SAAM;QACL,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAChC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EACtB,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,gBAAgB,CACnD,CAAC;QACF,MAAM,YAAY,GAAG;YACnB,oBAAoB;YACpB,IAAI,CAAC,OAAO;YACZ,aAAa;YACb,IAAI,CAAC,GAAG;YACR,gBAAgB;SACjB,CAAC;QACF,IAAI,IAAI,CAAC,OAAO,EAAE;YAChB,YAAY,CAAC,OAAO,CAAC,WAAW,EAAE,IAAI,CAAC,OAAO,CAAC,CAAC;SACjD;QACD,IAAA,eAAQ,EAAC,gCAAgC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QACtD,MAAM,IAAA,oBAAa,EAAC,UAAU,EAAE,YAAY,CAAC,CAAC;QAE9C,MAAM,IAAI,GAAG,CAAC,WAAW,EAAE,gBAAgB,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QAC9F,IAAI,IAAI,CAAC,QAAQ,EAAE;YACjB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;SAC3C;QAED,IAAA,eAAQ,EAAC,uCAAuC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC7D,MAAM,IAAA,oBAAa,EAAC,cAAc,EAAE,IAAI,CAAC,CAAC;QAC1C,MAAM,IAAA,oBAAa,EAAC,IAAI,EAAE,CAAC,gBAAgB,CAAC,CAAC,CAAC;KAC/C;AACH,CAAC;AAED;;;;;GAKG;AACI,KAAK,UAAU,QAAQ,CAAE,KAAkB;IAChD,IAAA,eAAQ,EAAC,uBAAuB,EAAE,UAAU,CAAC,CAAC;IAC9C,MAAM,gBAAgB,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACvD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,IAAI,gBAAgB,CAAC,QAAQ,EAAE;QAC7B,IAAA,eAAQ,EAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,gBAAgB,CAAC,kBAAkB,KAAK,KAAK,EAAE;YACjD,aAAa;SACd;aAAM;YACL,UAAU,GAAG,MAAM,IAAA,gCAAc,EAAC,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EAAE,gBAAgB,CAAC,QAAQ,CAAC,CAAC;SACjG;KACF;SAAM;QACL,IAAA,gBAAS,EAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,gBAAgB,CAAC,QAAQ,KAAK,KAAK,EAAE;YACvC,IAAA,eAAQ,EACN,iHAAiH,CAClH,CAAC;YACF,UAAU,GAAG,MAAM,IAAA,gCAAc,EAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,oCAAoC,CACrC,CAAC;SACH;aAAM;YACL,IAAA,eAAQ,EACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,IAAA,gCAAc,EAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,yBAAyB,CAC1B,CAAC;SACH;KACF;IAED,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;QACzB,gCAAgC;QAChC,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;YACzB,IAAA,gBAAS,EAAC,2DAA2D,CAAC,CAAC;SACxE;aAAM;YACL,IAAA,eAAQ,EAAC,mBAAmB,CAAC,CAAC;SAC/B;QACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;KAC/B;SAAM;QACL,oBAAoB;QACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;KACnD;IAED,IAAA,eAAQ,EACN,2BAA2B,EAC3B,IAAI,EACJ,gBAAgB,EAChB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,mBAAmB,EACnB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,iBAAiB,EACjB,gBAAgB,CAAC,OAAO,EACxB,IAAI,EACJ,aAAa,EACb,gBAAgB,CAAC,QAAQ,EACzB,IAAI,EACJ,YAAY,EACZ,gBAAgB,CAAC,OAAO,CACzB,CAAC;IACF,MAAM,mBAAmB,CAAC,gBAAgB,EAAE,aAAa,CAAC,CAAC;IAE3D,IAAA,eAAQ,EAAC,wBAAwB,CAAC,CAAC;AACrC,CAAC;AApED,4BAoEC;AAED;;;;;GAKG;AACI,MAAM,IAAI,GAAG,CAAC,IAAiB,EAAE,EAA4B,EAAE,EAAE;IACtE,QAAQ,CAAC,IAAI,CAAC;SACX,IAAI,CAAC,GAAG,EAAE;QACT,IAAA,eAAQ,EAAC,mCAAmC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QACzD,IAAI,EAAE;YAAE,EAAE,EAAE,CAAC;IACf,CAAC,CAAC;SACD,KAAK,CAAC,CAAC,GAAG,EAAE,EAAE;QACb,IAAA,eAAQ,EAAC,cAAc,CAAC,CAAC;QACzB,IAAI,GAAG,CAAC,OAAO;YAAE,IAAA,eAAQ,EAAC,GAAG,CAAC,OAAO,CAAC,CAAC;aAClC,IAAI,GAAG,CAAC,KAAK;YAAE,IAAA,eAAQ,EAAC,GAAG,CAAC,KAAK,CAAC,CAAC;;YACnC,IAAA,eAAQ,EAAC,GAAG,CAAC,CAAC;QACnB,IAAI,EAAE;YAAE,EAAE,CAAC,GAAG,CAAC,CAAC;IAClB,CAAC,CAAC,CAAC;AACP,CAAC,CAAC;AAbW,QAAA,IAAI,QAaf"} |
| import { sign, signApp } from './sign'; | ||
| import { flat, buildPkg } from './flat'; | ||
| import { walkAsync } from './util'; | ||
| export { sign, flat, signApp as signAsync, signApp, buildPkg as flatAsync, buildPkg, walkAsync }; | ||
| export * from './types'; |
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __exportStar = (this && this.__exportStar) || function(m, exports) { | ||
| for (var p in m) if (p !== "default" && !Object.prototype.hasOwnProperty.call(exports, p)) __createBinding(exports, m, p); | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.walkAsync = exports.buildPkg = exports.flatAsync = exports.signApp = exports.signAsync = exports.flat = exports.sign = void 0; | ||
| const sign_1 = require("./sign"); | ||
| Object.defineProperty(exports, "sign", { enumerable: true, get: function () { return sign_1.sign; } }); | ||
| Object.defineProperty(exports, "signAsync", { enumerable: true, get: function () { return sign_1.signApp; } }); | ||
| Object.defineProperty(exports, "signApp", { enumerable: true, get: function () { return sign_1.signApp; } }); | ||
| const flat_1 = require("./flat"); | ||
| Object.defineProperty(exports, "flat", { enumerable: true, get: function () { return flat_1.flat; } }); | ||
| Object.defineProperty(exports, "flatAsync", { enumerable: true, get: function () { return flat_1.buildPkg; } }); | ||
| Object.defineProperty(exports, "buildPkg", { enumerable: true, get: function () { return flat_1.buildPkg; } }); | ||
| const util_1 = require("./util"); | ||
| Object.defineProperty(exports, "walkAsync", { enumerable: true, get: function () { return util_1.walkAsync; } }); | ||
| // TODO: Remove and leave only proper named exports, but for non-breaking change reasons | ||
| // we need to keep this weirdness for now | ||
| module.exports = sign_1.sign; | ||
| module.exports.sign = sign_1.sign; | ||
| module.exports.signAsync = sign_1.signApp; | ||
| module.exports.signApp = sign_1.signApp; | ||
| module.exports.flat = flat_1.flat; | ||
| module.exports.flatAsync = flat_1.buildPkg; | ||
| module.exports.buildPkg = flat_1.buildPkg; | ||
| module.exports.walkAsync = util_1.walkAsync; | ||
| __exportStar(require("./types"), exports); | ||
| //# sourceMappingURL=index.js.map |
| {"version":3,"file":"index.js","sourceRoot":"","sources":["../../src/index.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;AAAA,iCAAuC;AAe9B,qFAfA,WAAI,OAeA;AAAmB,0FAfjB,cAAO,OAemB;AAAE,wFAf5B,cAAO,OAe4B;AAdlD,iCAAwC;AAczB,qFAdN,WAAI,OAcM;AAA6C,0FAdjD,eAAQ,OAckD;AAAE,yFAd5D,eAAQ,OAc4D;AAbnF,iCAAmC;AAakD,0FAb5E,gBAAS,OAa4E;AAX9F,wFAAwF;AACxF,yCAAyC;AACzC,MAAM,CAAC,OAAO,GAAG,WAAI,CAAC;AACtB,MAAM,CAAC,OAAO,CAAC,IAAI,GAAG,WAAI,CAAC;AAC3B,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,cAAO,CAAC;AACnC,MAAM,CAAC,OAAO,CAAC,OAAO,GAAG,cAAO,CAAC;AACjC,MAAM,CAAC,OAAO,CAAC,IAAI,GAAG,WAAI,CAAC;AAC3B,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,eAAQ,CAAC;AACpC,MAAM,CAAC,OAAO,CAAC,QAAQ,GAAG,eAAQ,CAAC;AACnC,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,gBAAS,CAAC;AAGrC,0CAAwB"} |
| import { SignOptions } from './types'; | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| export declare function signApp(_opts: SignOptions): Promise<void>; | ||
| /** | ||
| * This function is a legacy callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link signAsync} method instead. | ||
| * @category Codesign | ||
| */ | ||
| export declare const sign: (opts: SignOptions, cb?: ((error?: Error) => void) | undefined) => void; |
-377
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { | ||
| Object.defineProperty(o, "default", { enumerable: true, value: v }); | ||
| }) : function(o, v) { | ||
| o["default"] = v; | ||
| }); | ||
| var __importStar = (this && this.__importStar) || function (mod) { | ||
| if (mod && mod.__esModule) return mod; | ||
| var result = {}; | ||
| if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k); | ||
| __setModuleDefault(result, mod); | ||
| return result; | ||
| }; | ||
| var __importDefault = (this && this.__importDefault) || function (mod) { | ||
| return (mod && mod.__esModule) ? mod : { "default": mod }; | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.sign = exports.signApp = void 0; | ||
| const fs = __importStar(require("fs-extra")); | ||
| const os = __importStar(require("os")); | ||
| const path = __importStar(require("path")); | ||
| const plist = __importStar(require("plist")); | ||
| const compare_version_1 = __importDefault(require("compare-version")); | ||
| const util_1 = require("./util"); | ||
| const util_identities_1 = require("./util-identities"); | ||
| const util_provisioning_profiles_1 = require("./util-provisioning-profiles"); | ||
| const util_entitlements_1 = require("./util-entitlements"); | ||
| const pkgVersion = require('../../package.json').version; | ||
| const osRelease = os.release(); | ||
| /** | ||
| * This function returns a promise validating opts.binaries, the additional binaries to be signed along with the discovered enclosed components. | ||
| */ | ||
| async function validateOptsBinaries(opts) { | ||
| if (opts.binaries) { | ||
| if (!Array.isArray(opts.binaries)) { | ||
| throw new Error('Additional binaries should be an Array.'); | ||
| } | ||
| // TODO: Presence check for binary files, reject if any does not exist | ||
| } | ||
| } | ||
| function validateOptsIgnore(ignore) { | ||
| if (ignore && !(ignore instanceof Array)) { | ||
| return [ignore]; | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| */ | ||
| async function validateSignOpts(opts) { | ||
| await validateOptsBinaries(opts); | ||
| await (0, util_1.validateOptsApp)(opts); | ||
| if (opts.provisioningProfile && typeof opts.provisioningProfile !== 'string') { | ||
| throw new Error('Path to provisioning profile should be a string.'); | ||
| } | ||
| if (opts.type && opts.type !== 'development' && opts.type !== 'distribution') { | ||
| throw new Error('Type must be either `development` or `distribution`.'); | ||
| } | ||
| const platform = await (0, util_1.validateOptsPlatform)(opts); | ||
| const cloned = Object.assign(Object.assign({}, opts), { ignore: validateOptsIgnore(opts.ignore), type: opts.type || 'distribution', platform }); | ||
| return cloned; | ||
| } | ||
| /** | ||
| * This function returns a promise verifying the code sign of application bundle. | ||
| */ | ||
| async function verifySignApplication(opts) { | ||
| // Verify with codesign | ||
| (0, util_1.debugLog)('Verifying application bundle with codesign...'); | ||
| const strictVerify = opts.strictVerify !== undefined ? opts.strictVerify : true; | ||
| await (0, util_1.execFileAsync)('codesign', ['--verify', '--deep'].concat(strictVerify !== false && (0, compare_version_1.default)(osRelease, '15.0.0') >= 0 // Strict flag since darwin 15.0.0 --> OS X 10.11.0 El Capitan | ||
| ? [ | ||
| '--strict' + | ||
| (strictVerify !== true ? '=' + strictVerify : '') | ||
| ] | ||
| : [], ['--verbose=2', opts.app])); | ||
| } | ||
| function defaultOptionsForFile(filePath, platform) { | ||
| const entitlementsFolder = path.resolve(__dirname, '..', '..', 'entitlements'); | ||
| let entitlementsFile; | ||
| if (platform === 'darwin') { | ||
| // Default Entitlements | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/app-entitlements.plist | ||
| // Also include JIT for main process V8 | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plist'); | ||
| // Plugin helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-plugin-entitlements.plist | ||
| if (filePath.includes('(Plugin).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plugin.plist'); | ||
| // GPU Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-gpu-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(GPU).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.gpu.plist'); | ||
| // Renderer Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-renderer-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(Renderer).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.renderer.plist'); | ||
| } | ||
| } | ||
| else { | ||
| // Default entitlements | ||
| // TODO: Can these be more scoped like the non-mas variant? | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.plist'); | ||
| // If it is not the top level app bundle, we sign with inherit | ||
| if (filePath.includes('.app/')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.child.plist'); | ||
| } | ||
| } | ||
| return { | ||
| entitlements: entitlementsFile, | ||
| hardenedRuntime: true, | ||
| requirements: undefined, | ||
| signatureFlags: undefined, | ||
| timestamp: undefined, | ||
| additionalArguments: [] | ||
| }; | ||
| } | ||
| async function mergeOptionsForFile(opts, defaults) { | ||
| const mergedPerFileOptions = Object.assign({}, defaults); | ||
| if (opts) { | ||
| if (opts.entitlements !== undefined) { | ||
| if (Array.isArray(opts.entitlements)) { | ||
| const entitlements = opts.entitlements.reduce((dict, entitlementKey) => (Object.assign(Object.assign({}, dict), { [entitlementKey]: true })), {}); | ||
| const dir = await fs.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await fs.writeFile(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| opts.entitlements = entitlementsPath; | ||
| } | ||
| mergedPerFileOptions.entitlements = opts.entitlements; | ||
| } | ||
| if (opts.hardenedRuntime !== undefined) { | ||
| mergedPerFileOptions.hardenedRuntime = opts.hardenedRuntime; | ||
| } | ||
| if (opts.requirements !== undefined) | ||
| mergedPerFileOptions.requirements = opts.requirements; | ||
| if (opts.signatureFlags !== undefined) { | ||
| mergedPerFileOptions.signatureFlags = opts.signatureFlags; | ||
| } | ||
| if (opts.timestamp !== undefined) | ||
| mergedPerFileOptions.timestamp = opts.timestamp; | ||
| if (opts.additionalArguments !== undefined) | ||
| mergedPerFileOptions.additionalArguments = opts.additionalArguments; | ||
| } | ||
| return mergedPerFileOptions; | ||
| } | ||
| /** | ||
| * This function returns a promise codesigning only. | ||
| */ | ||
| async function signApplication(opts, identity) { | ||
| function shouldIgnoreFilePath(filePath) { | ||
| if (opts.ignore) { | ||
| return opts.ignore.some(function (ignore) { | ||
| if (typeof ignore === 'function') { | ||
| return ignore(filePath); | ||
| } | ||
| return filePath.match(ignore); | ||
| }); | ||
| } | ||
| return false; | ||
| } | ||
| const children = await (0, util_1.walkAsync)((0, util_1.getAppContentsPath)(opts)); | ||
| if (opts.binaries) | ||
| children.push(...opts.binaries); | ||
| const args = ['--sign', identity.hash || identity.name, '--force']; | ||
| if (opts.keychain) { | ||
| args.push('--keychain', opts.keychain); | ||
| } | ||
| /** | ||
| * Sort the child paths by how deep they are in the file tree. Some arcane apple | ||
| * logic expects the deeper files to be signed first otherwise strange errors get | ||
| * thrown our way | ||
| */ | ||
| children.sort((a, b) => { | ||
| const aDepth = a.split(path.sep).length; | ||
| const bDepth = b.split(path.sep).length; | ||
| return bDepth - aDepth; | ||
| }); | ||
| for (const filePath of [...children, opts.app]) { | ||
| if (shouldIgnoreFilePath(filePath)) { | ||
| (0, util_1.debugLog)('Skipped... ' + filePath); | ||
| continue; | ||
| } | ||
| const perFileOptions = await mergeOptionsForFile(opts.optionsForFile ? opts.optionsForFile(filePath) : null, defaultOptionsForFile(filePath, opts.platform)); | ||
| // preAutoEntitlements should only be applied to the top level app bundle. | ||
| // Applying it other files will cause the app to crash and be rejected by Apple. | ||
| if (!filePath.includes('.app/')) { | ||
| if (opts.preAutoEntitlements === false) { | ||
| (0, util_1.debugWarn)('Pre-sign operation disabled for entitlements automation.'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Pre-sign operation enabled for entitlements automation with versions >= `1.1.1`:', '\n', '* Disable by setting `pre-auto-entitlements` to `false`.'); | ||
| if (!opts.version || (0, compare_version_1.default)(opts.version, '1.1.1') >= 0) { | ||
| // Enable Mac App Store sandboxing without using temporary-exception, introduced in Electron v1.1.1. Relates to electron#5601 | ||
| const newEntitlements = await (0, util_entitlements_1.preAutoEntitlements)(opts, perFileOptions, { | ||
| identity, | ||
| provisioningProfile: opts.provisioningProfile | ||
| ? await (0, util_provisioning_profiles_1.getProvisioningProfile)(opts.provisioningProfile, opts.keychain) | ||
| : undefined | ||
| }); | ||
| // preAutoEntitlements may provide us new entitlements, if so we update our options | ||
| // and ensure that entitlements-loginhelper has a correct default value | ||
| if (newEntitlements) { | ||
| perFileOptions.entitlements = newEntitlements; | ||
| } | ||
| } | ||
| } | ||
| } | ||
| (0, util_1.debugLog)('Signing... ' + filePath); | ||
| const perFileArgs = [...args]; | ||
| if (perFileOptions.requirements) { | ||
| if (perFileOptions.requirements.charAt(0) === '=') { | ||
| perFileArgs.push(`-r${perFileOptions.requirements}`); | ||
| } | ||
| else { | ||
| perFileArgs.push('--requirements', perFileOptions.requirements); | ||
| } | ||
| } | ||
| if (perFileOptions.timestamp) { | ||
| perFileArgs.push('--timestamp=' + perFileOptions.timestamp); | ||
| } | ||
| else { | ||
| perFileArgs.push('--timestamp'); | ||
| } | ||
| let optionsArguments = []; | ||
| if (perFileOptions.signatureFlags) { | ||
| if (Array.isArray(perFileOptions.signatureFlags)) { | ||
| optionsArguments.push(...perFileOptions.signatureFlags); | ||
| } | ||
| else { | ||
| const flags = perFileOptions.signatureFlags.split(',').map(function (flag) { | ||
| return flag.trim(); | ||
| }); | ||
| optionsArguments.push(...flags); | ||
| } | ||
| } | ||
| if (perFileOptions.hardenedRuntime || optionsArguments.includes('runtime')) { | ||
| // Hardened runtime since darwin 17.7.0 --> macOS 10.13.6 | ||
| if ((0, compare_version_1.default)(osRelease, '17.7.0') >= 0) { | ||
| optionsArguments.push('runtime'); | ||
| } | ||
| else { | ||
| // Remove runtime if passed in with --signature-flags | ||
| (0, util_1.debugLog)('Not enabling hardened runtime, current macOS version too low, requires 10.13.6 and higher'); | ||
| optionsArguments = optionsArguments.filter((arg) => { | ||
| return arg !== 'runtime'; | ||
| }); | ||
| } | ||
| } | ||
| if (optionsArguments.length) { | ||
| perFileArgs.push('--options', [...new Set(optionsArguments)].join(',')); | ||
| } | ||
| if (perFileOptions.additionalArguments) { | ||
| perFileArgs.push(...perFileOptions.additionalArguments); | ||
| } | ||
| await (0, util_1.execFileAsync)('codesign', perFileArgs.concat('--entitlements', perFileOptions.entitlements, filePath)); | ||
| } | ||
| // Verify code sign | ||
| (0, util_1.debugLog)('Verifying...'); | ||
| await verifySignApplication(opts); | ||
| (0, util_1.debugLog)('Verified.'); | ||
| // Check entitlements if applicable | ||
| (0, util_1.debugLog)('Displaying entitlements...'); | ||
| const result = await (0, util_1.execFileAsync)('codesign', [ | ||
| '--display', | ||
| '--entitlements', | ||
| ':-', | ||
| opts.app | ||
| ]); | ||
| (0, util_1.debugLog)('Entitlements:', '\n', result); | ||
| } | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| async function signApp(_opts) { | ||
| (0, util_1.debugLog)('electron-osx-sign@%s', pkgVersion); | ||
| const validatedOpts = await validateSignOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| // Determine identity for signing | ||
| if (validatedOpts.identity) { | ||
| (0, util_1.debugLog)('`identity` passed in arguments.'); | ||
| if (validatedOpts.identityValidation === false) { | ||
| identityInUse = new util_identities_1.Identity(validatedOpts.identity); | ||
| } | ||
| else { | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOpts.keychain || null, validatedOpts.identity); | ||
| } | ||
| } | ||
| else { | ||
| (0, util_1.debugWarn)('No `identity` passed in arguments...'); | ||
| if (validatedOpts.platform === 'mas') { | ||
| if (validatedOpts.type === 'distribution') { | ||
| (0, util_1.debugLog)('Finding `3rd Party Mac Developer Application` certificate for signing app distribution in the Mac App Store...'); | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOpts.keychain || null, '3rd Party Mac Developer Application:'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Finding `Mac Developer` certificate for signing app in development for the Mac App Store signing...'); | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOpts.keychain || null, 'Mac Developer:'); | ||
| } | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await (0, util_identities_1.findIdentities)(validatedOpts.keychain || null, 'Developer ID Application:'); | ||
| } | ||
| } | ||
| if (!identityInUse) { | ||
| if (identities.length > 0) { | ||
| // Identity(/ies) found | ||
| if (identities.length > 1) { | ||
| (0, util_1.debugWarn)('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| } | ||
| // Pre-sign operations | ||
| if (validatedOpts.preEmbedProvisioningProfile === false) { | ||
| (0, util_1.debugWarn)('Pre-sign operation disabled for provisioning profile embedding:', '\n', '* Enable by setting `pre-embed-provisioning-profile` to `true`.'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Pre-sign operation enabled for provisioning profile:', '\n', '* Disable by setting `pre-embed-provisioning-profile` to `false`.'); | ||
| await (0, util_provisioning_profiles_1.preEmbedProvisioningProfile)(validatedOpts, validatedOpts.provisioningProfile | ||
| ? await (0, util_provisioning_profiles_1.getProvisioningProfile)(validatedOpts.provisioningProfile, validatedOpts.keychain) | ||
| : null); | ||
| } | ||
| (0, util_1.debugLog)('Signing application...', '\n', '> Application:', validatedOpts.app, '\n', '> Platform:', validatedOpts.platform, '\n', '> Additional binaries:', validatedOpts.binaries, '\n', '> Identity:', validatedOpts.identity); | ||
| await signApplication(validatedOpts, identityInUse); | ||
| // Post-sign operations | ||
| (0, util_1.debugLog)('Application signed.'); | ||
| } | ||
| exports.signApp = signApp; | ||
| /** | ||
| * This function is a legacy callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link signAsync} method instead. | ||
| * @category Codesign | ||
| */ | ||
| const sign = (opts, cb) => { | ||
| signApp(opts) | ||
| .then(() => { | ||
| (0, util_1.debugLog)('Application signed: ' + opts.app); | ||
| if (cb) | ||
| cb(); | ||
| }) | ||
| .catch((err) => { | ||
| if (err.message) | ||
| (0, util_1.debugLog)(err.message); | ||
| else if (err.stack) | ||
| (0, util_1.debugLog)(err.stack); | ||
| else | ||
| (0, util_1.debugLog)(err); | ||
| if (cb) | ||
| cb(err); | ||
| }); | ||
| }; | ||
| exports.sign = sign; | ||
| //# sourceMappingURL=sign.js.map |
| {"version":3,"file":"sign.js","sourceRoot":"","sources":["../../src/sign.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAAA,6CAA+B;AAC/B,uCAAyB;AACzB,2CAA6B;AAC7B,6CAA+B;AAC/B,sEAA6C;AAE7C,iCAQgB;AAChB,uDAA6D;AAC7D,6EAAmG;AACnG,2DAA0D;AAG1D,MAAM,UAAU,GAAW,OAAO,CAAC,oBAAoB,CAAC,CAAC,OAAO,CAAC;AAEjE,MAAM,SAAS,GAAG,EAAE,CAAC,OAAO,EAAE,CAAC;AAE/B;;GAEG;AACH,KAAK,UAAU,oBAAoB,CAAE,IAAiB;IACpD,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,EAAE;YACjC,MAAM,IAAI,KAAK,CAAC,yCAAyC,CAAC,CAAC;SAC5D;QACD,sEAAsE;KACvE;AACH,CAAC;AAED,SAAS,kBAAkB,CAAE,MAA6B;IACxD,IAAI,MAAM,IAAI,CAAC,CAAC,MAAM,YAAY,KAAK,CAAC,EAAE;QACxC,OAAO,CAAC,MAAM,CAAC,CAAC;KACjB;AACH,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,gBAAgB,CAAE,IAAiB;IAChD,MAAM,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACjC,MAAM,IAAA,sBAAe,EAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,IAAI,CAAC,mBAAmB,IAAI,OAAO,IAAI,CAAC,mBAAmB,KAAK,QAAQ,EAAE;QAC5E,MAAM,IAAI,KAAK,CAAC,kDAAkD,CAAC,CAAC;KACrE;IAED,IAAI,IAAI,CAAC,IAAI,IAAI,IAAI,CAAC,IAAI,KAAK,aAAa,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc,EAAE;QAC5E,MAAM,IAAI,KAAK,CAAC,sDAAsD,CAAC,CAAC;KACzE;IAED,MAAM,QAAQ,GAAG,MAAM,IAAA,2BAAoB,EAAC,IAAI,CAAC,CAAC;IAClD,MAAM,MAAM,mCACP,IAAI,KACP,MAAM,EAAE,kBAAkB,CAAC,IAAI,CAAC,MAAM,CAAC,EACvC,IAAI,EAAE,IAAI,CAAC,IAAI,IAAI,cAAc,EACjC,QAAQ,GACT,CAAC;IACF,OAAO,MAAM,CAAC;AAChB,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,qBAAqB,CAAE,IAA0B;IAC9D,uBAAuB;IACvB,IAAA,eAAQ,EAAC,+CAA+C,CAAC,CAAC;IAE1D,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,KAAK,SAAS,CAAC,CAAC,CAAC,IAAI,CAAC,YAAY,CAAC,CAAC,CAAC,IAAI,CAAC;IAChF,MAAM,IAAA,oBAAa,EACjB,UAAU,EACV,CAAC,UAAU,EAAE,QAAQ,CAAC,CAAC,MAAM,CAC3B,YAAY,KAAK,KAAK,IAAI,IAAA,yBAAc,EAAC,SAAS,EAAE,QAAQ,CAAC,IAAI,CAAC,CAAC,8DAA8D;QAC/H,CAAC,CAAC;YACE,UAAU;gBACR,CAAC,YAAY,KAAK,IAAI,CAAC,CAAC,CAAC,GAAG,GAAG,YAAY,CAAC,CAAC,CAAC,EAAE,CAAC;SACpD;QACH,CAAC,CAAC,EAAE,EACN,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,CAAC,CAC1B,CACF,CAAC;AACJ,CAAC;AAED,SAAS,qBAAqB,CAAE,QAAgB,EAAE,QAA6B;IAC7E,MAAM,kBAAkB,GAAG,IAAI,CAAC,OAAO,CAAC,SAAS,EAAE,IAAI,EAAE,IAAI,EAAE,cAAc,CAAC,CAAC;IAE/E,IAAI,gBAAwB,CAAC;IAC7B,IAAI,QAAQ,KAAK,QAAQ,EAAE;QACzB,uBAAuB;QACvB,kGAAkG;QAClG,uCAAuC;QACvC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,sBAAsB,CAAC,CAAC;QAC5E,gBAAgB;QAChB,4GAA4G;QAC5G,IAAI,QAAQ,CAAC,QAAQ,CAAC,cAAc,CAAC,EAAE;YACrC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,6BAA6B,CAAC,CAAC;YACrF,aAAa;YACb,yGAAyG;SACxG;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,WAAW,CAAC,EAAE;YACzC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,0BAA0B,CAAC,CAAC;YAClF,kBAAkB;YAClB,8GAA8G;SAC7G;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,gBAAgB,CAAC,EAAE;YAC9C,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,+BAA+B,CAAC,CAAC;SACtF;KACF;SAAM;QACL,uBAAuB;QACvB,2DAA2D;QAC3D,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,mBAAmB,CAAC,CAAC;QAEzE,8DAA8D;QAC9D,IAAI,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE;YAC9B,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,yBAAyB,CAAC,CAAC;SAChF;KACF;IAED,OAAO;QACL,YAAY,EAAE,gBAAgB;QAC9B,eAAe,EAAE,IAAI;QACrB,YAAY,EAAE,SAA+B;QAC7C,cAAc,EAAE,SAA0C;QAC1D,SAAS,EAAE,SAA+B;QAC1C,mBAAmB,EAAE,EAA0B;KAChD,CAAC;AACJ,CAAC;AAED,KAAK,UAAU,mBAAmB,CAChC,IAA+B,EAC/B,QAAkD;IAElD,MAAM,oBAAoB,qBAAQ,QAAQ,CAAE,CAAC;IAC7C,IAAI,IAAI,EAAE;QACR,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS,EAAE;YACnC,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,YAAY,CAAC,EAAE;gBACpC,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC,MAAM,CAAsB,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,iCACxF,IAAI,KACP,CAAC,cAAc,CAAC,EAAE,IAAI,IACtB,EAAE,EAAE,CAAC,CAAC;gBACR,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;gBAC7E,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;gBAC9D,MAAM,EAAE,CAAC,SAAS,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;gBACxE,IAAI,CAAC,YAAY,GAAG,gBAAgB,CAAC;aACtC;YACD,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;SACvD;QACD,IAAI,IAAI,CAAC,eAAe,KAAK,SAAS,EAAE;YACtC,oBAAoB,CAAC,eAAe,GAAG,IAAI,CAAC,eAAe,CAAC;SAC7D;QACD,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS;YAAE,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;QAC3F,IAAI,IAAI,CAAC,cAAc,KAAK,SAAS,EAAE;YACrC,oBAAoB,CAAC,cAAc,GAAG,IAAI,CAAC,cAAc,CAAC;SAC3D;QACD,IAAI,IAAI,CAAC,SAAS,KAAK,SAAS;YAAE,oBAAoB,CAAC,SAAS,GAAG,IAAI,CAAC,SAAS,CAAC;QAClF,IAAI,IAAI,CAAC,mBAAmB,KAAK,SAAS;YAAE,oBAAoB,CAAC,mBAAmB,GAAG,IAAI,CAAC,mBAAmB,CAAC;KACjH;IACD,OAAO,oBAAoB,CAAC;AAC9B,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,eAAe,CAAE,IAA0B,EAAE,QAAkB;IAC5E,SAAS,oBAAoB,CAAE,QAAgB;QAC7C,IAAI,IAAI,CAAC,MAAM,EAAE;YACf,OAAO,IAAI,CAAC,MAAM,CAAC,IAAI,CAAC,UAAU,MAAM;gBACtC,IAAI,OAAO,MAAM,KAAK,UAAU,EAAE;oBAChC,OAAO,MAAM,CAAC,QAAQ,CAAC,CAAC;iBACzB;gBACD,OAAO,QAAQ,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC;YAChC,CAAC,CAAC,CAAC;SACJ;QACD,OAAO,KAAK,CAAC;IACf,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,IAAA,gBAAS,EAAC,IAAA,yBAAkB,EAAC,IAAI,CAAC,CAAC,CAAC;IAE3D,IAAI,IAAI,CAAC,QAAQ;QAAE,QAAQ,CAAC,IAAI,CAAC,GAAG,IAAI,CAAC,QAAQ,CAAC,CAAC;IAEnD,MAAM,IAAI,GAAG,CAAC,QAAQ,EAAE,QAAQ,CAAC,IAAI,IAAI,QAAQ,CAAC,IAAI,EAAE,SAAS,CAAC,CAAC;IACnE,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,CAAC,IAAI,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;KACxC;IAED;;;;OAIG;IACH,QAAQ,CAAC,IAAI,CAAC,CAAC,CAAC,EAAE,CAAC,EAAE,EAAE;QACrB,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,OAAO,MAAM,GAAG,MAAM,CAAC;IACzB,CAAC,CAAC,CAAC;IAEH,KAAK,MAAM,QAAQ,IAAI,CAAC,GAAG,QAAQ,EAAE,IAAI,CAAC,GAAG,CAAC,EAAE;QAC9C,IAAI,oBAAoB,CAAC,QAAQ,CAAC,EAAE;YAClC,IAAA,eAAQ,EAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;YACnC,SAAS;SACV;QAED,MAAM,cAAc,GAAG,MAAM,mBAAmB,CAC9C,IAAI,CAAC,cAAc,CAAC,CAAC,CAAC,IAAI,CAAC,cAAc,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,IAAI,EAC1D,qBAAqB,CAAC,QAAQ,EAAE,IAAI,CAAC,QAAQ,CAAC,CAC/C,CAAC;QAEF,0EAA0E;QAC1E,gFAAgF;QAChF,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE;YAC/B,IAAI,IAAI,CAAC,mBAAmB,KAAK,KAAK,EAAE;gBACtC,IAAA,gBAAS,EAAC,0DAA0D,CAAC,CAAC;aACvE;iBAAM;gBACL,IAAA,eAAQ,EACN,kFAAkF,EAClF,IAAI,EACJ,0DAA0D,CAC3D,CAAC;gBACF,IAAI,CAAC,IAAI,CAAC,OAAO,IAAI,IAAA,yBAAc,EAAC,IAAI,CAAC,OAAO,EAAE,OAAO,CAAC,IAAI,CAAC,EAAE;oBAC/D,6HAA6H;oBAC7H,MAAM,eAAe,GAAG,MAAM,IAAA,uCAAmB,EAAC,IAAI,EAAE,cAAc,EAAE;wBACtE,QAAQ;wBACR,mBAAmB,EAAE,IAAI,CAAC,mBAAmB;4BAC3C,CAAC,CAAC,MAAM,IAAA,mDAAsB,EAAC,IAAI,CAAC,mBAAmB,EAAE,IAAI,CAAC,QAAQ,CAAC;4BACvE,CAAC,CAAC,SAAS;qBACd,CAAC,CAAC;oBAEH,mFAAmF;oBACnF,uEAAuE;oBACvE,IAAI,eAAe,EAAE;wBACnB,cAAc,CAAC,YAAY,GAAG,eAAe,CAAC;qBAC/C;iBACF;aACF;SACF;QAED,IAAA,eAAQ,EAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;QAEnC,MAAM,WAAW,GAAG,CAAC,GAAG,IAAI,CAAC,CAAC;QAE9B,IAAI,cAAc,CAAC,YAAY,EAAE;YAC/B,IAAI,cAAc,CAAC,YAAY,CAAC,MAAM,CAAC,CAAC,CAAC,KAAK,GAAG,EAAE;gBACjD,WAAW,CAAC,IAAI,CAAC,KAAK,cAAc,CAAC,YAAY,EAAE,CAAC,CAAC;aACtD;iBAAM;gBACL,WAAW,CAAC,IAAI,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,CAAC,CAAC;aACjE;SACF;QACD,IAAI,cAAc,CAAC,SAAS,EAAE;YAC5B,WAAW,CAAC,IAAI,CAAC,cAAc,GAAG,cAAc,CAAC,SAAS,CAAC,CAAC;SAC7D;aAAM;YACL,WAAW,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;SACjC;QAED,IAAI,gBAAgB,GAAa,EAAE,CAAC;QAEpC,IAAI,cAAc,CAAC,cAAc,EAAE;YACjC,IAAI,KAAK,CAAC,OAAO,CAAC,cAAc,CAAC,cAAc,CAAC,EAAE;gBAChD,gBAAgB,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,cAAc,CAAC,CAAC;aACzD;iBAAM;gBACL,MAAM,KAAK,GAAG,cAAc,CAAC,cAAc,CAAC,KAAK,CAAC,GAAG,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;oBACvE,OAAO,IAAI,CAAC,IAAI,EAAE,CAAC;gBACrB,CAAC,CAAC,CAAC;gBACH,gBAAgB,CAAC,IAAI,CAAC,GAAG,KAAK,CAAC,CAAC;aACjC;SACF;QAED,IAAI,cAAc,CAAC,eAAe,IAAI,gBAAgB,CAAC,QAAQ,CAAC,SAAS,CAAC,EAAE;YAC1E,yDAAyD;YACzD,IAAI,IAAA,yBAAc,EAAC,SAAS,EAAE,QAAQ,CAAC,IAAI,CAAC,EAAE;gBAC5C,gBAAgB,CAAC,IAAI,CAAC,SAAS,CAAC,CAAC;aAClC;iBAAM;gBACL,qDAAqD;gBACrD,IAAA,eAAQ,EACN,2FAA2F,CAC5F,CAAC;gBACF,gBAAgB,GAAG,gBAAgB,CAAC,MAAM,CAAC,CAAC,GAAG,EAAE,EAAE;oBACjD,OAAO,GAAG,KAAK,SAAS,CAAC;gBAC3B,CAAC,CAAC,CAAC;aACJ;SACF;QAED,IAAI,gBAAgB,CAAC,MAAM,EAAE;YAC3B,WAAW,CAAC,IAAI,CAAC,WAAW,EAAE,CAAC,GAAG,IAAI,GAAG,CAAC,gBAAgB,CAAC,CAAC,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC;SACzE;QAED,IAAI,cAAc,CAAC,mBAAmB,EAAE;YACtC,WAAW,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,mBAAmB,CAAC,CAAC;SACzD;QAED,MAAM,IAAA,oBAAa,EACjB,UAAU,EACV,WAAW,CAAC,MAAM,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,EAAE,QAAQ,CAAC,CAC5E,CAAC;KACH;IAED,mBAAmB;IACnB,IAAA,eAAQ,EAAC,cAAc,CAAC,CAAC;IACzB,MAAM,qBAAqB,CAAC,IAAI,CAAC,CAAC;IAClC,IAAA,eAAQ,EAAC,WAAW,CAAC,CAAC;IAEtB,mCAAmC;IACnC,IAAA,eAAQ,EAAC,4BAA4B,CAAC,CAAC;IACvC,MAAM,MAAM,GAAG,MAAM,IAAA,oBAAa,EAAC,UAAU,EAAE;QAC7C,WAAW;QACX,gBAAgB;QAChB,IAAI;QACJ,IAAI,CAAC,GAAG;KACT,CAAC,CAAC;IAEH,IAAA,eAAQ,EAAC,eAAe,EAAE,IAAI,EAAE,MAAM,CAAC,CAAC;AAC1C,CAAC;AAED;;;;;GAKG;AACI,KAAK,UAAU,OAAO,CAAE,KAAkB;IAC/C,IAAA,eAAQ,EAAC,sBAAsB,EAAE,UAAU,CAAC,CAAC;IAC7C,MAAM,aAAa,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACpD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,iCAAiC;IACjC,IAAI,aAAa,CAAC,QAAQ,EAAE;QAC1B,IAAA,eAAQ,EAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,aAAa,CAAC,kBAAkB,KAAK,KAAK,EAAE;YAC9C,aAAa,GAAG,IAAI,0BAAQ,CAAC,aAAa,CAAC,QAAQ,CAAC,CAAC;SACtD;aAAM;YACL,UAAU,GAAG,MAAM,IAAA,gCAAc,EAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,aAAa,CAAC,QAAQ,CAAC,CAAC;SAC3F;KACF;SAAM;QACL,IAAA,gBAAS,EAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,aAAa,CAAC,QAAQ,KAAK,KAAK,EAAE;YACpC,IAAI,aAAa,CAAC,IAAI,KAAK,cAAc,EAAE;gBACzC,IAAA,eAAQ,EACN,gHAAgH,CACjH,CAAC;gBACF,UAAU,GAAG,MAAM,IAAA,gCAAc,EAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,sCAAsC,CACvC,CAAC;aACH;iBAAM;gBACL,IAAA,eAAQ,EACN,qGAAqG,CACtG,CAAC;gBACF,UAAU,GAAG,MAAM,IAAA,gCAAc,EAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,gBAAgB,CAAC,CAAC;aACrF;SACF;aAAM;YACL,IAAA,eAAQ,EACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,IAAA,gCAAc,EAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,2BAA2B,CAC5B,CAAC;SACH;KACF;IAED,IAAI,CAAC,aAAa,EAAE;QAClB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;YACzB,uBAAuB;YACvB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;gBACzB,IAAA,gBAAS,EAAC,2DAA2D,CAAC,CAAC;aACxE;iBAAM;gBACL,IAAA,eAAQ,EAAC,mBAAmB,CAAC,CAAC;aAC/B;YACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;SAC/B;aAAM;YACL,oBAAoB;YACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;SACnD;KACF;IAED,sBAAsB;IACtB,IAAI,aAAa,CAAC,2BAA2B,KAAK,KAAK,EAAE;QACvD,IAAA,gBAAS,EACP,iEAAiE,EACjE,IAAI,EACJ,iEAAiE,CAClE,CAAC;KACH;SAAM;QACL,IAAA,eAAQ,EACN,sDAAsD,EACtD,IAAI,EACJ,mEAAmE,CACpE,CAAC;QACF,MAAM,IAAA,wDAA2B,EAC/B,aAAa,EACb,aAAa,CAAC,mBAAmB;YAC/B,CAAC,CAAC,MAAM,IAAA,mDAAsB,EAAC,aAAa,CAAC,mBAAmB,EAAE,aAAa,CAAC,QAAQ,CAAC;YACzF,CAAC,CAAC,IAAI,CACT,CAAC;KACH;IAED,IAAA,eAAQ,EACN,wBAAwB,EACxB,IAAI,EACJ,gBAAgB,EAChB,aAAa,CAAC,GAAG,EACjB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,wBAAwB,EACxB,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,CACvB,CAAC;IACF,MAAM,eAAe,CAAC,aAAa,EAAE,aAAa,CAAC,CAAC;IAEpD,uBAAuB;IACvB,IAAA,eAAQ,EAAC,qBAAqB,CAAC,CAAC;AAClC,CAAC;AAjGD,0BAiGC;AAED;;;;;GAKG;AACI,MAAM,IAAI,GAAG,CAAC,IAAiB,EAAE,EAA4B,EAAE,EAAE;IACtE,OAAO,CAAC,IAAI,CAAC;SACV,IAAI,CAAC,GAAG,EAAE;QACT,IAAA,eAAQ,EAAC,sBAAsB,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC5C,IAAI,EAAE;YAAE,EAAE,EAAE,CAAC;IACf,CAAC,CAAC;SACD,KAAK,CAAC,CAAC,GAAG,EAAE,EAAE;QACb,IAAI,GAAG,CAAC,OAAO;YAAE,IAAA,eAAQ,EAAC,GAAG,CAAC,OAAO,CAAC,CAAC;aAClC,IAAI,GAAG,CAAC,KAAK;YAAE,IAAA,eAAQ,EAAC,GAAG,CAAC,KAAK,CAAC,CAAC;;YACnC,IAAA,eAAQ,EAAC,GAAG,CAAC,CAAC;QACnB,IAAI,EAAE;YAAE,EAAE,CAAC,GAAG,CAAC,CAAC;IAClB,CAAC,CAAC,CAAC;AACP,CAAC,CAAC;AAZW,QAAA,IAAI,QAYf"} |
| /** | ||
| * macOS applications can be distributed via the Mac App Store (MAS) or directly | ||
| * downloaded from the developer's website. @electron/osx-sign distinguishes between | ||
| * MAS apps (`mas`) or non-MAS apps (`darwin`). | ||
| * @category Utility | ||
| */ | ||
| export type ElectronMacPlatform = 'darwin' | 'mas'; | ||
| /** | ||
| * MAS apps can be signed using Development or Distribution certificates. | ||
| * See [Apple Documentation](https://developer.apple.com/help/account/create-certificates/certificates-overview/) for more info. | ||
| * @category Utility | ||
| */ | ||
| export type SigningDistributionType = 'development' | 'distribution'; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type BaseSignOptions = Readonly<{ | ||
| /** | ||
| * Path to the application package. | ||
| * Needs to end with the file extension `.app`. | ||
| */ | ||
| app: string; | ||
| /** | ||
| * The keychain name. | ||
| * | ||
| * @defaultValue `login` | ||
| */ | ||
| keychain?: string; | ||
| /** | ||
| * Build platform of your Electron app. | ||
| * Allowed values: `darwin` (Direct Download App), `mas` (Mac App Store). | ||
| * | ||
| * @defaultValue Determined by presence of `Squirrel.framework` within the application bundle, | ||
| * which is used for non-MAS apps. | ||
| */ | ||
| platform?: ElectronMacPlatform; | ||
| /** | ||
| * Name of the certificate to use when signing. | ||
| * | ||
| * @defaultValue Selected with respect to {@link SignOptions.provisioningProfile | provisioningProfile} | ||
| * and {@link SignOptions.platform | platform} from the selected {@link SignOptions.keychain | keychain}. | ||
| * * `mas` will look for `3rd Party Mac Developer Application: * (*)` | ||
| * * `darwin` will look for `Developer ID Application: * (*)` by default. | ||
| */ | ||
| identity?: string; | ||
| }>; | ||
| type OnlyValidatedBaseSignOptions = { | ||
| platform: ElectronMacPlatform; | ||
| }; | ||
| /** | ||
| * A set of signing options that can be overriden on a per-file basis. | ||
| * Any missing options will use the default values, and providing a partial structure | ||
| * will shallow merge with the default values. | ||
| * @interface | ||
| * @category Codesign | ||
| */ | ||
| export type PerFileSignOptions = { | ||
| /** | ||
| * String specifying the path to an `entitlements.plist` file. | ||
| * Can also be an array of entitlement keys that osx-sign will write to an entitlements file for you. | ||
| * | ||
| * @defaultValue `@electron/osx-sign`'s built-in entitlements files. | ||
| */ | ||
| entitlements?: string | string[]; | ||
| /** | ||
| * Whether to enable [Hardened Runtime](https://developer.apple.com/documentation/security/hardened_runtime) | ||
| * for this file. | ||
| * | ||
| * Note: Hardened Runtime is a pre-requisite for notarization, which is mandatory for apps running on macOS 10.15 and above. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| hardenedRuntime?: boolean; | ||
| /** | ||
| * Either a string beginning with `=` which specifies in plain text the | ||
| * [signing requirements](https://developer.apple.com/library/mac/documentation/Security/Conceptual/CodeSigningGuide/RequirementLang/RequirementLang.html) | ||
| * that you recommend to be used to evaluate the code signature, or a string specifying a path to a text or | ||
| * properly encoded `.rqset` file which contains those requirements. | ||
| */ | ||
| requirements?: string; | ||
| /** | ||
| * When signing, a set of option flags can be specified to change the behavior of the system when using the signed code. | ||
| * Accepts an array of strings or a comma-separated string. | ||
| * | ||
| * See --options of the `codesign` command. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTION_FLAGS | ||
| */ | ||
| signatureFlags?: string | string[]; | ||
| /** | ||
| * String specifying the URL of the timestamp authority server. | ||
| * Please note that this default server may not support signatures not furnished by Apple. | ||
| * Disable the timestamp service with `none`. | ||
| * | ||
| * @defaultValue Uses the Apple-provided timestamp server. | ||
| */ | ||
| timestamp?: string; | ||
| /** | ||
| * Additional raw arguments to pass to the `codesign` command. | ||
| * | ||
| * These can be things like `--deep` for instance when code signing specific resources that may | ||
| * require such arguments. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTIONS | ||
| */ | ||
| additionalArguments?: string[]; | ||
| }; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type OnlySignOptions = { | ||
| /** | ||
| * Array of paths to additional binaries that will be signed along with built-ins of Electron. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| binaries?: string[]; | ||
| /** | ||
| * Function that receives the path to a file and can return the entitlements to use for that file to override the default behavior. The | ||
| * object this function returns can include any of the following optional keys. Any properties that are returned **override** the default | ||
| * values that `@electron/osx-sign` generates. Any properties not returned use the default value. | ||
| * | ||
| * @param filePath Path to file | ||
| * @returns Override signing options | ||
| */ | ||
| optionsForFile?: (filePath: string) => PerFileSignOptions; | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link SignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Defines files that will be skipped during the code signing process. | ||
| * This property accepts a regex, function or an array of regexes and functions. | ||
| * Elements of other types are treated as `RegExp`. | ||
| * | ||
| * File paths matching a regex or returning a `true` value from a function will be ignored. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| ignore?: string | string[] | ((file: string) => boolean); | ||
| /** | ||
| * Flag to enable/disable entitlements automation tasks necessary for code signing most Electron apps. | ||
| * * Adds [`com.apple.security.application-groups`](https://developer.apple.com/documentation/bundleresources/entitlements/com_apple_security_application-groups) to the entitlements file | ||
| * * Fills in the `ElectronTeamID` property in `Info.plist` with the provisioning profile's Team Identifier or by parsing the identity name. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preAutoEntitlements?: boolean; | ||
| /** | ||
| * Flag to enable/disable the embedding of a provisioning profile into the app's `Contents` folder. | ||
| * Will use the profile from {@link OnlySignOptions.provisioningProfile} if provided. Otherwise, it | ||
| * searches for a `.provisionprofile` file in the current working directory. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preEmbedProvisioningProfile?: boolean; | ||
| /** | ||
| * Path to a provisioning profile, which can be used to grant restricted entitlements to your app. | ||
| * | ||
| * See [Apple Documentation](https://developer.apple.com/documentation/technotes/tn3125-inside-code-signing-provisioning-profiles) for more details. | ||
| */ | ||
| provisioningProfile?: string; | ||
| /** | ||
| * Flag to enable/disable the `--strict` flag when verifying the signed application bundle. | ||
| * Also supports string values to specify which strict restrictions to use, see codesign man page for supported values. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| strictVerify?: boolean | string; | ||
| /** | ||
| * Type of certificate to use when signing a MAS app. | ||
| * @defaultValue `"distribution"` | ||
| */ | ||
| type?: SigningDistributionType; | ||
| /** | ||
| * Build version of Electron. Values may be like: `1.1.1`, `1.2.0`. For use for signing legacy versions | ||
| * of Electron to ensure backwards compatibility. | ||
| */ | ||
| version?: string; | ||
| }; | ||
| type OnlyValidatedSignOptions = { | ||
| ignore?: (string | ((file: string) => boolean))[]; | ||
| type: SigningDistributionType; | ||
| }; | ||
| type OnlyFlatOptions = { | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link BaseSignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Path to install the bundle. | ||
| * @defaultValue `"/Applications"` | ||
| */ | ||
| install?: string; | ||
| /** | ||
| * Output path for the flattened installer package. | ||
| * Needs file extension `.pkg`. | ||
| * | ||
| * @defaultValue Inferred from the app name passed into `opts.app`. | ||
| */ | ||
| pkg?: string; | ||
| /** | ||
| * Path to a directory containing `preinstall.sh` or `postinstall.sh` scripts. | ||
| * These must be executable and will run on pre/postinstall depending on the file | ||
| * name. | ||
| * | ||
| * This option is only valid if {@link FlatOptions.platform} is set to `darwin`. | ||
| */ | ||
| scripts?: string; | ||
| }; | ||
| type OnlyValidatedFlatOptions = { | ||
| install: string; | ||
| pkg: string; | ||
| }; | ||
| /** | ||
| * Utility type that represents an `UnValidated` type after validation, | ||
| * replacing any properties in the unvalidated type that also exist in the | ||
| * `Validated` type with the validated versions. | ||
| * | ||
| * @template UnValidated - The type representing the unvalidated form. | ||
| * @template Validated - The type representing the validated form. | ||
| */ | ||
| type ValidatedForm<UnValidated, Validated> = Omit<UnValidated, keyof Validated> & Validated; | ||
| type ValidatedBaseSignOptions = Readonly<ValidatedForm<BaseSignOptions, OnlyValidatedBaseSignOptions>>; | ||
| type _SignOptions = Readonly<OnlySignOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for codesigning a packaged `.app` bundle. | ||
| * @category Codesign | ||
| */ | ||
| export interface SignOptions extends _SignOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedSignOptions = Readonly<ValidatedForm<OnlySignOptions, OnlyValidatedSignOptions> & ValidatedBaseSignOptions>; | ||
| type _FlatOptions = Readonly<OnlyFlatOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for creating a flat `.pkg` installer. | ||
| * @category Flat | ||
| */ | ||
| export interface FlatOptions extends _FlatOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedFlatOptions = Readonly<ValidatedForm<OnlyFlatOptions, OnlyValidatedFlatOptions> & ValidatedBaseSignOptions>; | ||
| export {}; |
| "use strict"; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| //# sourceMappingURL=types.js.map |
| {"version":3,"file":"types.js","sourceRoot":"","sources":["../../src/types.ts"],"names":[],"mappings":""} |
| import { PerFileSignOptions, ValidatedSignOptions } from './types'; | ||
| import { Identity } from './util-identities'; | ||
| import { ProvisioningProfile } from './util-provisioning-profiles'; | ||
| type ComputedOptions = { | ||
| identity: Identity; | ||
| provisioningProfile?: ProvisioningProfile; | ||
| }; | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| export declare function preAutoEntitlements(opts: ValidatedSignOptions, perFileOpts: PerFileSignOptions, computed: ComputedOptions): Promise<void | string>; | ||
| export {}; |
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { | ||
| Object.defineProperty(o, "default", { enumerable: true, value: v }); | ||
| }) : function(o, v) { | ||
| o["default"] = v; | ||
| }); | ||
| var __importStar = (this && this.__importStar) || function (mod) { | ||
| if (mod && mod.__esModule) return mod; | ||
| var result = {}; | ||
| if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k); | ||
| __setModuleDefault(result, mod); | ||
| return result; | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.preAutoEntitlements = void 0; | ||
| const fs = __importStar(require("fs-extra")); | ||
| const os = __importStar(require("os")); | ||
| const path = __importStar(require("path")); | ||
| const plist = __importStar(require("plist")); | ||
| const util_1 = require("./util"); | ||
| const preAuthMemo = new Map(); | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| async function preAutoEntitlements(opts, perFileOpts, computed) { | ||
| var _a; | ||
| if (!perFileOpts.entitlements) | ||
| return; | ||
| const memoKey = [opts.app, perFileOpts.entitlements].join('---'); | ||
| if (preAuthMemo.has(memoKey)) | ||
| return preAuthMemo.get(memoKey); | ||
| // If entitlements file not provided, default will be used. Fixes #41 | ||
| const appInfoPath = path.join((0, util_1.getAppContentsPath)(opts), 'Info.plist'); | ||
| (0, util_1.debugLog)('Automating entitlement app group...', '\n', '> Info.plist:', appInfoPath, '\n'); | ||
| let entitlements; | ||
| if (typeof perFileOpts.entitlements === 'string') { | ||
| const entitlementsContents = await fs.readFile(perFileOpts.entitlements, 'utf8'); | ||
| entitlements = plist.parse(entitlementsContents); | ||
| } | ||
| else { | ||
| entitlements = perFileOpts.entitlements.reduce((dict, entitlementKey) => (Object.assign(Object.assign({}, dict), { [entitlementKey]: true })), {}); | ||
| } | ||
| if (!entitlements['com.apple.security.app-sandbox']) { | ||
| // Only automate when app sandbox enabled by user | ||
| return; | ||
| } | ||
| const appInfoContents = await fs.readFile(appInfoPath, 'utf8'); | ||
| const appInfo = plist.parse(appInfoContents); | ||
| // Use ElectronTeamID in Info.plist if already specified | ||
| if (appInfo.ElectronTeamID) { | ||
| (0, util_1.debugLog)('`ElectronTeamID` found in `Info.plist`: ' + appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| // The team identifier in signing identity should not be trusted | ||
| if (computed.provisioningProfile) { | ||
| appInfo.ElectronTeamID = | ||
| computed.provisioningProfile.message.Entitlements['com.apple.developer.team-identifier']; | ||
| (0, util_1.debugLog)('`ElectronTeamID` not found in `Info.plist`, use parsed from provisioning profile: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| const teamID = (_a = /^.+\((.+?)\)$/g.exec(computed.identity.name)) === null || _a === void 0 ? void 0 : _a[1]; | ||
| if (!teamID) { | ||
| throw new Error(`Could not automatically determine ElectronTeamID from identity: ${computed.identity.name}`); | ||
| } | ||
| appInfo.ElectronTeamID = teamID; | ||
| (0, util_1.debugLog)('`ElectronTeamID` not found in `Info.plist`, use parsed from signing identity: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| await fs.writeFile(appInfoPath, plist.build(appInfo), 'utf8'); | ||
| (0, util_1.debugLog)('`Info.plist` updated:', '\n', '> Info.plist:', appInfoPath); | ||
| } | ||
| const appIdentifier = appInfo.ElectronTeamID + '.' + appInfo.CFBundleIdentifier; | ||
| // Insert application identifier if not exists | ||
| if (entitlements['com.apple.application-identifier']) { | ||
| (0, util_1.debugLog)('`com.apple.application-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.application-identifier']); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('`com.apple.application-identifier` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.application-identifier'] = appIdentifier; | ||
| } | ||
| // Insert developer team identifier if not exists | ||
| if (entitlements['com.apple.developer.team-identifier']) { | ||
| (0, util_1.debugLog)('`com.apple.developer.team-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.developer.team-identifier']); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('`com.apple.developer.team-identifier` not found in entitlements file, new inserted: ' + | ||
| appInfo.ElectronTeamID); | ||
| entitlements['com.apple.developer.team-identifier'] = appInfo.ElectronTeamID; | ||
| } | ||
| // Init entitlements app group key to array if not exists | ||
| if (!entitlements['com.apple.security.application-groups']) { | ||
| entitlements['com.apple.security.application-groups'] = []; | ||
| } | ||
| // Insert app group if not exists | ||
| if (Array.isArray(entitlements['com.apple.security.application-groups']) && | ||
| entitlements['com.apple.security.application-groups'].indexOf(appIdentifier) === -1) { | ||
| (0, util_1.debugLog)('`com.apple.security.application-groups` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.security.application-groups'].push(appIdentifier); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('`com.apple.security.application-groups` found in entitlements file: ' + appIdentifier); | ||
| } | ||
| // Create temporary entitlements file | ||
| const dir = await fs.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await fs.writeFile(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| (0, util_1.debugLog)('Entitlements file updated:', '\n', '> Entitlements:', entitlementsPath); | ||
| preAuthMemo.set(memoKey, entitlementsPath); | ||
| return entitlementsPath; | ||
| } | ||
| exports.preAutoEntitlements = preAutoEntitlements; | ||
| //# sourceMappingURL=util-entitlements.js.map |
| {"version":3,"file":"util-entitlements.js","sourceRoot":"","sources":["../../src/util-entitlements.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;AAAA,6CAA+B;AAC/B,uCAAyB;AACzB,2CAA6B;AAC7B,6CAA+B;AAE/B,iCAAsD;AAStD,MAAM,WAAW,GAAG,IAAI,GAAG,EAAkB,CAAC;AAE9C;;;;;;;GAOG;AACI,KAAK,UAAU,mBAAmB,CACvC,IAA0B,EAC1B,WAA+B,EAC/B,QAAyB;;IAEzB,IAAI,CAAC,WAAW,CAAC,YAAY;QAAE,OAAO;IAEtC,MAAM,OAAO,GAAG,CAAC,IAAI,CAAC,GAAG,EAAE,WAAW,CAAC,YAAY,CAAC,CAAC,IAAI,CAAC,KAAK,CAAC,CAAC;IACjE,IAAI,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC;QAAE,OAAO,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC,CAAC;IAE9D,qEAAqE;IACrE,MAAM,WAAW,GAAG,IAAI,CAAC,IAAI,CAAC,IAAA,yBAAkB,EAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;IAEtE,IAAA,eAAQ,EACN,qCAAqC,EACrC,IAAI,EACJ,eAAe,EACf,WAAW,EACX,IAAI,CACL,CAAC;IACF,IAAI,YAAiC,CAAC;IACtC,IAAI,OAAO,WAAW,CAAC,YAAY,KAAK,QAAQ,EAAE;QAChD,MAAM,oBAAoB,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,WAAW,CAAC,YAAY,EAAE,MAAM,CAAC,CAAC;QACjF,YAAY,GAAG,KAAK,CAAC,KAAK,CAAC,oBAAoB,CAAwB,CAAC;KACzE;SAAM;QACL,YAAY,GAAG,WAAW,CAAC,YAAY,CAAC,MAAM,CAAsB,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,iCACzF,IAAI,KACP,CAAC,cAAc,CAAC,EAAE,IAAI,IACtB,EAAE,EAAE,CAAC,CAAC;KACT;IACD,IAAI,CAAC,YAAY,CAAC,gCAAgC,CAAC,EAAE;QACnD,iDAAiD;QACjD,OAAO;KACR;IAED,MAAM,eAAe,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,WAAW,EAAE,MAAM,CAAC,CAAC;IAC/D,MAAM,OAAO,GAAG,KAAK,CAAC,KAAK,CAAC,eAAe,CAAwB,CAAC;IACpE,wDAAwD;IACxD,IAAI,OAAO,CAAC,cAAc,EAAE;QAC1B,IAAA,eAAQ,EAAC,0CAA0C,GAAG,OAAO,CAAC,cAAc,CAAC,CAAC;KAC/E;SAAM;QACL,gEAAgE;QAChE,IAAI,QAAQ,CAAC,mBAAmB,EAAE;YAChC,OAAO,CAAC,cAAc;gBACpB,QAAQ,CAAC,mBAAmB,CAAC,OAAO,CAAC,YAAY,CAAC,qCAAqC,CAAC,CAAC;YAC3F,IAAA,eAAQ,EACN,oFAAoF;gBAClF,OAAO,CAAC,cAAc,CACzB,CAAC;SACH;aAAM;YACL,MAAM,MAAM,GAAG,MAAA,gBAAgB,CAAC,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,IAAI,CAAC,0CAAG,CAAC,CAAC,CAAC;YAClE,IAAI,CAAC,MAAM,EAAE;gBACX,MAAM,IAAI,KAAK,CAAC,mEAAmE,QAAQ,CAAC,QAAQ,CAAC,IAAI,EAAE,CAAC,CAAC;aAC9G;YACD,OAAO,CAAC,cAAc,GAAG,MAAM,CAAC;YAChC,IAAA,eAAQ,EACN,gFAAgF;gBAC9E,OAAO,CAAC,cAAc,CACzB,CAAC;SACH;QACD,MAAM,EAAE,CAAC,SAAS,CAAC,WAAW,EAAE,KAAK,CAAC,KAAK,CAAC,OAAO,CAAC,EAAE,MAAM,CAAC,CAAC;QAE9D,IAAA,eAAQ,EAAC,uBAAuB,EAAE,IAAI,EAAE,eAAe,EAAE,WAAW,CAAC,CAAC;KACvE;IAED,MAAM,aAAa,GAAG,OAAO,CAAC,cAAc,GAAG,GAAG,GAAG,OAAO,CAAC,kBAAkB,CAAC;IAChF,8CAA8C;IAC9C,IAAI,YAAY,CAAC,kCAAkC,CAAC,EAAE;QACpD,IAAA,eAAQ,EACN,iEAAiE;YAC/D,YAAY,CAAC,kCAAkC,CAAC,CACnD,CAAC;KACH;SAAM;QACL,IAAA,eAAQ,EACN,mFAAmF;YACjF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,kCAAkC,CAAC,GAAG,aAAa,CAAC;KAClE;IACD,iDAAiD;IACjD,IAAI,YAAY,CAAC,qCAAqC,CAAC,EAAE;QACvD,IAAA,eAAQ,EACN,oEAAoE;YAClE,YAAY,CAAC,qCAAqC,CAAC,CACtD,CAAC;KACH;SAAM;QACL,IAAA,eAAQ,EACN,sFAAsF;YACpF,OAAO,CAAC,cAAc,CACzB,CAAC;QACF,YAAY,CAAC,qCAAqC,CAAC,GAAG,OAAO,CAAC,cAAc,CAAC;KAC9E;IACD,yDAAyD;IACzD,IAAI,CAAC,YAAY,CAAC,uCAAuC,CAAC,EAAE;QAC1D,YAAY,CAAC,uCAAuC,CAAC,GAAG,EAAE,CAAC;KAC5D;IACD,iCAAiC;IACjC,IACE,KAAK,CAAC,OAAO,CAAC,YAAY,CAAC,uCAAuC,CAAC,CAAC;QACpE,YAAY,CAAC,uCAAuC,CAAC,CAAC,OAAO,CAAC,aAAa,CAAC,KAAK,CAAC,CAAC,EACnF;QACA,IAAA,eAAQ,EACN,wFAAwF;YACtF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,uCAAuC,CAAC,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;KAC3E;SAAM;QACL,IAAA,eAAQ,EACN,sEAAsE,GAAG,aAAa,CACvF,CAAC;KACH;IACD,qCAAqC;IACrC,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;IAC7E,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;IAC9D,MAAM,EAAE,CAAC,SAAS,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;IACxE,IAAA,eAAQ,EAAC,4BAA4B,EAAE,IAAI,EAAE,iBAAiB,EAAE,gBAAgB,CAAC,CAAC;IAElF,WAAW,CAAC,GAAG,CAAC,OAAO,EAAE,gBAAgB,CAAC,CAAC;IAC3C,OAAO,gBAAgB,CAAC;AAC1B,CAAC;AAvHD,kDAuHC"} |
| export declare class Identity { | ||
| name: string; | ||
| hash?: string | undefined; | ||
| constructor(name: string, hash?: string | undefined); | ||
| } | ||
| export declare function findIdentities(keychain: string | null, identity: string): Promise<Identity[]>; |
| "use strict"; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.findIdentities = exports.Identity = void 0; | ||
| const util_1 = require("./util"); | ||
| class Identity { | ||
| constructor(name, hash) { | ||
| this.name = name; | ||
| this.hash = hash; | ||
| } | ||
| } | ||
| exports.Identity = Identity; | ||
| async function findIdentities(keychain, identity) { | ||
| // Only to look for valid identities, excluding those flagged with | ||
| // CSSMERR_TP_CERT_EXPIRED or CSSMERR_TP_NOT_TRUSTED. Fixes #9 | ||
| const args = [ | ||
| 'find-identity', | ||
| '-v' | ||
| ]; | ||
| if (keychain) { | ||
| args.push(keychain); | ||
| } | ||
| const result = await (0, util_1.execFileAsync)('security', args); | ||
| const identities = result.split('\n').map(function (line) { | ||
| if (line.indexOf(identity) >= 0) { | ||
| const identityFound = line.substring(line.indexOf('"') + 1, line.lastIndexOf('"')); | ||
| const identityHashFound = line.substring(line.indexOf(')') + 2, line.indexOf('"') - 1); | ||
| (0, util_1.debugLog)('Identity:', '\n', '> Name:', identityFound, '\n', '> Hash:', identityHashFound); | ||
| return new Identity(identityFound, identityHashFound); | ||
| } | ||
| return null; | ||
| }); | ||
| return (0, util_1.compactFlattenedList)(identities); | ||
| } | ||
| exports.findIdentities = findIdentities; | ||
| //# sourceMappingURL=util-identities.js.map |
| {"version":3,"file":"util-identities.js","sourceRoot":"","sources":["../../src/util-identities.ts"],"names":[],"mappings":";;;AAAA,iCAAuE;AAEvE,MAAa,QAAQ;IACnB,YAAoB,IAAY,EAAS,IAAa;QAAlC,SAAI,GAAJ,IAAI,CAAQ;QAAS,SAAI,GAAJ,IAAI,CAAS;IAAG,CAAC;CAC3D;AAFD,4BAEC;AAEM,KAAK,UAAU,cAAc,CAAE,QAAuB,EAAE,QAAgB;IAC7E,kEAAkE;IAClE,8DAA8D;IAE9D,MAAM,IAAI,GAAG;QACX,eAAe;QACf,IAAI;KACL,CAAC;IACF,IAAI,QAAQ,EAAE;QACZ,IAAI,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;KACrB;IAED,MAAM,MAAM,GAAG,MAAM,IAAA,oBAAa,EAAC,UAAU,EAAE,IAAI,CAAC,CAAC;IACrD,MAAM,UAAU,GAAG,MAAM,CAAC,KAAK,CAAC,IAAI,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;QACtD,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,IAAI,CAAC,EAAE;YAC/B,MAAM,aAAa,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,WAAW,CAAC,GAAG,CAAC,CAAC,CAAC;YACnF,MAAM,iBAAiB,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,CAAC,CAAC;YACvF,IAAA,eAAQ,EAAC,WAAW,EAAE,IAAI,EACxB,SAAS,EAAE,aAAa,EAAE,IAAI,EAC9B,SAAS,EAAE,iBAAiB,CAAC,CAAC;YAChC,OAAO,IAAI,QAAQ,CAAC,aAAa,EAAE,iBAAiB,CAAC,CAAC;SACvD;QAED,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CAAC;IAEH,OAAO,IAAA,2BAAoB,EAAC,UAAU,CAAC,CAAC;AAC1C,CAAC;AA3BD,wCA2BC"} |
| import { ElectronMacPlatform, ValidatedSignOptions } from './types'; | ||
| export declare class ProvisioningProfile { | ||
| filePath: string; | ||
| message: any; | ||
| constructor(filePath: string, message: any); | ||
| get name(): string; | ||
| get platforms(): ElectronMacPlatform[]; | ||
| get type(): "development" | "distribution"; | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| export declare function getProvisioningProfile(filePath: string, keychain?: string | null): Promise<ProvisioningProfile>; | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| export declare function findProvisioningProfiles(opts: ValidatedSignOptions): Promise<ProvisioningProfile[]>; | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| export declare function preEmbedProvisioningProfile(opts: ValidatedSignOptions, profile: ProvisioningProfile | null): Promise<void>; |
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { | ||
| Object.defineProperty(o, "default", { enumerable: true, value: v }); | ||
| }) : function(o, v) { | ||
| o["default"] = v; | ||
| }); | ||
| var __importStar = (this && this.__importStar) || function (mod) { | ||
| if (mod && mod.__esModule) return mod; | ||
| var result = {}; | ||
| if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k); | ||
| __setModuleDefault(result, mod); | ||
| return result; | ||
| }; | ||
| var __importDefault = (this && this.__importDefault) || function (mod) { | ||
| return (mod && mod.__esModule) ? mod : { "default": mod }; | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.preEmbedProvisioningProfile = exports.findProvisioningProfiles = exports.getProvisioningProfile = exports.ProvisioningProfile = void 0; | ||
| const fs = __importStar(require("fs-extra")); | ||
| const path = __importStar(require("path")); | ||
| const plist_1 = __importDefault(require("plist")); | ||
| const util_1 = require("./util"); | ||
| class ProvisioningProfile { | ||
| constructor(filePath, message) { | ||
| this.filePath = filePath; | ||
| this.message = message; | ||
| } | ||
| get name() { | ||
| return this.message.Name; | ||
| } | ||
| get platforms() { | ||
| if ('ProvisionsAllDevices' in this.message) | ||
| return ['darwin']; | ||
| // Developer ID | ||
| else if (this.type === 'distribution') | ||
| return ['mas']; | ||
| // Mac App Store | ||
| else | ||
| return ['darwin', 'mas']; // Mac App Development | ||
| } | ||
| get type() { | ||
| if ('ProvisionedDevices' in this.message) | ||
| return 'development'; | ||
| // Mac App Development | ||
| else | ||
| return 'distribution'; // Developer ID or Mac App Store | ||
| } | ||
| } | ||
| exports.ProvisioningProfile = ProvisioningProfile; | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| async function getProvisioningProfile(filePath, keychain = null) { | ||
| const securityArgs = [ | ||
| 'cms', | ||
| '-D', | ||
| '-i', | ||
| filePath // Use infile as source of data | ||
| ]; | ||
| if (keychain) { | ||
| securityArgs.push('-k', keychain); | ||
| } | ||
| const result = await (0, util_1.execFileAsync)('security', securityArgs); | ||
| const provisioningProfile = new ProvisioningProfile(filePath, plist_1.default.parse(result)); | ||
| (0, util_1.debugLog)('Provisioning profile:', '\n', '> Name:', provisioningProfile.name, '\n', '> Platforms:', provisioningProfile.platforms, '\n', '> Type:', provisioningProfile.type, '\n', '> Path:', provisioningProfile.filePath, '\n', '> Message:', provisioningProfile.message); | ||
| return provisioningProfile; | ||
| } | ||
| exports.getProvisioningProfile = getProvisioningProfile; | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| async function findProvisioningProfiles(opts) { | ||
| const cwd = process.cwd(); | ||
| const children = await fs.readdir(cwd); | ||
| const foundProfiles = (0, util_1.compactFlattenedList)(await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(cwd, child); | ||
| const stat = await fs.stat(filePath); | ||
| if (stat.isFile() && path.extname(filePath) === '.provisionprofile') { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| }))); | ||
| return (0, util_1.compactFlattenedList)(await Promise.all(foundProfiles.map(async (filePath) => { | ||
| const profile = await getProvisioningProfile(filePath); | ||
| if (profile.platforms.indexOf(opts.platform) >= 0 && profile.type === opts.type) { | ||
| return profile; | ||
| } | ||
| (0, util_1.debugWarn)('Provisioning profile above ignored, not for ' + opts.platform + ' ' + opts.type + '.'); | ||
| return null; | ||
| }))); | ||
| } | ||
| exports.findProvisioningProfiles = findProvisioningProfiles; | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| async function preEmbedProvisioningProfile(opts, profile) { | ||
| async function embedProvisioningProfile(profile) { | ||
| (0, util_1.debugLog)('Looking for existing provisioning profile...'); | ||
| const embeddedFilePath = path.join((0, util_1.getAppContentsPath)(opts), 'embedded.provisionprofile'); | ||
| if (await fs.pathExists(embeddedFilePath)) { | ||
| (0, util_1.debugLog)('Found embedded provisioning profile:', '\n', '* Please manually remove the existing file if not wanted.', '\n', '* Current file at:', embeddedFilePath); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Embedding provisioning profile...'); | ||
| await fs.copy(profile.filePath, embeddedFilePath); | ||
| } | ||
| } | ||
| if (profile) { | ||
| // User input provisioning profile | ||
| return await embedProvisioningProfile(profile); | ||
| } | ||
| else { | ||
| // Discover provisioning profile | ||
| (0, util_1.debugLog)('No `provisioning-profile` passed in arguments, will find in current working directory and in user library...'); | ||
| const profiles = await findProvisioningProfiles(opts); | ||
| if (profiles.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (profiles.length > 1) { | ||
| (0, util_1.debugLog)('Multiple provisioning profiles found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| (0, util_1.debugLog)('Found 1 provisioning profile.'); | ||
| } | ||
| await embedProvisioningProfile(profiles[0]); | ||
| } | ||
| else { | ||
| // No provisioning profile found | ||
| (0, util_1.debugLog)('No provisioning profile found, will not embed profile in app contents.'); | ||
| } | ||
| } | ||
| } | ||
| exports.preEmbedProvisioningProfile = preEmbedProvisioningProfile; | ||
| //# sourceMappingURL=util-provisioning-profiles.js.map |
| {"version":3,"file":"util-provisioning-profiles.js","sourceRoot":"","sources":["../../src/util-provisioning-profiles.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAAA,6CAA+B;AAC/B,2CAA6B;AAC7B,kDAA0B;AAG1B,iCAAsG;AAEtG,MAAa,mBAAmB;IAC9B,YAAoB,QAAgB,EAAS,OAAY;QAArC,aAAQ,GAAR,QAAQ,CAAQ;QAAS,YAAO,GAAP,OAAO,CAAK;IAAG,CAAC;IAE7D,IAAI,IAAI;QACN,OAAO,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC;IAC3B,CAAC;IAED,IAAI,SAAS;QACX,IAAI,sBAAsB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,CAAC,QAAQ,CAAC,CAAC;QAC9D,eAAe;aACV,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc;YAAE,OAAO,CAAC,KAAK,CAAC,CAAC;QACtD,gBAAgB;;YACX,OAAO,CAAC,QAAQ,EAAE,KAAK,CAAC,CAAC,CAAC,sBAAsB;IACvD,CAAC;IAED,IAAI,IAAI;QACN,IAAI,oBAAoB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,aAAa,CAAC;QAC/D,sBAAsB;;YACjB,OAAO,cAAc,CAAC,CAAC,gCAAgC;IAC9D,CAAC;CACF;AApBD,kDAoBC;AAED;;;;;;GAMG;AACI,KAAK,UAAU,sBAAsB,CAAE,QAAgB,EAAE,WAA0B,IAAI;IAC5F,MAAM,YAAY,GAAG;QACnB,KAAK;QACL,IAAI;QACJ,IAAI;QACJ,QAAQ,CAAC,+BAA+B;KACzC,CAAC;IAEF,IAAI,QAAQ,EAAE;QACZ,YAAY,CAAC,IAAI,CAAC,IAAI,EAAE,QAAQ,CAAC,CAAC;KACnC;IAED,MAAM,MAAM,GAAG,MAAM,IAAA,oBAAa,EAAC,UAAU,EAAE,YAAY,CAAC,CAAC;IAC7D,MAAM,mBAAmB,GAAG,IAAI,mBAAmB,CAAC,QAAQ,EAAE,eAAK,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC,CAAC;IACnF,IAAA,eAAQ,EACN,uBAAuB,EACvB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,cAAc,EACd,mBAAmB,CAAC,SAAS,EAC7B,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,QAAQ,EAC5B,IAAI,EACJ,YAAY,EACZ,mBAAmB,CAAC,OAAO,CAC5B,CAAC;IACF,OAAO,mBAAmB,CAAC;AAC7B,CAAC;AAjCD,wDAiCC;AAED;;GAEG;AACI,KAAK,UAAU,wBAAwB,CAAE,IAA0B;IACxE,MAAM,GAAG,GAAG,OAAO,CAAC,GAAG,EAAE,CAAC;IAC1B,MAAM,QAAQ,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,GAAG,CAAC,CAAC;IACvC,MAAM,aAAa,GAAG,IAAA,2BAAoB,EACxC,MAAM,OAAO,CAAC,GAAG,CACf,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;QAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,GAAG,EAAE,KAAK,CAAC,CAAC;QAC1C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;QACrC,IAAI,IAAI,CAAC,MAAM,EAAE,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,KAAK,mBAAmB,EAAE;YACnE,OAAO,QAAQ,CAAC;SACjB;QACD,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;IAEF,OAAO,IAAA,2BAAoB,EACzB,MAAM,OAAO,CAAC,GAAG,CACf,aAAa,CAAC,GAAG,CAAC,KAAK,EAAE,QAAQ,EAAE,EAAE;QACnC,MAAM,OAAO,GAAG,MAAM,sBAAsB,CAAC,QAAQ,CAAC,CAAC;QACvD,IAAI,OAAO,CAAC,SAAS,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,IAAI,OAAO,CAAC,IAAI,KAAK,IAAI,CAAC,IAAI,EAAE;YAAE,OAAO,OAAO,CAAC;SAAE;QACpG,IAAA,gBAAS,EACP,8CAA8C,GAAG,IAAI,CAAC,QAAQ,GAAG,GAAG,GAAG,IAAI,CAAC,IAAI,GAAG,GAAG,CACvF,CAAC;QACF,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;AACJ,CAAC;AA5BD,4DA4BC;AAED;;GAEG;AACI,KAAK,UAAU,2BAA2B,CAAE,IAA0B,EAAE,OAAmC;IAChH,KAAK,UAAU,wBAAwB,CAAE,OAA4B;QACnE,IAAA,eAAQ,EAAC,8CAA8C,CAAC,CAAC;QACzD,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,IAAA,yBAAkB,EAAC,IAAI,CAAC,EAAE,2BAA2B,CAAC,CAAC;QAE1F,IAAI,MAAM,EAAE,CAAC,UAAU,CAAC,gBAAgB,CAAC,EAAE;YACzC,IAAA,eAAQ,EACN,sCAAsC,EACtC,IAAI,EACJ,2DAA2D,EAC3D,IAAI,EACJ,oBAAoB,EACpB,gBAAgB,CACjB,CAAC;SACH;aAAM;YACL,IAAA,eAAQ,EAAC,mCAAmC,CAAC,CAAC;YAC9C,MAAM,EAAE,CAAC,IAAI,CAAC,OAAO,CAAC,QAAQ,EAAE,gBAAgB,CAAC,CAAC;SACnD;IACH,CAAC;IAED,IAAI,OAAO,EAAE;QACX,kCAAkC;QAClC,OAAO,MAAM,wBAAwB,CAAC,OAAO,CAAC,CAAC;KAChD;SAAM;QACL,gCAAgC;QAChC,IAAA,eAAQ,EACN,8GAA8G,CAC/G,CAAC;QACF,MAAM,QAAQ,GAAG,MAAM,wBAAwB,CAAC,IAAI,CAAC,CAAC;QACtD,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE;YACvB,gCAAgC;YAChC,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE;gBACvB,IAAA,eAAQ,EAAC,sEAAsE,CAAC,CAAC;aAClF;iBAAM;gBACL,IAAA,eAAQ,EAAC,+BAA+B,CAAC,CAAC;aAC3C;YACD,MAAM,wBAAwB,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,CAAC;SAC7C;aAAM;YACL,gCAAgC;YAChC,IAAA,eAAQ,EAAC,wEAAwE,CAAC,CAAC;SACpF;KACF;AACH,CAAC;AA1CD,kEA0CC"} |
| /// <reference types="node" /> | ||
| import * as child from 'child_process'; | ||
| import debug from 'debug'; | ||
| import { BaseSignOptions, ElectronMacPlatform } from './types'; | ||
| export declare const debugLog: debug.Debugger; | ||
| export declare const debugWarn: debug.Debugger; | ||
| export declare function execFileAsync(file: string, args: string[], options?: child.ExecFileOptions): Promise<string>; | ||
| type DeepListItem<T> = null | T | DeepListItem<T>[]; | ||
| type DeepList<T> = DeepListItem<T>[]; | ||
| export declare function compactFlattenedList<T>(list: DeepList<T>): T[]; | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| export declare function getAppContentsPath(opts: BaseSignOptions): string; | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| export declare function getAppFrameworksPath(opts: BaseSignOptions): string; | ||
| export declare function detectElectronPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| export declare function validateOptsApp(opts: BaseSignOptions): Promise<void>; | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| export declare function validateOptsPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| export declare function walkAsync(dirPath: string): Promise<string[]>; | ||
| export {}; |
-183
| "use strict"; | ||
| var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| var desc = Object.getOwnPropertyDescriptor(m, k); | ||
| if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { | ||
| desc = { enumerable: true, get: function() { return m[k]; } }; | ||
| } | ||
| Object.defineProperty(o, k2, desc); | ||
| }) : (function(o, m, k, k2) { | ||
| if (k2 === undefined) k2 = k; | ||
| o[k2] = m[k]; | ||
| })); | ||
| var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { | ||
| Object.defineProperty(o, "default", { enumerable: true, value: v }); | ||
| }) : function(o, v) { | ||
| o["default"] = v; | ||
| }); | ||
| var __importStar = (this && this.__importStar) || function (mod) { | ||
| if (mod && mod.__esModule) return mod; | ||
| var result = {}; | ||
| if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k); | ||
| __setModuleDefault(result, mod); | ||
| return result; | ||
| }; | ||
| var __importDefault = (this && this.__importDefault) || function (mod) { | ||
| return (mod && mod.__esModule) ? mod : { "default": mod }; | ||
| }; | ||
| Object.defineProperty(exports, "__esModule", { value: true }); | ||
| exports.walkAsync = exports.validateOptsPlatform = exports.validateOptsApp = exports.detectElectronPlatform = exports.getAppFrameworksPath = exports.getAppContentsPath = exports.compactFlattenedList = exports.execFileAsync = exports.debugWarn = exports.debugLog = void 0; | ||
| const child = __importStar(require("child_process")); | ||
| const fs = __importStar(require("fs-extra")); | ||
| const isbinaryfile_1 = require("isbinaryfile"); | ||
| const path = __importStar(require("path")); | ||
| const debug_1 = __importDefault(require("debug")); | ||
| exports.debugLog = (0, debug_1.default)('electron-osx-sign'); | ||
| exports.debugLog.log = console.log.bind(console); | ||
| exports.debugWarn = (0, debug_1.default)('electron-osx-sign:warn'); | ||
| exports.debugWarn.log = console.warn.bind(console); | ||
| const removePassword = function (input) { | ||
| return input.replace(/(-P |pass:|\/p|-pass )([^ ]+)/, function (_, p1) { | ||
| return `${p1}***`; | ||
| }); | ||
| }; | ||
| async function execFileAsync(file, args, options = {}) { | ||
| if (exports.debugLog.enabled) { | ||
| (0, exports.debugLog)('Executing...', file, args && Array.isArray(args) ? removePassword(args.join(' ')) : ''); | ||
| } | ||
| return new Promise(function (resolve, reject) { | ||
| child.execFile(file, args, options, function (err, stdout, stderr) { | ||
| if (err) { | ||
| (0, exports.debugLog)('Error executing file:', '\n', '> Stdout:', stdout, '\n', '> Stderr:', stderr); | ||
| reject(err); | ||
| return; | ||
| } | ||
| resolve(stdout); | ||
| }); | ||
| }); | ||
| } | ||
| exports.execFileAsync = execFileAsync; | ||
| function compactFlattenedList(list) { | ||
| const result = []; | ||
| function populateResult(list) { | ||
| if (!Array.isArray(list)) { | ||
| if (list) | ||
| result.push(list); | ||
| } | ||
| else if (list.length > 0) { | ||
| for (const item of list) | ||
| if (item) | ||
| populateResult(item); | ||
| } | ||
| } | ||
| populateResult(list); | ||
| return result; | ||
| } | ||
| exports.compactFlattenedList = compactFlattenedList; | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| function getAppContentsPath(opts) { | ||
| return path.join(opts.app, 'Contents'); | ||
| } | ||
| exports.getAppContentsPath = getAppContentsPath; | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| function getAppFrameworksPath(opts) { | ||
| return path.join(getAppContentsPath(opts), 'Frameworks'); | ||
| } | ||
| exports.getAppFrameworksPath = getAppFrameworksPath; | ||
| async function detectElectronPlatform(opts) { | ||
| const appFrameworksPath = getAppFrameworksPath(opts); | ||
| if (await fs.pathExists(path.resolve(appFrameworksPath, 'Squirrel.framework'))) { | ||
| return 'darwin'; | ||
| } | ||
| else { | ||
| return 'mas'; | ||
| } | ||
| } | ||
| exports.detectElectronPlatform = detectElectronPlatform; | ||
| /** | ||
| * This function returns a promise resolving the file path if file binary. | ||
| */ | ||
| async function getFilePathIfBinary(filePath) { | ||
| if (await (0, isbinaryfile_1.isBinaryFile)(filePath)) { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| } | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| async function validateOptsApp(opts) { | ||
| if (!opts.app) { | ||
| throw new Error('Path to application must be specified.'); | ||
| } | ||
| if (path.extname(opts.app) !== '.app') { | ||
| throw new Error('Extension of application must be `.app`.'); | ||
| } | ||
| if (!(await fs.pathExists(opts.app))) { | ||
| throw new Error(`Application at path "${opts.app}" could not be found`); | ||
| } | ||
| } | ||
| exports.validateOptsApp = validateOptsApp; | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| async function validateOptsPlatform(opts) { | ||
| if (opts.platform) { | ||
| if (opts.platform === 'mas' || opts.platform === 'darwin') { | ||
| return opts.platform; | ||
| } | ||
| else { | ||
| (0, exports.debugWarn)('`platform` passed in arguments not supported, checking Electron platform...'); | ||
| } | ||
| } | ||
| else { | ||
| (0, exports.debugWarn)('No `platform` passed in arguments, checking Electron platform...'); | ||
| } | ||
| return await detectElectronPlatform(opts); | ||
| } | ||
| exports.validateOptsPlatform = validateOptsPlatform; | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| async function walkAsync(dirPath) { | ||
| (0, exports.debugLog)('Walking... ' + dirPath); | ||
| async function _walkAsync(dirPath) { | ||
| const children = await fs.readdir(dirPath); | ||
| return await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(dirPath, child); | ||
| const stat = await fs.stat(filePath); | ||
| if (stat.isFile()) { | ||
| switch (path.extname(filePath)) { | ||
| case '.cstemp': // Temporary file generated from past codesign | ||
| (0, exports.debugLog)('Removing... ' + filePath); | ||
| await fs.remove(filePath); | ||
| return null; | ||
| default: | ||
| return await getFilePathIfBinary(filePath); | ||
| } | ||
| } | ||
| else if (stat.isDirectory() && !stat.isSymbolicLink()) { | ||
| const walkResult = await _walkAsync(filePath); | ||
| switch (path.extname(filePath)) { | ||
| case '.app': // Application | ||
| case '.framework': // Framework | ||
| walkResult.push(filePath); | ||
| } | ||
| return walkResult; | ||
| } | ||
| return null; | ||
| })); | ||
| } | ||
| const allPaths = await _walkAsync(dirPath); | ||
| return compactFlattenedList(allPaths); | ||
| } | ||
| exports.walkAsync = walkAsync; | ||
| //# sourceMappingURL=util.js.map |
| {"version":3,"file":"util.js","sourceRoot":"","sources":["../../src/util.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAAA,qDAAuC;AACvC,6CAA+B;AAC/B,+CAA4C;AAC5C,2CAA6B;AAE7B,kDAA0B;AAGb,QAAA,QAAQ,GAAG,IAAA,eAAK,EAAC,mBAAmB,CAAC,CAAC;AACnD,gBAAQ,CAAC,GAAG,GAAG,OAAO,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAE5B,QAAA,SAAS,GAAG,IAAA,eAAK,EAAC,wBAAwB,CAAC,CAAC;AACzD,iBAAS,CAAC,GAAG,GAAG,OAAO,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAE3C,MAAM,cAAc,GAAG,UAAU,KAAa;IAC5C,OAAO,KAAK,CAAC,OAAO,CAAC,+BAA+B,EAAE,UAAU,CAAC,EAAE,EAAE;QACnE,OAAO,GAAG,EAAE,KAAK,CAAC;IACpB,CAAC,CAAC,CAAC;AACL,CAAC,CAAC;AAEK,KAAK,UAAU,aAAa,CACjC,IAAY,EACZ,IAAc,EACd,UAAiC,EAAE;IAEnC,IAAI,gBAAQ,CAAC,OAAO,EAAE;QACpB,IAAA,gBAAQ,EACN,cAAc,EACd,IAAI,EACJ,IAAI,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,CAAC,CAAC,CAAC,cAAc,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC,CAAC,CAAC,EAAE,CAClE,CAAC;KACH;IAED,OAAO,IAAI,OAAO,CAAC,UAAU,OAAO,EAAE,MAAM;QAC1C,KAAK,CAAC,QAAQ,CAAC,IAAI,EAAE,IAAI,EAAE,OAAO,EAAE,UAAU,GAAG,EAAE,MAAM,EAAE,MAAM;YAC/D,IAAI,GAAG,EAAE;gBACP,IAAA,gBAAQ,EAAC,uBAAuB,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,CAAC,CAAC;gBACxF,MAAM,CAAC,GAAG,CAAC,CAAC;gBACZ,OAAO;aACR;YACD,OAAO,CAAC,MAAM,CAAC,CAAC;QAClB,CAAC,CAAC,CAAC;IACL,CAAC,CAAC,CAAC;AACL,CAAC;AAvBD,sCAuBC;AAKD,SAAgB,oBAAoB,CAAK,IAAiB;IACxD,MAAM,MAAM,GAAQ,EAAE,CAAC;IAEvB,SAAS,cAAc,CAAE,IAAqB;QAC5C,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,EAAE;YACxB,IAAI,IAAI;gBAAE,MAAM,CAAC,IAAI,CAAC,IAAI,CAAC,CAAC;SAC7B;aAAM,IAAI,IAAI,CAAC,MAAM,GAAG,CAAC,EAAE;YAC1B,KAAK,MAAM,IAAI,IAAI,IAAI;gBAAE,IAAI,IAAI;oBAAE,cAAc,CAAC,IAAI,CAAC,CAAC;SACzD;IACH,CAAC;IAED,cAAc,CAAC,IAAI,CAAC,CAAC;IACrB,OAAO,MAAM,CAAC;AAChB,CAAC;AAbD,oDAaC;AAED;;GAEG;AACH,SAAgB,kBAAkB,CAAE,IAAqB;IACvD,OAAO,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,UAAU,CAAC,CAAC;AACzC,CAAC;AAFD,gDAEC;AAED;;GAEG;AACH,SAAgB,oBAAoB,CAAE,IAAqB;IACzD,OAAO,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;AAC3D,CAAC;AAFD,oDAEC;AAEM,KAAK,UAAU,sBAAsB,CAAE,IAAqB;IACjE,MAAM,iBAAiB,GAAG,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACrD,IAAI,MAAM,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,OAAO,CAAC,iBAAiB,EAAE,oBAAoB,CAAC,CAAC,EAAE;QAC9E,OAAO,QAAQ,CAAC;KACjB;SAAM;QACL,OAAO,KAAK,CAAC;KACd;AACH,CAAC;AAPD,wDAOC;AAED;;GAEG;AACH,KAAK,UAAU,mBAAmB,CAAE,QAAgB;IAClD,IAAI,MAAM,IAAA,2BAAY,EAAC,QAAQ,CAAC,EAAE;QAChC,OAAO,QAAQ,CAAC;KACjB;IACD,OAAO,IAAI,CAAC;AACd,CAAC;AAED;;GAEG;AACI,KAAK,UAAU,eAAe,CAAE,IAAqB;IAC1D,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE;QACb,MAAM,IAAI,KAAK,CAAC,wCAAwC,CAAC,CAAC;KAC3D;IACD,IAAI,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE;QACrC,MAAM,IAAI,KAAK,CAAC,0CAA0C,CAAC,CAAC;KAC7D;IACD,IAAI,CAAC,CAAC,MAAM,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,EAAE;QACpC,MAAM,IAAI,KAAK,CAAC,wBAAwB,IAAI,CAAC,GAAG,sBAAsB,CAAC,CAAC;KACzE;AACH,CAAC;AAVD,0CAUC;AAED;;GAEG;AACI,KAAK,UAAU,oBAAoB,CAAE,IAAqB;IAC/D,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,IAAI,IAAI,CAAC,QAAQ,KAAK,QAAQ,EAAE;YACzD,OAAO,IAAI,CAAC,QAAQ,CAAC;SACtB;aAAM;YACL,IAAA,iBAAS,EAAC,6EAA6E,CAAC,CAAC;SAC1F;KACF;SAAM;QACL,IAAA,iBAAS,EAAC,kEAAkE,CAAC,CAAC;KAC/E;IAED,OAAO,MAAM,sBAAsB,CAAC,IAAI,CAAC,CAAC;AAC5C,CAAC;AAZD,oDAYC;AAED;;;;;;GAMG;AACI,KAAK,UAAU,SAAS,CAAE,OAAe;IAC9C,IAAA,gBAAQ,EAAC,aAAa,GAAG,OAAO,CAAC,CAAC;IAElC,KAAK,UAAU,UAAU,CAAE,OAAe;QACxC,MAAM,QAAQ,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,OAAO,CAAC,CAAC;QAC3C,OAAO,MAAM,OAAO,CAAC,GAAG,CACtB,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;YAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,OAAO,EAAE,KAAK,CAAC,CAAC;YAE9C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;YACrC,IAAI,IAAI,CAAC,MAAM,EAAE,EAAE;gBACjB,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE;oBAC9B,KAAK,SAAS,EAAE,8CAA8C;wBAC5D,IAAA,gBAAQ,EAAC,cAAc,GAAG,QAAQ,CAAC,CAAC;wBACpC,MAAM,EAAE,CAAC,MAAM,CAAC,QAAQ,CAAC,CAAC;wBAC1B,OAAO,IAAI,CAAC;oBACd;wBACE,OAAO,MAAM,mBAAmB,CAAC,QAAQ,CAAC,CAAC;iBAC9C;aACF;iBAAM,IAAI,IAAI,CAAC,WAAW,EAAE,IAAI,CAAC,IAAI,CAAC,cAAc,EAAE,EAAE;gBACvD,MAAM,UAAU,GAAG,MAAM,UAAU,CAAC,QAAQ,CAAC,CAAC;gBAC9C,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE;oBAC9B,KAAK,MAAM,CAAC,CAAC,cAAc;oBAC3B,KAAK,YAAY,EAAE,YAAY;wBAC7B,UAAU,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;iBAC7B;gBACD,OAAO,UAAU,CAAC;aACnB;YACD,OAAO,IAAI,CAAC;QACd,CAAC,CAAC,CACH,CAAC;IACJ,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,UAAU,CAAC,OAAO,CAAC,CAAC;IAC3C,OAAO,oBAAoB,CAAC,QAAQ,CAAC,CAAC;AACxC,CAAC;AAnCD,8BAmCC"} |
| import { FlatOptions } from './types'; | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| export declare function buildPkg(_opts: FlatOptions): Promise<void>; | ||
| /** | ||
| * This function is exported with normal callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link flatAsync} method instead. | ||
| * @category Flat | ||
| */ | ||
| export declare const flat: (opts: FlatOptions, cb?: ((error?: Error) => void) | undefined) => void; |
-151
| import * as path from 'path'; | ||
| import { debugLog, debugWarn, execFileAsync, validateOptsApp, validateOptsPlatform } from './util'; | ||
| import { findIdentities } from './util-identities'; | ||
| const pkgVersion = require('../../package.json').version; | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| * @function | ||
| * @param {Object} opts - Options. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| async function validateFlatOpts(opts) { | ||
| await validateOptsApp(opts); | ||
| let pkg = opts.pkg; | ||
| if (pkg) { | ||
| if (typeof pkg !== 'string') | ||
| throw new Error('`pkg` must be a string.'); | ||
| if (path.extname(pkg) !== '.pkg') { | ||
| throw new Error('Extension of output package must be `.pkg`.'); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `pkg` passed in arguments, will fallback to default inferred from the given application.'); | ||
| pkg = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '.pkg'); | ||
| } | ||
| let install = opts.install; | ||
| if (install) { | ||
| if (typeof install !== 'string') { | ||
| return Promise.reject(new Error('`install` must be a string.')); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `install` passed in arguments, will fallback to default `/Applications`.'); | ||
| install = '/Applications'; | ||
| } | ||
| if (typeof opts.scripts === 'string' && opts.platform === 'mas') { | ||
| debugWarn('Mac App Store packages cannot have `scripts`, ignoring option.'); | ||
| } | ||
| return Object.assign(Object.assign({}, opts), { pkg, | ||
| install, platform: await validateOptsPlatform(opts) }); | ||
| } | ||
| /** | ||
| * This function returns a promise flattening the application. | ||
| * @param opts - Options for building the .pkg archive | ||
| */ | ||
| async function buildApplicationPkg(opts, identity) { | ||
| if (opts.platform === 'mas') { | ||
| const args = ['--component', opts.app, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| debugLog('Flattening Mac App Store package... ' + opts.app); | ||
| await execFileAsync('productbuild', args); | ||
| } | ||
| else { | ||
| const componentPkgPath = path.join(path.dirname(opts.app), path.basename(opts.app, '.app') + '-component.pkg'); | ||
| const pkgbuildArgs = [ | ||
| '--install-location', | ||
| opts.install, | ||
| '--component', | ||
| opts.app, | ||
| componentPkgPath | ||
| ]; | ||
| if (opts.scripts) { | ||
| pkgbuildArgs.unshift('--scripts', opts.scripts); | ||
| } | ||
| debugLog('Building component package... ' + opts.app); | ||
| await execFileAsync('pkgbuild', pkgbuildArgs); | ||
| const args = ['--package', componentPkgPath, opts.install, '--sign', identity.name, opts.pkg]; | ||
| if (opts.keychain) { | ||
| args.unshift('--keychain', opts.keychain); | ||
| } | ||
| debugLog('Flattening OS X Installer package... ' + opts.app); | ||
| await execFileAsync('productbuild', args); | ||
| await execFileAsync('rm', [componentPkgPath]); | ||
| } | ||
| } | ||
| /** | ||
| * Generates a flat `.pkg` installer for a packaged Electron `.app` bundle. | ||
| * @returns A void Promise once the flattening operation is complete. | ||
| * | ||
| * @category Flat | ||
| */ | ||
| export async function buildPkg(_opts) { | ||
| debugLog('@electron/osx-sign@%s', pkgVersion); | ||
| const validatedOptions = await validateFlatOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| if (validatedOptions.identity) { | ||
| debugLog('`identity` passed in arguments.'); | ||
| if (validatedOptions.identityValidation === false) { | ||
| // Do nothing | ||
| } | ||
| else { | ||
| identities = await findIdentities(validatedOptions.keychain || null, validatedOptions.identity); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `identity` passed in arguments...'); | ||
| if (validatedOptions.platform === 'mas') { | ||
| debugLog('Finding `3rd Party Mac Developer Installer` certificate for flattening app distribution in the Mac App Store...'); | ||
| identities = await findIdentities(validatedOptions.keychain || null, '3rd Party Mac Developer Installer:'); | ||
| } | ||
| else { | ||
| debugLog('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await findIdentities(validatedOptions.keychain || null, 'Developer ID Installer:'); | ||
| } | ||
| } | ||
| if (identities.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (identities.length > 1) { | ||
| debugWarn('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| debugLog('Flattening application...', '\n', '> Application:', validatedOptions.app, '\n', '> Package output:', validatedOptions.pkg, '\n', '> Install path:', validatedOptions.install, '\n', '> Identity:', validatedOptions.identity, '\n', '> Scripts:', validatedOptions.scripts); | ||
| await buildApplicationPkg(validatedOptions, identityInUse); | ||
| debugLog('Application flattened.'); | ||
| } | ||
| /** | ||
| * This function is exported with normal callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link flatAsync} method instead. | ||
| * @category Flat | ||
| */ | ||
| export const flat = (opts, cb) => { | ||
| buildPkg(opts) | ||
| .then(() => { | ||
| debugLog('Application flattened, saved to: ' + opts.app); | ||
| if (cb) | ||
| cb(); | ||
| }) | ||
| .catch((err) => { | ||
| debugLog('Flat failed:'); | ||
| if (err.message) | ||
| debugLog(err.message); | ||
| else if (err.stack) | ||
| debugLog(err.stack); | ||
| else | ||
| debugLog(err); | ||
| if (cb) | ||
| cb(err); | ||
| }); | ||
| }; | ||
| //# sourceMappingURL=flat.js.map |
| {"version":3,"file":"flat.js","sourceRoot":"","sources":["../../src/flat.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,IAAI,MAAM,MAAM,CAAC;AAC7B,OAAO,EAAE,QAAQ,EAAE,SAAS,EAAE,aAAa,EAAE,eAAe,EAAE,oBAAoB,EAAE,MAAM,QAAQ,CAAC;AAEnG,OAAO,EAAY,cAAc,EAAE,MAAM,mBAAmB,CAAC;AAI7D,MAAM,UAAU,GAAG,OAAO,CAAC,oBAAoB,CAAC,CAAC,OAAiB,CAAC;AAEnE;;;;;GAKG;AACH,KAAK,UAAU,gBAAgB,CAAE,IAAiB;IAChD,MAAM,eAAe,CAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,GAAG,GAAG,IAAI,CAAC,GAAG,CAAC;IACnB,IAAI,GAAG,EAAE;QACP,IAAI,OAAO,GAAG,KAAK,QAAQ;YAAE,MAAM,IAAI,KAAK,CAAC,yBAAyB,CAAC,CAAC;QACxE,IAAI,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE;YAChC,MAAM,IAAI,KAAK,CAAC,6CAA6C,CAAC,CAAC;SAChE;KACF;SAAM;QACL,SAAS,CACP,6FAA6F,CAC9F,CAAC;QACF,GAAG,GAAG,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,MAAM,CAAC,CAAC;KACnF;IAED,IAAI,OAAO,GAAG,IAAI,CAAC,OAAO,CAAC;IAC3B,IAAI,OAAO,EAAE;QACX,IAAI,OAAO,OAAO,KAAK,QAAQ,EAAE;YAC/B,OAAO,OAAO,CAAC,MAAM,CAAC,IAAI,KAAK,CAAC,6BAA6B,CAAC,CAAC,CAAC;SACjE;KACF;SAAM;QACL,SAAS,CAAC,6EAA6E,CAAC,CAAC;QACzF,OAAO,GAAG,eAAe,CAAC;KAC3B;IAED,IAAI,OAAO,IAAI,CAAC,OAAO,KAAK,QAAQ,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE;QAC/D,SAAS,CAAC,gEAAgE,CAAC,CAAC;KAC7E;IAED,uCACK,IAAI,KACP,GAAG;QACH,OAAO,EACP,QAAQ,EAAE,MAAM,oBAAoB,CAAC,IAAI,CAAC,IAC1C;AACJ,CAAC;AAED;;;GAGG;AACH,KAAK,UAAU,mBAAmB,CAAE,IAA0B,EAAE,QAAkB;IAChF,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,EAAE;QAC3B,MAAM,IAAI,GAAG,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QACxF,IAAI,IAAI,CAAC,QAAQ,EAAE;YACjB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;SAC3C;QAED,QAAQ,CAAC,sCAAsC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC5D,MAAM,aAAa,CAAC,cAAc,EAAE,IAAI,CAAC,CAAC;KAC3C;SAAM;QACL,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAChC,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,EACtB,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,GAAG,EAAE,MAAM,CAAC,GAAG,gBAAgB,CACnD,CAAC;QACF,MAAM,YAAY,GAAG;YACnB,oBAAoB;YACpB,IAAI,CAAC,OAAO;YACZ,aAAa;YACb,IAAI,CAAC,GAAG;YACR,gBAAgB;SACjB,CAAC;QACF,IAAI,IAAI,CAAC,OAAO,EAAE;YAChB,YAAY,CAAC,OAAO,CAAC,WAAW,EAAE,IAAI,CAAC,OAAO,CAAC,CAAC;SACjD;QACD,QAAQ,CAAC,gCAAgC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QACtD,MAAM,aAAa,CAAC,UAAU,EAAE,YAAY,CAAC,CAAC;QAE9C,MAAM,IAAI,GAAG,CAAC,WAAW,EAAE,gBAAgB,EAAE,IAAI,CAAC,OAAO,EAAE,QAAQ,EAAE,QAAQ,CAAC,IAAI,EAAE,IAAI,CAAC,GAAG,CAAC,CAAC;QAC9F,IAAI,IAAI,CAAC,QAAQ,EAAE;YACjB,IAAI,CAAC,OAAO,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;SAC3C;QAED,QAAQ,CAAC,uCAAuC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC7D,MAAM,aAAa,CAAC,cAAc,EAAE,IAAI,CAAC,CAAC;QAC1C,MAAM,aAAa,CAAC,IAAI,EAAE,CAAC,gBAAgB,CAAC,CAAC,CAAC;KAC/C;AACH,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,KAAK,UAAU,QAAQ,CAAE,KAAkB;IAChD,QAAQ,CAAC,uBAAuB,EAAE,UAAU,CAAC,CAAC;IAC9C,MAAM,gBAAgB,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACvD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,IAAI,gBAAgB,CAAC,QAAQ,EAAE;QAC7B,QAAQ,CAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,gBAAgB,CAAC,kBAAkB,KAAK,KAAK,EAAE;YACjD,aAAa;SACd;aAAM;YACL,UAAU,GAAG,MAAM,cAAc,CAAC,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EAAE,gBAAgB,CAAC,QAAQ,CAAC,CAAC;SACjG;KACF;SAAM;QACL,SAAS,CAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,gBAAgB,CAAC,QAAQ,KAAK,KAAK,EAAE;YACvC,QAAQ,CACN,iHAAiH,CAClH,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,oCAAoC,CACrC,CAAC;SACH;aAAM;YACL,QAAQ,CACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,gBAAgB,CAAC,QAAQ,IAAI,IAAI,EACjC,yBAAyB,CAC1B,CAAC;SACH;KACF;IAED,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;QACzB,gCAAgC;QAChC,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;YACzB,SAAS,CAAC,2DAA2D,CAAC,CAAC;SACxE;aAAM;YACL,QAAQ,CAAC,mBAAmB,CAAC,CAAC;SAC/B;QACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;KAC/B;SAAM;QACL,oBAAoB;QACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;KACnD;IAED,QAAQ,CACN,2BAA2B,EAC3B,IAAI,EACJ,gBAAgB,EAChB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,mBAAmB,EACnB,gBAAgB,CAAC,GAAG,EACpB,IAAI,EACJ,iBAAiB,EACjB,gBAAgB,CAAC,OAAO,EACxB,IAAI,EACJ,aAAa,EACb,gBAAgB,CAAC,QAAQ,EACzB,IAAI,EACJ,YAAY,EACZ,gBAAgB,CAAC,OAAO,CACzB,CAAC;IACF,MAAM,mBAAmB,CAAC,gBAAgB,EAAE,aAAa,CAAC,CAAC;IAE3D,QAAQ,CAAC,wBAAwB,CAAC,CAAC;AACrC,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,MAAM,IAAI,GAAG,CAAC,IAAiB,EAAE,EAA4B,EAAE,EAAE;IACtE,QAAQ,CAAC,IAAI,CAAC;SACX,IAAI,CAAC,GAAG,EAAE;QACT,QAAQ,CAAC,mCAAmC,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QACzD,IAAI,EAAE;YAAE,EAAE,EAAE,CAAC;IACf,CAAC,CAAC;SACD,KAAK,CAAC,CAAC,GAAG,EAAE,EAAE;QACb,QAAQ,CAAC,cAAc,CAAC,CAAC;QACzB,IAAI,GAAG,CAAC,OAAO;YAAE,QAAQ,CAAC,GAAG,CAAC,OAAO,CAAC,CAAC;aAClC,IAAI,GAAG,CAAC,KAAK;YAAE,QAAQ,CAAC,GAAG,CAAC,KAAK,CAAC,CAAC;;YACnC,QAAQ,CAAC,GAAG,CAAC,CAAC;QACnB,IAAI,EAAE;YAAE,EAAE,CAAC,GAAG,CAAC,CAAC;IAClB,CAAC,CAAC,CAAC;AACP,CAAC,CAAC"} |
| import { sign, signApp } from './sign'; | ||
| import { flat, buildPkg } from './flat'; | ||
| import { walkAsync } from './util'; | ||
| export { sign, flat, signApp as signAsync, signApp, buildPkg as flatAsync, buildPkg, walkAsync }; | ||
| export * from './types'; |
| import { sign, signApp } from './sign'; | ||
| import { flat, buildPkg } from './flat'; | ||
| import { walkAsync } from './util'; | ||
| // TODO: Remove and leave only proper named exports, but for non-breaking change reasons | ||
| // we need to keep this weirdness for now | ||
| module.exports = sign; | ||
| module.exports.sign = sign; | ||
| module.exports.signAsync = signApp; | ||
| module.exports.signApp = signApp; | ||
| module.exports.flat = flat; | ||
| module.exports.flatAsync = buildPkg; | ||
| module.exports.buildPkg = buildPkg; | ||
| module.exports.walkAsync = walkAsync; | ||
| export { sign, flat, signApp as signAsync, signApp, buildPkg as flatAsync, buildPkg, walkAsync }; | ||
| export * from './types'; | ||
| //# sourceMappingURL=index.js.map |
| {"version":3,"file":"index.js","sourceRoot":"","sources":["../../src/index.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,IAAI,EAAE,OAAO,EAAE,MAAM,QAAQ,CAAC;AACvC,OAAO,EAAE,IAAI,EAAE,QAAQ,EAAE,MAAM,QAAQ,CAAC;AACxC,OAAO,EAAE,SAAS,EAAE,MAAM,QAAQ,CAAC;AAEnC,wFAAwF;AACxF,yCAAyC;AACzC,MAAM,CAAC,OAAO,GAAG,IAAI,CAAC;AACtB,MAAM,CAAC,OAAO,CAAC,IAAI,GAAG,IAAI,CAAC;AAC3B,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,OAAO,CAAC;AACnC,MAAM,CAAC,OAAO,CAAC,OAAO,GAAG,OAAO,CAAC;AACjC,MAAM,CAAC,OAAO,CAAC,IAAI,GAAG,IAAI,CAAC;AAC3B,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,QAAQ,CAAC;AACpC,MAAM,CAAC,OAAO,CAAC,QAAQ,GAAG,QAAQ,CAAC;AACnC,MAAM,CAAC,OAAO,CAAC,SAAS,GAAG,SAAS,CAAC;AAErC,OAAO,EAAE,IAAI,EAAE,IAAI,EAAE,OAAO,IAAI,SAAS,EAAE,OAAO,EAAE,QAAQ,IAAI,SAAS,EAAE,QAAQ,EAAE,SAAS,EAAE,CAAC;AACjG,cAAc,SAAS,CAAC"} |
| import { SignOptions } from './types'; | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| export declare function signApp(_opts: SignOptions): Promise<void>; | ||
| /** | ||
| * This function is a legacy callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link signAsync} method instead. | ||
| * @category Codesign | ||
| */ | ||
| export declare const sign: (opts: SignOptions, cb?: ((error?: Error) => void) | undefined) => void; |
-346
| import * as fs from 'fs-extra'; | ||
| import * as os from 'os'; | ||
| import * as path from 'path'; | ||
| import * as plist from 'plist'; | ||
| import compareVersion from 'compare-version'; | ||
| import { debugLog, debugWarn, getAppContentsPath, execFileAsync, validateOptsApp, validateOptsPlatform, walkAsync } from './util'; | ||
| import { Identity, findIdentities } from './util-identities'; | ||
| import { preEmbedProvisioningProfile, getProvisioningProfile } from './util-provisioning-profiles'; | ||
| import { preAutoEntitlements } from './util-entitlements'; | ||
| const pkgVersion = require('../../package.json').version; | ||
| const osRelease = os.release(); | ||
| /** | ||
| * This function returns a promise validating opts.binaries, the additional binaries to be signed along with the discovered enclosed components. | ||
| */ | ||
| async function validateOptsBinaries(opts) { | ||
| if (opts.binaries) { | ||
| if (!Array.isArray(opts.binaries)) { | ||
| throw new Error('Additional binaries should be an Array.'); | ||
| } | ||
| // TODO: Presence check for binary files, reject if any does not exist | ||
| } | ||
| } | ||
| function validateOptsIgnore(ignore) { | ||
| if (ignore && !(ignore instanceof Array)) { | ||
| return [ignore]; | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise validating all options passed in opts. | ||
| */ | ||
| async function validateSignOpts(opts) { | ||
| await validateOptsBinaries(opts); | ||
| await validateOptsApp(opts); | ||
| if (opts.provisioningProfile && typeof opts.provisioningProfile !== 'string') { | ||
| throw new Error('Path to provisioning profile should be a string.'); | ||
| } | ||
| if (opts.type && opts.type !== 'development' && opts.type !== 'distribution') { | ||
| throw new Error('Type must be either `development` or `distribution`.'); | ||
| } | ||
| const platform = await validateOptsPlatform(opts); | ||
| const cloned = Object.assign(Object.assign({}, opts), { ignore: validateOptsIgnore(opts.ignore), type: opts.type || 'distribution', platform }); | ||
| return cloned; | ||
| } | ||
| /** | ||
| * This function returns a promise verifying the code sign of application bundle. | ||
| */ | ||
| async function verifySignApplication(opts) { | ||
| // Verify with codesign | ||
| debugLog('Verifying application bundle with codesign...'); | ||
| const strictVerify = opts.strictVerify !== undefined ? opts.strictVerify : true; | ||
| await execFileAsync('codesign', ['--verify', '--deep'].concat(strictVerify !== false && compareVersion(osRelease, '15.0.0') >= 0 // Strict flag since darwin 15.0.0 --> OS X 10.11.0 El Capitan | ||
| ? [ | ||
| '--strict' + | ||
| (strictVerify !== true ? '=' + strictVerify : '') | ||
| ] | ||
| : [], ['--verbose=2', opts.app])); | ||
| } | ||
| function defaultOptionsForFile(filePath, platform) { | ||
| const entitlementsFolder = path.resolve(__dirname, '..', '..', 'entitlements'); | ||
| let entitlementsFile; | ||
| if (platform === 'darwin') { | ||
| // Default Entitlements | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/app-entitlements.plist | ||
| // Also include JIT for main process V8 | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plist'); | ||
| // Plugin helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-plugin-entitlements.plist | ||
| if (filePath.includes('(Plugin).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.plugin.plist'); | ||
| // GPU Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-gpu-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(GPU).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.gpu.plist'); | ||
| // Renderer Helper | ||
| // c.f. https://source.chromium.org/chromium/chromium/src/+/main:chrome/app/helper-renderer-entitlements.plist | ||
| } | ||
| else if (filePath.includes('(Renderer).app')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.darwin.renderer.plist'); | ||
| } | ||
| } | ||
| else { | ||
| // Default entitlements | ||
| // TODO: Can these be more scoped like the non-mas variant? | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.plist'); | ||
| // If it is not the top level app bundle, we sign with inherit | ||
| if (filePath.includes('.app/')) { | ||
| entitlementsFile = path.resolve(entitlementsFolder, 'default.mas.child.plist'); | ||
| } | ||
| } | ||
| return { | ||
| entitlements: entitlementsFile, | ||
| hardenedRuntime: true, | ||
| requirements: undefined, | ||
| signatureFlags: undefined, | ||
| timestamp: undefined, | ||
| additionalArguments: [] | ||
| }; | ||
| } | ||
| async function mergeOptionsForFile(opts, defaults) { | ||
| const mergedPerFileOptions = Object.assign({}, defaults); | ||
| if (opts) { | ||
| if (opts.entitlements !== undefined) { | ||
| if (Array.isArray(opts.entitlements)) { | ||
| const entitlements = opts.entitlements.reduce((dict, entitlementKey) => (Object.assign(Object.assign({}, dict), { [entitlementKey]: true })), {}); | ||
| const dir = await fs.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await fs.writeFile(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| opts.entitlements = entitlementsPath; | ||
| } | ||
| mergedPerFileOptions.entitlements = opts.entitlements; | ||
| } | ||
| if (opts.hardenedRuntime !== undefined) { | ||
| mergedPerFileOptions.hardenedRuntime = opts.hardenedRuntime; | ||
| } | ||
| if (opts.requirements !== undefined) | ||
| mergedPerFileOptions.requirements = opts.requirements; | ||
| if (opts.signatureFlags !== undefined) { | ||
| mergedPerFileOptions.signatureFlags = opts.signatureFlags; | ||
| } | ||
| if (opts.timestamp !== undefined) | ||
| mergedPerFileOptions.timestamp = opts.timestamp; | ||
| if (opts.additionalArguments !== undefined) | ||
| mergedPerFileOptions.additionalArguments = opts.additionalArguments; | ||
| } | ||
| return mergedPerFileOptions; | ||
| } | ||
| /** | ||
| * This function returns a promise codesigning only. | ||
| */ | ||
| async function signApplication(opts, identity) { | ||
| function shouldIgnoreFilePath(filePath) { | ||
| if (opts.ignore) { | ||
| return opts.ignore.some(function (ignore) { | ||
| if (typeof ignore === 'function') { | ||
| return ignore(filePath); | ||
| } | ||
| return filePath.match(ignore); | ||
| }); | ||
| } | ||
| return false; | ||
| } | ||
| const children = await walkAsync(getAppContentsPath(opts)); | ||
| if (opts.binaries) | ||
| children.push(...opts.binaries); | ||
| const args = ['--sign', identity.hash || identity.name, '--force']; | ||
| if (opts.keychain) { | ||
| args.push('--keychain', opts.keychain); | ||
| } | ||
| /** | ||
| * Sort the child paths by how deep they are in the file tree. Some arcane apple | ||
| * logic expects the deeper files to be signed first otherwise strange errors get | ||
| * thrown our way | ||
| */ | ||
| children.sort((a, b) => { | ||
| const aDepth = a.split(path.sep).length; | ||
| const bDepth = b.split(path.sep).length; | ||
| return bDepth - aDepth; | ||
| }); | ||
| for (const filePath of [...children, opts.app]) { | ||
| if (shouldIgnoreFilePath(filePath)) { | ||
| debugLog('Skipped... ' + filePath); | ||
| continue; | ||
| } | ||
| const perFileOptions = await mergeOptionsForFile(opts.optionsForFile ? opts.optionsForFile(filePath) : null, defaultOptionsForFile(filePath, opts.platform)); | ||
| // preAutoEntitlements should only be applied to the top level app bundle. | ||
| // Applying it other files will cause the app to crash and be rejected by Apple. | ||
| if (!filePath.includes('.app/')) { | ||
| if (opts.preAutoEntitlements === false) { | ||
| debugWarn('Pre-sign operation disabled for entitlements automation.'); | ||
| } | ||
| else { | ||
| debugLog('Pre-sign operation enabled for entitlements automation with versions >= `1.1.1`:', '\n', '* Disable by setting `pre-auto-entitlements` to `false`.'); | ||
| if (!opts.version || compareVersion(opts.version, '1.1.1') >= 0) { | ||
| // Enable Mac App Store sandboxing without using temporary-exception, introduced in Electron v1.1.1. Relates to electron#5601 | ||
| const newEntitlements = await preAutoEntitlements(opts, perFileOptions, { | ||
| identity, | ||
| provisioningProfile: opts.provisioningProfile | ||
| ? await getProvisioningProfile(opts.provisioningProfile, opts.keychain) | ||
| : undefined | ||
| }); | ||
| // preAutoEntitlements may provide us new entitlements, if so we update our options | ||
| // and ensure that entitlements-loginhelper has a correct default value | ||
| if (newEntitlements) { | ||
| perFileOptions.entitlements = newEntitlements; | ||
| } | ||
| } | ||
| } | ||
| } | ||
| debugLog('Signing... ' + filePath); | ||
| const perFileArgs = [...args]; | ||
| if (perFileOptions.requirements) { | ||
| if (perFileOptions.requirements.charAt(0) === '=') { | ||
| perFileArgs.push(`-r${perFileOptions.requirements}`); | ||
| } | ||
| else { | ||
| perFileArgs.push('--requirements', perFileOptions.requirements); | ||
| } | ||
| } | ||
| if (perFileOptions.timestamp) { | ||
| perFileArgs.push('--timestamp=' + perFileOptions.timestamp); | ||
| } | ||
| else { | ||
| perFileArgs.push('--timestamp'); | ||
| } | ||
| let optionsArguments = []; | ||
| if (perFileOptions.signatureFlags) { | ||
| if (Array.isArray(perFileOptions.signatureFlags)) { | ||
| optionsArguments.push(...perFileOptions.signatureFlags); | ||
| } | ||
| else { | ||
| const flags = perFileOptions.signatureFlags.split(',').map(function (flag) { | ||
| return flag.trim(); | ||
| }); | ||
| optionsArguments.push(...flags); | ||
| } | ||
| } | ||
| if (perFileOptions.hardenedRuntime || optionsArguments.includes('runtime')) { | ||
| // Hardened runtime since darwin 17.7.0 --> macOS 10.13.6 | ||
| if (compareVersion(osRelease, '17.7.0') >= 0) { | ||
| optionsArguments.push('runtime'); | ||
| } | ||
| else { | ||
| // Remove runtime if passed in with --signature-flags | ||
| debugLog('Not enabling hardened runtime, current macOS version too low, requires 10.13.6 and higher'); | ||
| optionsArguments = optionsArguments.filter((arg) => { | ||
| return arg !== 'runtime'; | ||
| }); | ||
| } | ||
| } | ||
| if (optionsArguments.length) { | ||
| perFileArgs.push('--options', [...new Set(optionsArguments)].join(',')); | ||
| } | ||
| if (perFileOptions.additionalArguments) { | ||
| perFileArgs.push(...perFileOptions.additionalArguments); | ||
| } | ||
| await execFileAsync('codesign', perFileArgs.concat('--entitlements', perFileOptions.entitlements, filePath)); | ||
| } | ||
| // Verify code sign | ||
| debugLog('Verifying...'); | ||
| await verifySignApplication(opts); | ||
| debugLog('Verified.'); | ||
| // Check entitlements if applicable | ||
| debugLog('Displaying entitlements...'); | ||
| const result = await execFileAsync('codesign', [ | ||
| '--display', | ||
| '--entitlements', | ||
| ':-', | ||
| opts.app | ||
| ]); | ||
| debugLog('Entitlements:', '\n', result); | ||
| } | ||
| /** | ||
| * Signs a macOS application. | ||
| * @returns A void Promise once the signing operation is complete. | ||
| * | ||
| * @category Codesign | ||
| */ | ||
| export async function signApp(_opts) { | ||
| debugLog('electron-osx-sign@%s', pkgVersion); | ||
| const validatedOpts = await validateSignOpts(_opts); | ||
| let identities = []; | ||
| let identityInUse = null; | ||
| // Determine identity for signing | ||
| if (validatedOpts.identity) { | ||
| debugLog('`identity` passed in arguments.'); | ||
| if (validatedOpts.identityValidation === false) { | ||
| identityInUse = new Identity(validatedOpts.identity); | ||
| } | ||
| else { | ||
| identities = await findIdentities(validatedOpts.keychain || null, validatedOpts.identity); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `identity` passed in arguments...'); | ||
| if (validatedOpts.platform === 'mas') { | ||
| if (validatedOpts.type === 'distribution') { | ||
| debugLog('Finding `3rd Party Mac Developer Application` certificate for signing app distribution in the Mac App Store...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, '3rd Party Mac Developer Application:'); | ||
| } | ||
| else { | ||
| debugLog('Finding `Mac Developer` certificate for signing app in development for the Mac App Store signing...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, 'Mac Developer:'); | ||
| } | ||
| } | ||
| else { | ||
| debugLog('Finding `Developer ID Application` certificate for distribution outside the Mac App Store...'); | ||
| identities = await findIdentities(validatedOpts.keychain || null, 'Developer ID Application:'); | ||
| } | ||
| } | ||
| if (!identityInUse) { | ||
| if (identities.length > 0) { | ||
| // Identity(/ies) found | ||
| if (identities.length > 1) { | ||
| debugWarn('Multiple identities found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 identity.'); | ||
| } | ||
| identityInUse = identities[0]; | ||
| } | ||
| else { | ||
| // No identity found | ||
| throw new Error('No identity found for signing.'); | ||
| } | ||
| } | ||
| // Pre-sign operations | ||
| if (validatedOpts.preEmbedProvisioningProfile === false) { | ||
| debugWarn('Pre-sign operation disabled for provisioning profile embedding:', '\n', '* Enable by setting `pre-embed-provisioning-profile` to `true`.'); | ||
| } | ||
| else { | ||
| debugLog('Pre-sign operation enabled for provisioning profile:', '\n', '* Disable by setting `pre-embed-provisioning-profile` to `false`.'); | ||
| await preEmbedProvisioningProfile(validatedOpts, validatedOpts.provisioningProfile | ||
| ? await getProvisioningProfile(validatedOpts.provisioningProfile, validatedOpts.keychain) | ||
| : null); | ||
| } | ||
| debugLog('Signing application...', '\n', '> Application:', validatedOpts.app, '\n', '> Platform:', validatedOpts.platform, '\n', '> Additional binaries:', validatedOpts.binaries, '\n', '> Identity:', validatedOpts.identity); | ||
| await signApplication(validatedOpts, identityInUse); | ||
| // Post-sign operations | ||
| debugLog('Application signed.'); | ||
| } | ||
| /** | ||
| * This function is a legacy callback implementation. | ||
| * | ||
| * @deprecated Please use the Promise-based {@link signAsync} method instead. | ||
| * @category Codesign | ||
| */ | ||
| export const sign = (opts, cb) => { | ||
| signApp(opts) | ||
| .then(() => { | ||
| debugLog('Application signed: ' + opts.app); | ||
| if (cb) | ||
| cb(); | ||
| }) | ||
| .catch((err) => { | ||
| if (err.message) | ||
| debugLog(err.message); | ||
| else if (err.stack) | ||
| debugLog(err.stack); | ||
| else | ||
| debugLog(err); | ||
| if (cb) | ||
| cb(err); | ||
| }); | ||
| }; | ||
| //# sourceMappingURL=sign.js.map |
| {"version":3,"file":"sign.js","sourceRoot":"","sources":["../../src/sign.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,EAAE,MAAM,UAAU,CAAC;AAC/B,OAAO,KAAK,EAAE,MAAM,IAAI,CAAC;AACzB,OAAO,KAAK,IAAI,MAAM,MAAM,CAAC;AAC7B,OAAO,KAAK,KAAK,MAAM,OAAO,CAAC;AAC/B,OAAO,cAAc,MAAM,iBAAiB,CAAC;AAE7C,OAAO,EACL,QAAQ,EACR,SAAS,EACT,kBAAkB,EAClB,aAAa,EACb,eAAe,EACf,oBAAoB,EACpB,SAAS,EACV,MAAM,QAAQ,CAAC;AAChB,OAAO,EAAE,QAAQ,EAAE,cAAc,EAAE,MAAM,mBAAmB,CAAC;AAC7D,OAAO,EAAE,2BAA2B,EAAE,sBAAsB,EAAE,MAAM,8BAA8B,CAAC;AACnG,OAAO,EAAE,mBAAmB,EAAE,MAAM,qBAAqB,CAAC;AAG1D,MAAM,UAAU,GAAW,OAAO,CAAC,oBAAoB,CAAC,CAAC,OAAO,CAAC;AAEjE,MAAM,SAAS,GAAG,EAAE,CAAC,OAAO,EAAE,CAAC;AAE/B;;GAEG;AACH,KAAK,UAAU,oBAAoB,CAAE,IAAiB;IACpD,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,EAAE;YACjC,MAAM,IAAI,KAAK,CAAC,yCAAyC,CAAC,CAAC;SAC5D;QACD,sEAAsE;KACvE;AACH,CAAC;AAED,SAAS,kBAAkB,CAAE,MAA6B;IACxD,IAAI,MAAM,IAAI,CAAC,CAAC,MAAM,YAAY,KAAK,CAAC,EAAE;QACxC,OAAO,CAAC,MAAM,CAAC,CAAC;KACjB;AACH,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,gBAAgB,CAAE,IAAiB;IAChD,MAAM,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACjC,MAAM,eAAe,CAAC,IAAI,CAAC,CAAC;IAE5B,IAAI,IAAI,CAAC,mBAAmB,IAAI,OAAO,IAAI,CAAC,mBAAmB,KAAK,QAAQ,EAAE;QAC5E,MAAM,IAAI,KAAK,CAAC,kDAAkD,CAAC,CAAC;KACrE;IAED,IAAI,IAAI,CAAC,IAAI,IAAI,IAAI,CAAC,IAAI,KAAK,aAAa,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc,EAAE;QAC5E,MAAM,IAAI,KAAK,CAAC,sDAAsD,CAAC,CAAC;KACzE;IAED,MAAM,QAAQ,GAAG,MAAM,oBAAoB,CAAC,IAAI,CAAC,CAAC;IAClD,MAAM,MAAM,mCACP,IAAI,KACP,MAAM,EAAE,kBAAkB,CAAC,IAAI,CAAC,MAAM,CAAC,EACvC,IAAI,EAAE,IAAI,CAAC,IAAI,IAAI,cAAc,EACjC,QAAQ,GACT,CAAC;IACF,OAAO,MAAM,CAAC;AAChB,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,qBAAqB,CAAE,IAA0B;IAC9D,uBAAuB;IACvB,QAAQ,CAAC,+CAA+C,CAAC,CAAC;IAE1D,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,KAAK,SAAS,CAAC,CAAC,CAAC,IAAI,CAAC,YAAY,CAAC,CAAC,CAAC,IAAI,CAAC;IAChF,MAAM,aAAa,CACjB,UAAU,EACV,CAAC,UAAU,EAAE,QAAQ,CAAC,CAAC,MAAM,CAC3B,YAAY,KAAK,KAAK,IAAI,cAAc,CAAC,SAAS,EAAE,QAAQ,CAAC,IAAI,CAAC,CAAC,8DAA8D;QAC/H,CAAC,CAAC;YACE,UAAU;gBACR,CAAC,YAAY,KAAK,IAAI,CAAC,CAAC,CAAC,GAAG,GAAG,YAAY,CAAC,CAAC,CAAC,EAAE,CAAC;SACpD;QACH,CAAC,CAAC,EAAE,EACN,CAAC,aAAa,EAAE,IAAI,CAAC,GAAG,CAAC,CAC1B,CACF,CAAC;AACJ,CAAC;AAED,SAAS,qBAAqB,CAAE,QAAgB,EAAE,QAA6B;IAC7E,MAAM,kBAAkB,GAAG,IAAI,CAAC,OAAO,CAAC,SAAS,EAAE,IAAI,EAAE,IAAI,EAAE,cAAc,CAAC,CAAC;IAE/E,IAAI,gBAAwB,CAAC;IAC7B,IAAI,QAAQ,KAAK,QAAQ,EAAE;QACzB,uBAAuB;QACvB,kGAAkG;QAClG,uCAAuC;QACvC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,sBAAsB,CAAC,CAAC;QAC5E,gBAAgB;QAChB,4GAA4G;QAC5G,IAAI,QAAQ,CAAC,QAAQ,CAAC,cAAc,CAAC,EAAE;YACrC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,6BAA6B,CAAC,CAAC;YACrF,aAAa;YACb,yGAAyG;SACxG;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,WAAW,CAAC,EAAE;YACzC,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,0BAA0B,CAAC,CAAC;YAClF,kBAAkB;YAClB,8GAA8G;SAC7G;aAAM,IAAI,QAAQ,CAAC,QAAQ,CAAC,gBAAgB,CAAC,EAAE;YAC9C,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,+BAA+B,CAAC,CAAC;SACtF;KACF;SAAM;QACL,uBAAuB;QACvB,2DAA2D;QAC3D,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,mBAAmB,CAAC,CAAC;QAEzE,8DAA8D;QAC9D,IAAI,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE;YAC9B,gBAAgB,GAAG,IAAI,CAAC,OAAO,CAAC,kBAAkB,EAAE,yBAAyB,CAAC,CAAC;SAChF;KACF;IAED,OAAO;QACL,YAAY,EAAE,gBAAgB;QAC9B,eAAe,EAAE,IAAI;QACrB,YAAY,EAAE,SAA+B;QAC7C,cAAc,EAAE,SAA0C;QAC1D,SAAS,EAAE,SAA+B;QAC1C,mBAAmB,EAAE,EAA0B;KAChD,CAAC;AACJ,CAAC;AAED,KAAK,UAAU,mBAAmB,CAChC,IAA+B,EAC/B,QAAkD;IAElD,MAAM,oBAAoB,qBAAQ,QAAQ,CAAE,CAAC;IAC7C,IAAI,IAAI,EAAE;QACR,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS,EAAE;YACnC,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,YAAY,CAAC,EAAE;gBACpC,MAAM,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC,MAAM,CAAsB,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,iCACxF,IAAI,KACP,CAAC,cAAc,CAAC,EAAE,IAAI,IACtB,EAAE,EAAE,CAAC,CAAC;gBACR,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;gBAC7E,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;gBAC9D,MAAM,EAAE,CAAC,SAAS,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;gBACxE,IAAI,CAAC,YAAY,GAAG,gBAAgB,CAAC;aACtC;YACD,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;SACvD;QACD,IAAI,IAAI,CAAC,eAAe,KAAK,SAAS,EAAE;YACtC,oBAAoB,CAAC,eAAe,GAAG,IAAI,CAAC,eAAe,CAAC;SAC7D;QACD,IAAI,IAAI,CAAC,YAAY,KAAK,SAAS;YAAE,oBAAoB,CAAC,YAAY,GAAG,IAAI,CAAC,YAAY,CAAC;QAC3F,IAAI,IAAI,CAAC,cAAc,KAAK,SAAS,EAAE;YACrC,oBAAoB,CAAC,cAAc,GAAG,IAAI,CAAC,cAAc,CAAC;SAC3D;QACD,IAAI,IAAI,CAAC,SAAS,KAAK,SAAS;YAAE,oBAAoB,CAAC,SAAS,GAAG,IAAI,CAAC,SAAS,CAAC;QAClF,IAAI,IAAI,CAAC,mBAAmB,KAAK,SAAS;YAAE,oBAAoB,CAAC,mBAAmB,GAAG,IAAI,CAAC,mBAAmB,CAAC;KACjH;IACD,OAAO,oBAAoB,CAAC;AAC9B,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,eAAe,CAAE,IAA0B,EAAE,QAAkB;IAC5E,SAAS,oBAAoB,CAAE,QAAgB;QAC7C,IAAI,IAAI,CAAC,MAAM,EAAE;YACf,OAAO,IAAI,CAAC,MAAM,CAAC,IAAI,CAAC,UAAU,MAAM;gBACtC,IAAI,OAAO,MAAM,KAAK,UAAU,EAAE;oBAChC,OAAO,MAAM,CAAC,QAAQ,CAAC,CAAC;iBACzB;gBACD,OAAO,QAAQ,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC;YAChC,CAAC,CAAC,CAAC;SACJ;QACD,OAAO,KAAK,CAAC;IACf,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,SAAS,CAAC,kBAAkB,CAAC,IAAI,CAAC,CAAC,CAAC;IAE3D,IAAI,IAAI,CAAC,QAAQ;QAAE,QAAQ,CAAC,IAAI,CAAC,GAAG,IAAI,CAAC,QAAQ,CAAC,CAAC;IAEnD,MAAM,IAAI,GAAG,CAAC,QAAQ,EAAE,QAAQ,CAAC,IAAI,IAAI,QAAQ,CAAC,IAAI,EAAE,SAAS,CAAC,CAAC;IACnE,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,CAAC,IAAI,CAAC,YAAY,EAAE,IAAI,CAAC,QAAQ,CAAC,CAAC;KACxC;IAED;;;;OAIG;IACH,QAAQ,CAAC,IAAI,CAAC,CAAC,CAAC,EAAE,CAAC,EAAE,EAAE;QACrB,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,MAAM,MAAM,GAAG,CAAC,CAAC,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,MAAM,CAAC;QACxC,OAAO,MAAM,GAAG,MAAM,CAAC;IACzB,CAAC,CAAC,CAAC;IAEH,KAAK,MAAM,QAAQ,IAAI,CAAC,GAAG,QAAQ,EAAE,IAAI,CAAC,GAAG,CAAC,EAAE;QAC9C,IAAI,oBAAoB,CAAC,QAAQ,CAAC,EAAE;YAClC,QAAQ,CAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;YACnC,SAAS;SACV;QAED,MAAM,cAAc,GAAG,MAAM,mBAAmB,CAC9C,IAAI,CAAC,cAAc,CAAC,CAAC,CAAC,IAAI,CAAC,cAAc,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,IAAI,EAC1D,qBAAqB,CAAC,QAAQ,EAAE,IAAI,CAAC,QAAQ,CAAC,CAC/C,CAAC;QAEF,0EAA0E;QAC1E,gFAAgF;QAChF,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE;YAC/B,IAAI,IAAI,CAAC,mBAAmB,KAAK,KAAK,EAAE;gBACtC,SAAS,CAAC,0DAA0D,CAAC,CAAC;aACvE;iBAAM;gBACL,QAAQ,CACN,kFAAkF,EAClF,IAAI,EACJ,0DAA0D,CAC3D,CAAC;gBACF,IAAI,CAAC,IAAI,CAAC,OAAO,IAAI,cAAc,CAAC,IAAI,CAAC,OAAO,EAAE,OAAO,CAAC,IAAI,CAAC,EAAE;oBAC/D,6HAA6H;oBAC7H,MAAM,eAAe,GAAG,MAAM,mBAAmB,CAAC,IAAI,EAAE,cAAc,EAAE;wBACtE,QAAQ;wBACR,mBAAmB,EAAE,IAAI,CAAC,mBAAmB;4BAC3C,CAAC,CAAC,MAAM,sBAAsB,CAAC,IAAI,CAAC,mBAAmB,EAAE,IAAI,CAAC,QAAQ,CAAC;4BACvE,CAAC,CAAC,SAAS;qBACd,CAAC,CAAC;oBAEH,mFAAmF;oBACnF,uEAAuE;oBACvE,IAAI,eAAe,EAAE;wBACnB,cAAc,CAAC,YAAY,GAAG,eAAe,CAAC;qBAC/C;iBACF;aACF;SACF;QAED,QAAQ,CAAC,aAAa,GAAG,QAAQ,CAAC,CAAC;QAEnC,MAAM,WAAW,GAAG,CAAC,GAAG,IAAI,CAAC,CAAC;QAE9B,IAAI,cAAc,CAAC,YAAY,EAAE;YAC/B,IAAI,cAAc,CAAC,YAAY,CAAC,MAAM,CAAC,CAAC,CAAC,KAAK,GAAG,EAAE;gBACjD,WAAW,CAAC,IAAI,CAAC,KAAK,cAAc,CAAC,YAAY,EAAE,CAAC,CAAC;aACtD;iBAAM;gBACL,WAAW,CAAC,IAAI,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,CAAC,CAAC;aACjE;SACF;QACD,IAAI,cAAc,CAAC,SAAS,EAAE;YAC5B,WAAW,CAAC,IAAI,CAAC,cAAc,GAAG,cAAc,CAAC,SAAS,CAAC,CAAC;SAC7D;aAAM;YACL,WAAW,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;SACjC;QAED,IAAI,gBAAgB,GAAa,EAAE,CAAC;QAEpC,IAAI,cAAc,CAAC,cAAc,EAAE;YACjC,IAAI,KAAK,CAAC,OAAO,CAAC,cAAc,CAAC,cAAc,CAAC,EAAE;gBAChD,gBAAgB,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,cAAc,CAAC,CAAC;aACzD;iBAAM;gBACL,MAAM,KAAK,GAAG,cAAc,CAAC,cAAc,CAAC,KAAK,CAAC,GAAG,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;oBACvE,OAAO,IAAI,CAAC,IAAI,EAAE,CAAC;gBACrB,CAAC,CAAC,CAAC;gBACH,gBAAgB,CAAC,IAAI,CAAC,GAAG,KAAK,CAAC,CAAC;aACjC;SACF;QAED,IAAI,cAAc,CAAC,eAAe,IAAI,gBAAgB,CAAC,QAAQ,CAAC,SAAS,CAAC,EAAE;YAC1E,yDAAyD;YACzD,IAAI,cAAc,CAAC,SAAS,EAAE,QAAQ,CAAC,IAAI,CAAC,EAAE;gBAC5C,gBAAgB,CAAC,IAAI,CAAC,SAAS,CAAC,CAAC;aAClC;iBAAM;gBACL,qDAAqD;gBACrD,QAAQ,CACN,2FAA2F,CAC5F,CAAC;gBACF,gBAAgB,GAAG,gBAAgB,CAAC,MAAM,CAAC,CAAC,GAAG,EAAE,EAAE;oBACjD,OAAO,GAAG,KAAK,SAAS,CAAC;gBAC3B,CAAC,CAAC,CAAC;aACJ;SACF;QAED,IAAI,gBAAgB,CAAC,MAAM,EAAE;YAC3B,WAAW,CAAC,IAAI,CAAC,WAAW,EAAE,CAAC,GAAG,IAAI,GAAG,CAAC,gBAAgB,CAAC,CAAC,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC;SACzE;QAED,IAAI,cAAc,CAAC,mBAAmB,EAAE;YACtC,WAAW,CAAC,IAAI,CAAC,GAAG,cAAc,CAAC,mBAAmB,CAAC,CAAC;SACzD;QAED,MAAM,aAAa,CACjB,UAAU,EACV,WAAW,CAAC,MAAM,CAAC,gBAAgB,EAAE,cAAc,CAAC,YAAY,EAAE,QAAQ,CAAC,CAC5E,CAAC;KACH;IAED,mBAAmB;IACnB,QAAQ,CAAC,cAAc,CAAC,CAAC;IACzB,MAAM,qBAAqB,CAAC,IAAI,CAAC,CAAC;IAClC,QAAQ,CAAC,WAAW,CAAC,CAAC;IAEtB,mCAAmC;IACnC,QAAQ,CAAC,4BAA4B,CAAC,CAAC;IACvC,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE;QAC7C,WAAW;QACX,gBAAgB;QAChB,IAAI;QACJ,IAAI,CAAC,GAAG;KACT,CAAC,CAAC;IAEH,QAAQ,CAAC,eAAe,EAAE,IAAI,EAAE,MAAM,CAAC,CAAC;AAC1C,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,KAAK,UAAU,OAAO,CAAE,KAAkB;IAC/C,QAAQ,CAAC,sBAAsB,EAAE,UAAU,CAAC,CAAC;IAC7C,MAAM,aAAa,GAAG,MAAM,gBAAgB,CAAC,KAAK,CAAC,CAAC;IACpD,IAAI,UAAU,GAAe,EAAE,CAAC;IAChC,IAAI,aAAa,GAAoB,IAAI,CAAC;IAE1C,iCAAiC;IACjC,IAAI,aAAa,CAAC,QAAQ,EAAE;QAC1B,QAAQ,CAAC,iCAAiC,CAAC,CAAC;QAC5C,IAAI,aAAa,CAAC,kBAAkB,KAAK,KAAK,EAAE;YAC9C,aAAa,GAAG,IAAI,QAAQ,CAAC,aAAa,CAAC,QAAQ,CAAC,CAAC;SACtD;aAAM;YACL,UAAU,GAAG,MAAM,cAAc,CAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,aAAa,CAAC,QAAQ,CAAC,CAAC;SAC3F;KACF;SAAM;QACL,SAAS,CAAC,sCAAsC,CAAC,CAAC;QAClD,IAAI,aAAa,CAAC,QAAQ,KAAK,KAAK,EAAE;YACpC,IAAI,aAAa,CAAC,IAAI,KAAK,cAAc,EAAE;gBACzC,QAAQ,CACN,gHAAgH,CACjH,CAAC;gBACF,UAAU,GAAG,MAAM,cAAc,CAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,sCAAsC,CACvC,CAAC;aACH;iBAAM;gBACL,QAAQ,CACN,qGAAqG,CACtG,CAAC;gBACF,UAAU,GAAG,MAAM,cAAc,CAAC,aAAa,CAAC,QAAQ,IAAI,IAAI,EAAE,gBAAgB,CAAC,CAAC;aACrF;SACF;aAAM;YACL,QAAQ,CACN,8FAA8F,CAC/F,CAAC;YACF,UAAU,GAAG,MAAM,cAAc,CAC/B,aAAa,CAAC,QAAQ,IAAI,IAAI,EAC9B,2BAA2B,CAC5B,CAAC;SACH;KACF;IAED,IAAI,CAAC,aAAa,EAAE;QAClB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;YACzB,uBAAuB;YACvB,IAAI,UAAU,CAAC,MAAM,GAAG,CAAC,EAAE;gBACzB,SAAS,CAAC,2DAA2D,CAAC,CAAC;aACxE;iBAAM;gBACL,QAAQ,CAAC,mBAAmB,CAAC,CAAC;aAC/B;YACD,aAAa,GAAG,UAAU,CAAC,CAAC,CAAC,CAAC;SAC/B;aAAM;YACL,oBAAoB;YACpB,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;SACnD;KACF;IAED,sBAAsB;IACtB,IAAI,aAAa,CAAC,2BAA2B,KAAK,KAAK,EAAE;QACvD,SAAS,CACP,iEAAiE,EACjE,IAAI,EACJ,iEAAiE,CAClE,CAAC;KACH;SAAM;QACL,QAAQ,CACN,sDAAsD,EACtD,IAAI,EACJ,mEAAmE,CACpE,CAAC;QACF,MAAM,2BAA2B,CAC/B,aAAa,EACb,aAAa,CAAC,mBAAmB;YAC/B,CAAC,CAAC,MAAM,sBAAsB,CAAC,aAAa,CAAC,mBAAmB,EAAE,aAAa,CAAC,QAAQ,CAAC;YACzF,CAAC,CAAC,IAAI,CACT,CAAC;KACH;IAED,QAAQ,CACN,wBAAwB,EACxB,IAAI,EACJ,gBAAgB,EAChB,aAAa,CAAC,GAAG,EACjB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,wBAAwB,EACxB,aAAa,CAAC,QAAQ,EACtB,IAAI,EACJ,aAAa,EACb,aAAa,CAAC,QAAQ,CACvB,CAAC;IACF,MAAM,eAAe,CAAC,aAAa,EAAE,aAAa,CAAC,CAAC;IAEpD,uBAAuB;IACvB,QAAQ,CAAC,qBAAqB,CAAC,CAAC;AAClC,CAAC;AAED;;;;;GAKG;AACH,MAAM,CAAC,MAAM,IAAI,GAAG,CAAC,IAAiB,EAAE,EAA4B,EAAE,EAAE;IACtE,OAAO,CAAC,IAAI,CAAC;SACV,IAAI,CAAC,GAAG,EAAE;QACT,QAAQ,CAAC,sBAAsB,GAAG,IAAI,CAAC,GAAG,CAAC,CAAC;QAC5C,IAAI,EAAE;YAAE,EAAE,EAAE,CAAC;IACf,CAAC,CAAC;SACD,KAAK,CAAC,CAAC,GAAG,EAAE,EAAE;QACb,IAAI,GAAG,CAAC,OAAO;YAAE,QAAQ,CAAC,GAAG,CAAC,OAAO,CAAC,CAAC;aAClC,IAAI,GAAG,CAAC,KAAK;YAAE,QAAQ,CAAC,GAAG,CAAC,KAAK,CAAC,CAAC;;YACnC,QAAQ,CAAC,GAAG,CAAC,CAAC;QACnB,IAAI,EAAE;YAAE,EAAE,CAAC,GAAG,CAAC,CAAC;IAClB,CAAC,CAAC,CAAC;AACP,CAAC,CAAC"} |
| /** | ||
| * macOS applications can be distributed via the Mac App Store (MAS) or directly | ||
| * downloaded from the developer's website. @electron/osx-sign distinguishes between | ||
| * MAS apps (`mas`) or non-MAS apps (`darwin`). | ||
| * @category Utility | ||
| */ | ||
| export type ElectronMacPlatform = 'darwin' | 'mas'; | ||
| /** | ||
| * MAS apps can be signed using Development or Distribution certificates. | ||
| * See [Apple Documentation](https://developer.apple.com/help/account/create-certificates/certificates-overview/) for more info. | ||
| * @category Utility | ||
| */ | ||
| export type SigningDistributionType = 'development' | 'distribution'; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type BaseSignOptions = Readonly<{ | ||
| /** | ||
| * Path to the application package. | ||
| * Needs to end with the file extension `.app`. | ||
| */ | ||
| app: string; | ||
| /** | ||
| * The keychain name. | ||
| * | ||
| * @defaultValue `login` | ||
| */ | ||
| keychain?: string; | ||
| /** | ||
| * Build platform of your Electron app. | ||
| * Allowed values: `darwin` (Direct Download App), `mas` (Mac App Store). | ||
| * | ||
| * @defaultValue Determined by presence of `Squirrel.framework` within the application bundle, | ||
| * which is used for non-MAS apps. | ||
| */ | ||
| platform?: ElectronMacPlatform; | ||
| /** | ||
| * Name of the certificate to use when signing. | ||
| * | ||
| * @defaultValue Selected with respect to {@link SignOptions.provisioningProfile | provisioningProfile} | ||
| * and {@link SignOptions.platform | platform} from the selected {@link SignOptions.keychain | keychain}. | ||
| * * `mas` will look for `3rd Party Mac Developer Application: * (*)` | ||
| * * `darwin` will look for `Developer ID Application: * (*)` by default. | ||
| */ | ||
| identity?: string; | ||
| }>; | ||
| type OnlyValidatedBaseSignOptions = { | ||
| platform: ElectronMacPlatform; | ||
| }; | ||
| /** | ||
| * A set of signing options that can be overriden on a per-file basis. | ||
| * Any missing options will use the default values, and providing a partial structure | ||
| * will shallow merge with the default values. | ||
| * @interface | ||
| * @category Codesign | ||
| */ | ||
| export type PerFileSignOptions = { | ||
| /** | ||
| * String specifying the path to an `entitlements.plist` file. | ||
| * Can also be an array of entitlement keys that osx-sign will write to an entitlements file for you. | ||
| * | ||
| * @defaultValue `@electron/osx-sign`'s built-in entitlements files. | ||
| */ | ||
| entitlements?: string | string[]; | ||
| /** | ||
| * Whether to enable [Hardened Runtime](https://developer.apple.com/documentation/security/hardened_runtime) | ||
| * for this file. | ||
| * | ||
| * Note: Hardened Runtime is a pre-requisite for notarization, which is mandatory for apps running on macOS 10.15 and above. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| hardenedRuntime?: boolean; | ||
| /** | ||
| * Either a string beginning with `=` which specifies in plain text the | ||
| * [signing requirements](https://developer.apple.com/library/mac/documentation/Security/Conceptual/CodeSigningGuide/RequirementLang/RequirementLang.html) | ||
| * that you recommend to be used to evaluate the code signature, or a string specifying a path to a text or | ||
| * properly encoded `.rqset` file which contains those requirements. | ||
| */ | ||
| requirements?: string; | ||
| /** | ||
| * When signing, a set of option flags can be specified to change the behavior of the system when using the signed code. | ||
| * Accepts an array of strings or a comma-separated string. | ||
| * | ||
| * See --options of the `codesign` command. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTION_FLAGS | ||
| */ | ||
| signatureFlags?: string | string[]; | ||
| /** | ||
| * String specifying the URL of the timestamp authority server. | ||
| * Please note that this default server may not support signatures not furnished by Apple. | ||
| * Disable the timestamp service with `none`. | ||
| * | ||
| * @defaultValue Uses the Apple-provided timestamp server. | ||
| */ | ||
| timestamp?: string; | ||
| /** | ||
| * Additional raw arguments to pass to the `codesign` command. | ||
| * | ||
| * These can be things like `--deep` for instance when code signing specific resources that may | ||
| * require such arguments. | ||
| * | ||
| * https://keith.github.io/xcode-man-pages/codesign.1.html#OPTIONS | ||
| */ | ||
| additionalArguments?: string[]; | ||
| }; | ||
| /** | ||
| * @interface | ||
| * @internal | ||
| */ | ||
| export type OnlySignOptions = { | ||
| /** | ||
| * Array of paths to additional binaries that will be signed along with built-ins of Electron. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| binaries?: string[]; | ||
| /** | ||
| * Function that receives the path to a file and can return the entitlements to use for that file to override the default behavior. The | ||
| * object this function returns can include any of the following optional keys. Any properties that are returned **override** the default | ||
| * values that `@electron/osx-sign` generates. Any properties not returned use the default value. | ||
| * | ||
| * @param filePath Path to file | ||
| * @returns Override signing options | ||
| */ | ||
| optionsForFile?: (filePath: string) => PerFileSignOptions; | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link SignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Defines files that will be skipped during the code signing process. | ||
| * This property accepts a regex, function or an array of regexes and functions. | ||
| * Elements of other types are treated as `RegExp`. | ||
| * | ||
| * File paths matching a regex or returning a `true` value from a function will be ignored. | ||
| * | ||
| * @defaultValue `undefined` | ||
| */ | ||
| ignore?: string | string[] | ((file: string) => boolean); | ||
| /** | ||
| * Flag to enable/disable entitlements automation tasks necessary for code signing most Electron apps. | ||
| * * Adds [`com.apple.security.application-groups`](https://developer.apple.com/documentation/bundleresources/entitlements/com_apple_security_application-groups) to the entitlements file | ||
| * * Fills in the `ElectronTeamID` property in `Info.plist` with the provisioning profile's Team Identifier or by parsing the identity name. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preAutoEntitlements?: boolean; | ||
| /** | ||
| * Flag to enable/disable the embedding of a provisioning profile into the app's `Contents` folder. | ||
| * Will use the profile from {@link OnlySignOptions.provisioningProfile} if provided. Otherwise, it | ||
| * searches for a `.provisionprofile` file in the current working directory. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| preEmbedProvisioningProfile?: boolean; | ||
| /** | ||
| * Path to a provisioning profile, which can be used to grant restricted entitlements to your app. | ||
| * | ||
| * See [Apple Documentation](https://developer.apple.com/documentation/technotes/tn3125-inside-code-signing-provisioning-profiles) for more details. | ||
| */ | ||
| provisioningProfile?: string; | ||
| /** | ||
| * Flag to enable/disable the `--strict` flag when verifying the signed application bundle. | ||
| * Also supports string values to specify which strict restrictions to use, see codesign man page for supported values. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| strictVerify?: boolean | string; | ||
| /** | ||
| * Type of certificate to use when signing a MAS app. | ||
| * @defaultValue `"distribution"` | ||
| */ | ||
| type?: SigningDistributionType; | ||
| /** | ||
| * Build version of Electron. Values may be like: `1.1.1`, `1.2.0`. For use for signing legacy versions | ||
| * of Electron to ensure backwards compatibility. | ||
| */ | ||
| version?: string; | ||
| }; | ||
| type OnlyValidatedSignOptions = { | ||
| ignore?: (string | ((file: string) => boolean))[]; | ||
| type: SigningDistributionType; | ||
| }; | ||
| type OnlyFlatOptions = { | ||
| /** | ||
| * Flag to enable/disable validation for the signing identity. | ||
| * If enabled, the {@link BaseSignOptions.identity | identity} provided | ||
| * will be validated in the {@link BaseSignOptions.keychain | keychain} specified. | ||
| * | ||
| * @defaultValue `true` | ||
| */ | ||
| identityValidation?: boolean; | ||
| /** | ||
| * Path to install the bundle. | ||
| * @defaultValue `"/Applications"` | ||
| */ | ||
| install?: string; | ||
| /** | ||
| * Output path for the flattened installer package. | ||
| * Needs file extension `.pkg`. | ||
| * | ||
| * @defaultValue Inferred from the app name passed into `opts.app`. | ||
| */ | ||
| pkg?: string; | ||
| /** | ||
| * Path to a directory containing `preinstall.sh` or `postinstall.sh` scripts. | ||
| * These must be executable and will run on pre/postinstall depending on the file | ||
| * name. | ||
| * | ||
| * This option is only valid if {@link FlatOptions.platform} is set to `darwin`. | ||
| */ | ||
| scripts?: string; | ||
| }; | ||
| type OnlyValidatedFlatOptions = { | ||
| install: string; | ||
| pkg: string; | ||
| }; | ||
| /** | ||
| * Utility type that represents an `UnValidated` type after validation, | ||
| * replacing any properties in the unvalidated type that also exist in the | ||
| * `Validated` type with the validated versions. | ||
| * | ||
| * @template UnValidated - The type representing the unvalidated form. | ||
| * @template Validated - The type representing the validated form. | ||
| */ | ||
| type ValidatedForm<UnValidated, Validated> = Omit<UnValidated, keyof Validated> & Validated; | ||
| type ValidatedBaseSignOptions = Readonly<ValidatedForm<BaseSignOptions, OnlyValidatedBaseSignOptions>>; | ||
| type _SignOptions = Readonly<OnlySignOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for codesigning a packaged `.app` bundle. | ||
| * @category Codesign | ||
| */ | ||
| export interface SignOptions extends _SignOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedSignOptions = Readonly<ValidatedForm<OnlySignOptions, OnlyValidatedSignOptions> & ValidatedBaseSignOptions>; | ||
| type _FlatOptions = Readonly<OnlyFlatOptions & BaseSignOptions>; | ||
| /** | ||
| * Options for creating a flat `.pkg` installer. | ||
| * @category Flat | ||
| */ | ||
| export interface FlatOptions extends _FlatOptions { | ||
| } | ||
| /** | ||
| * @internal | ||
| */ | ||
| export type ValidatedFlatOptions = Readonly<ValidatedForm<OnlyFlatOptions, OnlyValidatedFlatOptions> & ValidatedBaseSignOptions>; | ||
| export {}; |
| export {}; | ||
| //# sourceMappingURL=types.js.map |
| {"version":3,"file":"types.js","sourceRoot":"","sources":["../../src/types.ts"],"names":[],"mappings":""} |
| import { PerFileSignOptions, ValidatedSignOptions } from './types'; | ||
| import { Identity } from './util-identities'; | ||
| import { ProvisioningProfile } from './util-provisioning-profiles'; | ||
| type ComputedOptions = { | ||
| identity: Identity; | ||
| provisioningProfile?: ProvisioningProfile; | ||
| }; | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| export declare function preAutoEntitlements(opts: ValidatedSignOptions, perFileOpts: PerFileSignOptions, computed: ComputedOptions): Promise<void | string>; | ||
| export {}; |
| import * as fs from 'fs-extra'; | ||
| import * as os from 'os'; | ||
| import * as path from 'path'; | ||
| import * as plist from 'plist'; | ||
| import { debugLog, getAppContentsPath } from './util'; | ||
| const preAuthMemo = new Map(); | ||
| /** | ||
| * This function returns a promise completing the entitlements automation: The | ||
| * process includes checking in `Info.plist` for `ElectronTeamID` or setting | ||
| * parsed value from identity, and checking in entitlements file for | ||
| * `com.apple.security.application-groups` or inserting new into array. A | ||
| * temporary entitlements file may be created to replace the input for any | ||
| * changes introduced. | ||
| */ | ||
| export async function preAutoEntitlements(opts, perFileOpts, computed) { | ||
| var _a; | ||
| if (!perFileOpts.entitlements) | ||
| return; | ||
| const memoKey = [opts.app, perFileOpts.entitlements].join('---'); | ||
| if (preAuthMemo.has(memoKey)) | ||
| return preAuthMemo.get(memoKey); | ||
| // If entitlements file not provided, default will be used. Fixes #41 | ||
| const appInfoPath = path.join(getAppContentsPath(opts), 'Info.plist'); | ||
| debugLog('Automating entitlement app group...', '\n', '> Info.plist:', appInfoPath, '\n'); | ||
| let entitlements; | ||
| if (typeof perFileOpts.entitlements === 'string') { | ||
| const entitlementsContents = await fs.readFile(perFileOpts.entitlements, 'utf8'); | ||
| entitlements = plist.parse(entitlementsContents); | ||
| } | ||
| else { | ||
| entitlements = perFileOpts.entitlements.reduce((dict, entitlementKey) => (Object.assign(Object.assign({}, dict), { [entitlementKey]: true })), {}); | ||
| } | ||
| if (!entitlements['com.apple.security.app-sandbox']) { | ||
| // Only automate when app sandbox enabled by user | ||
| return; | ||
| } | ||
| const appInfoContents = await fs.readFile(appInfoPath, 'utf8'); | ||
| const appInfo = plist.parse(appInfoContents); | ||
| // Use ElectronTeamID in Info.plist if already specified | ||
| if (appInfo.ElectronTeamID) { | ||
| debugLog('`ElectronTeamID` found in `Info.plist`: ' + appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| // The team identifier in signing identity should not be trusted | ||
| if (computed.provisioningProfile) { | ||
| appInfo.ElectronTeamID = | ||
| computed.provisioningProfile.message.Entitlements['com.apple.developer.team-identifier']; | ||
| debugLog('`ElectronTeamID` not found in `Info.plist`, use parsed from provisioning profile: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| else { | ||
| const teamID = (_a = /^.+\((.+?)\)$/g.exec(computed.identity.name)) === null || _a === void 0 ? void 0 : _a[1]; | ||
| if (!teamID) { | ||
| throw new Error(`Could not automatically determine ElectronTeamID from identity: ${computed.identity.name}`); | ||
| } | ||
| appInfo.ElectronTeamID = teamID; | ||
| debugLog('`ElectronTeamID` not found in `Info.plist`, use parsed from signing identity: ' + | ||
| appInfo.ElectronTeamID); | ||
| } | ||
| await fs.writeFile(appInfoPath, plist.build(appInfo), 'utf8'); | ||
| debugLog('`Info.plist` updated:', '\n', '> Info.plist:', appInfoPath); | ||
| } | ||
| const appIdentifier = appInfo.ElectronTeamID + '.' + appInfo.CFBundleIdentifier; | ||
| // Insert application identifier if not exists | ||
| if (entitlements['com.apple.application-identifier']) { | ||
| debugLog('`com.apple.application-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.application-identifier']); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.application-identifier` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.application-identifier'] = appIdentifier; | ||
| } | ||
| // Insert developer team identifier if not exists | ||
| if (entitlements['com.apple.developer.team-identifier']) { | ||
| debugLog('`com.apple.developer.team-identifier` found in entitlements file: ' + | ||
| entitlements['com.apple.developer.team-identifier']); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.developer.team-identifier` not found in entitlements file, new inserted: ' + | ||
| appInfo.ElectronTeamID); | ||
| entitlements['com.apple.developer.team-identifier'] = appInfo.ElectronTeamID; | ||
| } | ||
| // Init entitlements app group key to array if not exists | ||
| if (!entitlements['com.apple.security.application-groups']) { | ||
| entitlements['com.apple.security.application-groups'] = []; | ||
| } | ||
| // Insert app group if not exists | ||
| if (Array.isArray(entitlements['com.apple.security.application-groups']) && | ||
| entitlements['com.apple.security.application-groups'].indexOf(appIdentifier) === -1) { | ||
| debugLog('`com.apple.security.application-groups` not found in entitlements file, new inserted: ' + | ||
| appIdentifier); | ||
| entitlements['com.apple.security.application-groups'].push(appIdentifier); | ||
| } | ||
| else { | ||
| debugLog('`com.apple.security.application-groups` found in entitlements file: ' + appIdentifier); | ||
| } | ||
| // Create temporary entitlements file | ||
| const dir = await fs.mkdtemp(path.resolve(os.tmpdir(), 'tmp-entitlements-')); | ||
| const entitlementsPath = path.join(dir, 'entitlements.plist'); | ||
| await fs.writeFile(entitlementsPath, plist.build(entitlements), 'utf8'); | ||
| debugLog('Entitlements file updated:', '\n', '> Entitlements:', entitlementsPath); | ||
| preAuthMemo.set(memoKey, entitlementsPath); | ||
| return entitlementsPath; | ||
| } | ||
| //# sourceMappingURL=util-entitlements.js.map |
| {"version":3,"file":"util-entitlements.js","sourceRoot":"","sources":["../../src/util-entitlements.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,EAAE,MAAM,UAAU,CAAC;AAC/B,OAAO,KAAK,EAAE,MAAM,IAAI,CAAC;AACzB,OAAO,KAAK,IAAI,MAAM,MAAM,CAAC;AAC7B,OAAO,KAAK,KAAK,MAAM,OAAO,CAAC;AAE/B,OAAO,EAAE,QAAQ,EAAE,kBAAkB,EAAE,MAAM,QAAQ,CAAC;AAStD,MAAM,WAAW,GAAG,IAAI,GAAG,EAAkB,CAAC;AAE9C;;;;;;;GAOG;AACH,MAAM,CAAC,KAAK,UAAU,mBAAmB,CACvC,IAA0B,EAC1B,WAA+B,EAC/B,QAAyB;;IAEzB,IAAI,CAAC,WAAW,CAAC,YAAY;QAAE,OAAO;IAEtC,MAAM,OAAO,GAAG,CAAC,IAAI,CAAC,GAAG,EAAE,WAAW,CAAC,YAAY,CAAC,CAAC,IAAI,CAAC,KAAK,CAAC,CAAC;IACjE,IAAI,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC;QAAE,OAAO,WAAW,CAAC,GAAG,CAAC,OAAO,CAAC,CAAC;IAE9D,qEAAqE;IACrE,MAAM,WAAW,GAAG,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;IAEtE,QAAQ,CACN,qCAAqC,EACrC,IAAI,EACJ,eAAe,EACf,WAAW,EACX,IAAI,CACL,CAAC;IACF,IAAI,YAAiC,CAAC;IACtC,IAAI,OAAO,WAAW,CAAC,YAAY,KAAK,QAAQ,EAAE;QAChD,MAAM,oBAAoB,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,WAAW,CAAC,YAAY,EAAE,MAAM,CAAC,CAAC;QACjF,YAAY,GAAG,KAAK,CAAC,KAAK,CAAC,oBAAoB,CAAwB,CAAC;KACzE;SAAM;QACL,YAAY,GAAG,WAAW,CAAC,YAAY,CAAC,MAAM,CAAsB,CAAC,IAAI,EAAE,cAAc,EAAE,EAAE,CAAC,iCACzF,IAAI,KACP,CAAC,cAAc,CAAC,EAAE,IAAI,IACtB,EAAE,EAAE,CAAC,CAAC;KACT;IACD,IAAI,CAAC,YAAY,CAAC,gCAAgC,CAAC,EAAE;QACnD,iDAAiD;QACjD,OAAO;KACR;IAED,MAAM,eAAe,GAAG,MAAM,EAAE,CAAC,QAAQ,CAAC,WAAW,EAAE,MAAM,CAAC,CAAC;IAC/D,MAAM,OAAO,GAAG,KAAK,CAAC,KAAK,CAAC,eAAe,CAAwB,CAAC;IACpE,wDAAwD;IACxD,IAAI,OAAO,CAAC,cAAc,EAAE;QAC1B,QAAQ,CAAC,0CAA0C,GAAG,OAAO,CAAC,cAAc,CAAC,CAAC;KAC/E;SAAM;QACL,gEAAgE;QAChE,IAAI,QAAQ,CAAC,mBAAmB,EAAE;YAChC,OAAO,CAAC,cAAc;gBACpB,QAAQ,CAAC,mBAAmB,CAAC,OAAO,CAAC,YAAY,CAAC,qCAAqC,CAAC,CAAC;YAC3F,QAAQ,CACN,oFAAoF;gBAClF,OAAO,CAAC,cAAc,CACzB,CAAC;SACH;aAAM;YACL,MAAM,MAAM,GAAG,MAAA,gBAAgB,CAAC,IAAI,CAAC,QAAQ,CAAC,QAAQ,CAAC,IAAI,CAAC,0CAAG,CAAC,CAAC,CAAC;YAClE,IAAI,CAAC,MAAM,EAAE;gBACX,MAAM,IAAI,KAAK,CAAC,mEAAmE,QAAQ,CAAC,QAAQ,CAAC,IAAI,EAAE,CAAC,CAAC;aAC9G;YACD,OAAO,CAAC,cAAc,GAAG,MAAM,CAAC;YAChC,QAAQ,CACN,gFAAgF;gBAC9E,OAAO,CAAC,cAAc,CACzB,CAAC;SACH;QACD,MAAM,EAAE,CAAC,SAAS,CAAC,WAAW,EAAE,KAAK,CAAC,KAAK,CAAC,OAAO,CAAC,EAAE,MAAM,CAAC,CAAC;QAE9D,QAAQ,CAAC,uBAAuB,EAAE,IAAI,EAAE,eAAe,EAAE,WAAW,CAAC,CAAC;KACvE;IAED,MAAM,aAAa,GAAG,OAAO,CAAC,cAAc,GAAG,GAAG,GAAG,OAAO,CAAC,kBAAkB,CAAC;IAChF,8CAA8C;IAC9C,IAAI,YAAY,CAAC,kCAAkC,CAAC,EAAE;QACpD,QAAQ,CACN,iEAAiE;YAC/D,YAAY,CAAC,kCAAkC,CAAC,CACnD,CAAC;KACH;SAAM;QACL,QAAQ,CACN,mFAAmF;YACjF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,kCAAkC,CAAC,GAAG,aAAa,CAAC;KAClE;IACD,iDAAiD;IACjD,IAAI,YAAY,CAAC,qCAAqC,CAAC,EAAE;QACvD,QAAQ,CACN,oEAAoE;YAClE,YAAY,CAAC,qCAAqC,CAAC,CACtD,CAAC;KACH;SAAM;QACL,QAAQ,CACN,sFAAsF;YACpF,OAAO,CAAC,cAAc,CACzB,CAAC;QACF,YAAY,CAAC,qCAAqC,CAAC,GAAG,OAAO,CAAC,cAAc,CAAC;KAC9E;IACD,yDAAyD;IACzD,IAAI,CAAC,YAAY,CAAC,uCAAuC,CAAC,EAAE;QAC1D,YAAY,CAAC,uCAAuC,CAAC,GAAG,EAAE,CAAC;KAC5D;IACD,iCAAiC;IACjC,IACE,KAAK,CAAC,OAAO,CAAC,YAAY,CAAC,uCAAuC,CAAC,CAAC;QACpE,YAAY,CAAC,uCAAuC,CAAC,CAAC,OAAO,CAAC,aAAa,CAAC,KAAK,CAAC,CAAC,EACnF;QACA,QAAQ,CACN,wFAAwF;YACtF,aAAa,CAChB,CAAC;QACF,YAAY,CAAC,uCAAuC,CAAC,CAAC,IAAI,CAAC,aAAa,CAAC,CAAC;KAC3E;SAAM;QACL,QAAQ,CACN,sEAAsE,GAAG,aAAa,CACvF,CAAC;KACH;IACD,qCAAqC;IACrC,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC,MAAM,EAAE,EAAE,mBAAmB,CAAC,CAAC,CAAC;IAC7E,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,oBAAoB,CAAC,CAAC;IAC9D,MAAM,EAAE,CAAC,SAAS,CAAC,gBAAgB,EAAE,KAAK,CAAC,KAAK,CAAC,YAAY,CAAC,EAAE,MAAM,CAAC,CAAC;IACxE,QAAQ,CAAC,4BAA4B,EAAE,IAAI,EAAE,iBAAiB,EAAE,gBAAgB,CAAC,CAAC;IAElF,WAAW,CAAC,GAAG,CAAC,OAAO,EAAE,gBAAgB,CAAC,CAAC;IAC3C,OAAO,gBAAgB,CAAC;AAC1B,CAAC"} |
| export declare class Identity { | ||
| name: string; | ||
| hash?: string | undefined; | ||
| constructor(name: string, hash?: string | undefined); | ||
| } | ||
| export declare function findIdentities(keychain: string | null, identity: string): Promise<Identity[]>; |
| import { debugLog, compactFlattenedList, execFileAsync } from './util'; | ||
| export class Identity { | ||
| constructor(name, hash) { | ||
| this.name = name; | ||
| this.hash = hash; | ||
| } | ||
| } | ||
| export async function findIdentities(keychain, identity) { | ||
| // Only to look for valid identities, excluding those flagged with | ||
| // CSSMERR_TP_CERT_EXPIRED or CSSMERR_TP_NOT_TRUSTED. Fixes #9 | ||
| const args = [ | ||
| 'find-identity', | ||
| '-v' | ||
| ]; | ||
| if (keychain) { | ||
| args.push(keychain); | ||
| } | ||
| const result = await execFileAsync('security', args); | ||
| const identities = result.split('\n').map(function (line) { | ||
| if (line.indexOf(identity) >= 0) { | ||
| const identityFound = line.substring(line.indexOf('"') + 1, line.lastIndexOf('"')); | ||
| const identityHashFound = line.substring(line.indexOf(')') + 2, line.indexOf('"') - 1); | ||
| debugLog('Identity:', '\n', '> Name:', identityFound, '\n', '> Hash:', identityHashFound); | ||
| return new Identity(identityFound, identityHashFound); | ||
| } | ||
| return null; | ||
| }); | ||
| return compactFlattenedList(identities); | ||
| } | ||
| //# sourceMappingURL=util-identities.js.map |
| {"version":3,"file":"util-identities.js","sourceRoot":"","sources":["../../src/util-identities.ts"],"names":[],"mappings":"AAAA,OAAO,EAAE,QAAQ,EAAE,oBAAoB,EAAE,aAAa,EAAE,MAAM,QAAQ,CAAC;AAEvE,MAAM,OAAO,QAAQ;IACnB,YAAoB,IAAY,EAAS,IAAa;QAAlC,SAAI,GAAJ,IAAI,CAAQ;QAAS,SAAI,GAAJ,IAAI,CAAS;IAAG,CAAC;CAC3D;AAED,MAAM,CAAC,KAAK,UAAU,cAAc,CAAE,QAAuB,EAAE,QAAgB;IAC7E,kEAAkE;IAClE,8DAA8D;IAE9D,MAAM,IAAI,GAAG;QACX,eAAe;QACf,IAAI;KACL,CAAC;IACF,IAAI,QAAQ,EAAE;QACZ,IAAI,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;KACrB;IAED,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE,IAAI,CAAC,CAAC;IACrD,MAAM,UAAU,GAAG,MAAM,CAAC,KAAK,CAAC,IAAI,CAAC,CAAC,GAAG,CAAC,UAAU,IAAI;QACtD,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,IAAI,CAAC,EAAE;YAC/B,MAAM,aAAa,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,WAAW,CAAC,GAAG,CAAC,CAAC,CAAC;YACnF,MAAM,iBAAiB,GAAG,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,GAAG,CAAC,CAAC,CAAC;YACvF,QAAQ,CAAC,WAAW,EAAE,IAAI,EACxB,SAAS,EAAE,aAAa,EAAE,IAAI,EAC9B,SAAS,EAAE,iBAAiB,CAAC,CAAC;YAChC,OAAO,IAAI,QAAQ,CAAC,aAAa,EAAE,iBAAiB,CAAC,CAAC;SACvD;QAED,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CAAC;IAEH,OAAO,oBAAoB,CAAC,UAAU,CAAC,CAAC;AAC1C,CAAC"} |
| import { ElectronMacPlatform, ValidatedSignOptions } from './types'; | ||
| export declare class ProvisioningProfile { | ||
| filePath: string; | ||
| message: any; | ||
| constructor(filePath: string, message: any); | ||
| get name(): string; | ||
| get platforms(): ElectronMacPlatform[]; | ||
| get type(): "development" | "distribution"; | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| export declare function getProvisioningProfile(filePath: string, keychain?: string | null): Promise<ProvisioningProfile>; | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| export declare function findProvisioningProfiles(opts: ValidatedSignOptions): Promise<ProvisioningProfile[]>; | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| export declare function preEmbedProvisioningProfile(opts: ValidatedSignOptions, profile: ProvisioningProfile | null): Promise<void>; |
| import * as fs from 'fs-extra'; | ||
| import * as path from 'path'; | ||
| import plist from 'plist'; | ||
| import { debugLog, debugWarn, getAppContentsPath, compactFlattenedList, execFileAsync } from './util'; | ||
| export class ProvisioningProfile { | ||
| constructor(filePath, message) { | ||
| this.filePath = filePath; | ||
| this.message = message; | ||
| } | ||
| get name() { | ||
| return this.message.Name; | ||
| } | ||
| get platforms() { | ||
| if ('ProvisionsAllDevices' in this.message) | ||
| return ['darwin']; | ||
| // Developer ID | ||
| else if (this.type === 'distribution') | ||
| return ['mas']; | ||
| // Mac App Store | ||
| else | ||
| return ['darwin', 'mas']; // Mac App Development | ||
| } | ||
| get type() { | ||
| if ('ProvisionedDevices' in this.message) | ||
| return 'development'; | ||
| // Mac App Development | ||
| else | ||
| return 'distribution'; // Developer ID or Mac App Store | ||
| } | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a ProvisioningProfile instance based on file. | ||
| * @function | ||
| * @param {string} filePath - Path to provisioning profile. | ||
| * @param {string} keychain - Keychain to use when unlocking provisioning profile. | ||
| * @returns {Promise} Promise. | ||
| */ | ||
| export async function getProvisioningProfile(filePath, keychain = null) { | ||
| const securityArgs = [ | ||
| 'cms', | ||
| '-D', | ||
| '-i', | ||
| filePath // Use infile as source of data | ||
| ]; | ||
| if (keychain) { | ||
| securityArgs.push('-k', keychain); | ||
| } | ||
| const result = await execFileAsync('security', securityArgs); | ||
| const provisioningProfile = new ProvisioningProfile(filePath, plist.parse(result)); | ||
| debugLog('Provisioning profile:', '\n', '> Name:', provisioningProfile.name, '\n', '> Platforms:', provisioningProfile.platforms, '\n', '> Type:', provisioningProfile.type, '\n', '> Path:', provisioningProfile.filePath, '\n', '> Message:', provisioningProfile.message); | ||
| return provisioningProfile; | ||
| } | ||
| /** | ||
| * Returns a promise resolving to a list of suitable provisioning profile within the current working directory. | ||
| */ | ||
| export async function findProvisioningProfiles(opts) { | ||
| const cwd = process.cwd(); | ||
| const children = await fs.readdir(cwd); | ||
| const foundProfiles = compactFlattenedList(await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(cwd, child); | ||
| const stat = await fs.stat(filePath); | ||
| if (stat.isFile() && path.extname(filePath) === '.provisionprofile') { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| }))); | ||
| return compactFlattenedList(await Promise.all(foundProfiles.map(async (filePath) => { | ||
| const profile = await getProvisioningProfile(filePath); | ||
| if (profile.platforms.indexOf(opts.platform) >= 0 && profile.type === opts.type) { | ||
| return profile; | ||
| } | ||
| debugWarn('Provisioning profile above ignored, not for ' + opts.platform + ' ' + opts.type + '.'); | ||
| return null; | ||
| }))); | ||
| } | ||
| /** | ||
| * Returns a promise embedding the provisioning profile in the app Contents folder. | ||
| */ | ||
| export async function preEmbedProvisioningProfile(opts, profile) { | ||
| async function embedProvisioningProfile(profile) { | ||
| debugLog('Looking for existing provisioning profile...'); | ||
| const embeddedFilePath = path.join(getAppContentsPath(opts), 'embedded.provisionprofile'); | ||
| if (await fs.pathExists(embeddedFilePath)) { | ||
| debugLog('Found embedded provisioning profile:', '\n', '* Please manually remove the existing file if not wanted.', '\n', '* Current file at:', embeddedFilePath); | ||
| } | ||
| else { | ||
| debugLog('Embedding provisioning profile...'); | ||
| await fs.copy(profile.filePath, embeddedFilePath); | ||
| } | ||
| } | ||
| if (profile) { | ||
| // User input provisioning profile | ||
| return await embedProvisioningProfile(profile); | ||
| } | ||
| else { | ||
| // Discover provisioning profile | ||
| debugLog('No `provisioning-profile` passed in arguments, will find in current working directory and in user library...'); | ||
| const profiles = await findProvisioningProfiles(opts); | ||
| if (profiles.length > 0) { | ||
| // Provisioning profile(s) found | ||
| if (profiles.length > 1) { | ||
| debugLog('Multiple provisioning profiles found, will use the first discovered.'); | ||
| } | ||
| else { | ||
| debugLog('Found 1 provisioning profile.'); | ||
| } | ||
| await embedProvisioningProfile(profiles[0]); | ||
| } | ||
| else { | ||
| // No provisioning profile found | ||
| debugLog('No provisioning profile found, will not embed profile in app contents.'); | ||
| } | ||
| } | ||
| } | ||
| //# sourceMappingURL=util-provisioning-profiles.js.map |
| {"version":3,"file":"util-provisioning-profiles.js","sourceRoot":"","sources":["../../src/util-provisioning-profiles.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,EAAE,MAAM,UAAU,CAAC;AAC/B,OAAO,KAAK,IAAI,MAAM,MAAM,CAAC;AAC7B,OAAO,KAAK,MAAM,OAAO,CAAC;AAG1B,OAAO,EAAE,QAAQ,EAAE,SAAS,EAAE,kBAAkB,EAAE,oBAAoB,EAAE,aAAa,EAAE,MAAM,QAAQ,CAAC;AAEtG,MAAM,OAAO,mBAAmB;IAC9B,YAAoB,QAAgB,EAAS,OAAY;QAArC,aAAQ,GAAR,QAAQ,CAAQ;QAAS,YAAO,GAAP,OAAO,CAAK;IAAG,CAAC;IAE7D,IAAI,IAAI;QACN,OAAO,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC;IAC3B,CAAC;IAED,IAAI,SAAS;QACX,IAAI,sBAAsB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,CAAC,QAAQ,CAAC,CAAC;QAC9D,eAAe;aACV,IAAI,IAAI,CAAC,IAAI,KAAK,cAAc;YAAE,OAAO,CAAC,KAAK,CAAC,CAAC;QACtD,gBAAgB;;YACX,OAAO,CAAC,QAAQ,EAAE,KAAK,CAAC,CAAC,CAAC,sBAAsB;IACvD,CAAC;IAED,IAAI,IAAI;QACN,IAAI,oBAAoB,IAAI,IAAI,CAAC,OAAO;YAAE,OAAO,aAAa,CAAC;QAC/D,sBAAsB;;YACjB,OAAO,cAAc,CAAC,CAAC,gCAAgC;IAC9D,CAAC;CACF;AAED;;;;;;GAMG;AACH,MAAM,CAAC,KAAK,UAAU,sBAAsB,CAAE,QAAgB,EAAE,WAA0B,IAAI;IAC5F,MAAM,YAAY,GAAG;QACnB,KAAK;QACL,IAAI;QACJ,IAAI;QACJ,QAAQ,CAAC,+BAA+B;KACzC,CAAC;IAEF,IAAI,QAAQ,EAAE;QACZ,YAAY,CAAC,IAAI,CAAC,IAAI,EAAE,QAAQ,CAAC,CAAC;KACnC;IAED,MAAM,MAAM,GAAG,MAAM,aAAa,CAAC,UAAU,EAAE,YAAY,CAAC,CAAC;IAC7D,MAAM,mBAAmB,GAAG,IAAI,mBAAmB,CAAC,QAAQ,EAAE,KAAK,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC,CAAC;IACnF,QAAQ,CACN,uBAAuB,EACvB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,cAAc,EACd,mBAAmB,CAAC,SAAS,EAC7B,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,IAAI,EACxB,IAAI,EACJ,SAAS,EACT,mBAAmB,CAAC,QAAQ,EAC5B,IAAI,EACJ,YAAY,EACZ,mBAAmB,CAAC,OAAO,CAC5B,CAAC;IACF,OAAO,mBAAmB,CAAC;AAC7B,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,wBAAwB,CAAE,IAA0B;IACxE,MAAM,GAAG,GAAG,OAAO,CAAC,GAAG,EAAE,CAAC;IAC1B,MAAM,QAAQ,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,GAAG,CAAC,CAAC;IACvC,MAAM,aAAa,GAAG,oBAAoB,CACxC,MAAM,OAAO,CAAC,GAAG,CACf,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;QAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,GAAG,EAAE,KAAK,CAAC,CAAC;QAC1C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;QACrC,IAAI,IAAI,CAAC,MAAM,EAAE,IAAI,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,KAAK,mBAAmB,EAAE;YACnE,OAAO,QAAQ,CAAC;SACjB;QACD,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;IAEF,OAAO,oBAAoB,CACzB,MAAM,OAAO,CAAC,GAAG,CACf,aAAa,CAAC,GAAG,CAAC,KAAK,EAAE,QAAQ,EAAE,EAAE;QACnC,MAAM,OAAO,GAAG,MAAM,sBAAsB,CAAC,QAAQ,CAAC,CAAC;QACvD,IAAI,OAAO,CAAC,SAAS,CAAC,OAAO,CAAC,IAAI,CAAC,QAAQ,CAAC,IAAI,CAAC,IAAI,OAAO,CAAC,IAAI,KAAK,IAAI,CAAC,IAAI,EAAE;YAAE,OAAO,OAAO,CAAC;SAAE;QACpG,SAAS,CACP,8CAA8C,GAAG,IAAI,CAAC,QAAQ,GAAG,GAAG,GAAG,IAAI,CAAC,IAAI,GAAG,GAAG,CACvF,CAAC;QACF,OAAO,IAAI,CAAC;IACd,CAAC,CAAC,CACH,CACF,CAAC;AACJ,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,2BAA2B,CAAE,IAA0B,EAAE,OAAmC;IAChH,KAAK,UAAU,wBAAwB,CAAE,OAA4B;QACnE,QAAQ,CAAC,8CAA8C,CAAC,CAAC;QACzD,MAAM,gBAAgB,GAAG,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,2BAA2B,CAAC,CAAC;QAE1F,IAAI,MAAM,EAAE,CAAC,UAAU,CAAC,gBAAgB,CAAC,EAAE;YACzC,QAAQ,CACN,sCAAsC,EACtC,IAAI,EACJ,2DAA2D,EAC3D,IAAI,EACJ,oBAAoB,EACpB,gBAAgB,CACjB,CAAC;SACH;aAAM;YACL,QAAQ,CAAC,mCAAmC,CAAC,CAAC;YAC9C,MAAM,EAAE,CAAC,IAAI,CAAC,OAAO,CAAC,QAAQ,EAAE,gBAAgB,CAAC,CAAC;SACnD;IACH,CAAC;IAED,IAAI,OAAO,EAAE;QACX,kCAAkC;QAClC,OAAO,MAAM,wBAAwB,CAAC,OAAO,CAAC,CAAC;KAChD;SAAM;QACL,gCAAgC;QAChC,QAAQ,CACN,8GAA8G,CAC/G,CAAC;QACF,MAAM,QAAQ,GAAG,MAAM,wBAAwB,CAAC,IAAI,CAAC,CAAC;QACtD,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE;YACvB,gCAAgC;YAChC,IAAI,QAAQ,CAAC,MAAM,GAAG,CAAC,EAAE;gBACvB,QAAQ,CAAC,sEAAsE,CAAC,CAAC;aAClF;iBAAM;gBACL,QAAQ,CAAC,+BAA+B,CAAC,CAAC;aAC3C;YACD,MAAM,wBAAwB,CAAC,QAAQ,CAAC,CAAC,CAAC,CAAC,CAAC;SAC7C;aAAM;YACL,gCAAgC;YAChC,QAAQ,CAAC,wEAAwE,CAAC,CAAC;SACpF;KACF;AACH,CAAC"} |
| /// <reference types="node" /> | ||
| import * as child from 'child_process'; | ||
| import debug from 'debug'; | ||
| import { BaseSignOptions, ElectronMacPlatform } from './types'; | ||
| export declare const debugLog: debug.Debugger; | ||
| export declare const debugWarn: debug.Debugger; | ||
| export declare function execFileAsync(file: string, args: string[], options?: child.ExecFileOptions): Promise<string>; | ||
| type DeepListItem<T> = null | T | DeepListItem<T>[]; | ||
| type DeepList<T> = DeepListItem<T>[]; | ||
| export declare function compactFlattenedList<T>(list: DeepList<T>): T[]; | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| export declare function getAppContentsPath(opts: BaseSignOptions): string; | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| export declare function getAppFrameworksPath(opts: BaseSignOptions): string; | ||
| export declare function detectElectronPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| export declare function validateOptsApp(opts: BaseSignOptions): Promise<void>; | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| export declare function validateOptsPlatform(opts: BaseSignOptions): Promise<ElectronMacPlatform>; | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| export declare function walkAsync(dirPath: string): Promise<string[]>; | ||
| export {}; |
-146
| import * as child from 'child_process'; | ||
| import * as fs from 'fs-extra'; | ||
| import { isBinaryFile } from 'isbinaryfile'; | ||
| import * as path from 'path'; | ||
| import debug from 'debug'; | ||
| export const debugLog = debug('electron-osx-sign'); | ||
| debugLog.log = console.log.bind(console); | ||
| export const debugWarn = debug('electron-osx-sign:warn'); | ||
| debugWarn.log = console.warn.bind(console); | ||
| const removePassword = function (input) { | ||
| return input.replace(/(-P |pass:|\/p|-pass )([^ ]+)/, function (_, p1) { | ||
| return `${p1}***`; | ||
| }); | ||
| }; | ||
| export async function execFileAsync(file, args, options = {}) { | ||
| if (debugLog.enabled) { | ||
| debugLog('Executing...', file, args && Array.isArray(args) ? removePassword(args.join(' ')) : ''); | ||
| } | ||
| return new Promise(function (resolve, reject) { | ||
| child.execFile(file, args, options, function (err, stdout, stderr) { | ||
| if (err) { | ||
| debugLog('Error executing file:', '\n', '> Stdout:', stdout, '\n', '> Stderr:', stderr); | ||
| reject(err); | ||
| return; | ||
| } | ||
| resolve(stdout); | ||
| }); | ||
| }); | ||
| } | ||
| export function compactFlattenedList(list) { | ||
| const result = []; | ||
| function populateResult(list) { | ||
| if (!Array.isArray(list)) { | ||
| if (list) | ||
| result.push(list); | ||
| } | ||
| else if (list.length > 0) { | ||
| for (const item of list) | ||
| if (item) | ||
| populateResult(item); | ||
| } | ||
| } | ||
| populateResult(list); | ||
| return result; | ||
| } | ||
| /** | ||
| * Returns the path to the "Contents" folder inside the application bundle | ||
| */ | ||
| export function getAppContentsPath(opts) { | ||
| return path.join(opts.app, 'Contents'); | ||
| } | ||
| /** | ||
| * Returns the path to app "Frameworks" within contents. | ||
| */ | ||
| export function getAppFrameworksPath(opts) { | ||
| return path.join(getAppContentsPath(opts), 'Frameworks'); | ||
| } | ||
| export async function detectElectronPlatform(opts) { | ||
| const appFrameworksPath = getAppFrameworksPath(opts); | ||
| if (await fs.pathExists(path.resolve(appFrameworksPath, 'Squirrel.framework'))) { | ||
| return 'darwin'; | ||
| } | ||
| else { | ||
| return 'mas'; | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise resolving the file path if file binary. | ||
| */ | ||
| async function getFilePathIfBinary(filePath) { | ||
| if (await isBinaryFile(filePath)) { | ||
| return filePath; | ||
| } | ||
| return null; | ||
| } | ||
| /** | ||
| * This function returns a promise validating opts.app, the application to be signed or flattened. | ||
| */ | ||
| export async function validateOptsApp(opts) { | ||
| if (!opts.app) { | ||
| throw new Error('Path to application must be specified.'); | ||
| } | ||
| if (path.extname(opts.app) !== '.app') { | ||
| throw new Error('Extension of application must be `.app`.'); | ||
| } | ||
| if (!(await fs.pathExists(opts.app))) { | ||
| throw new Error(`Application at path "${opts.app}" could not be found`); | ||
| } | ||
| } | ||
| /** | ||
| * This function returns a promise validating opts.platform, the platform of Electron build. It allows auto-discovery if no opts.platform is specified. | ||
| */ | ||
| export async function validateOptsPlatform(opts) { | ||
| if (opts.platform) { | ||
| if (opts.platform === 'mas' || opts.platform === 'darwin') { | ||
| return opts.platform; | ||
| } | ||
| else { | ||
| debugWarn('`platform` passed in arguments not supported, checking Electron platform...'); | ||
| } | ||
| } | ||
| else { | ||
| debugWarn('No `platform` passed in arguments, checking Electron platform...'); | ||
| } | ||
| return await detectElectronPlatform(opts); | ||
| } | ||
| /** | ||
| * This function returns a promise resolving all child paths within the directory specified. | ||
| * @function | ||
| * @param {string} dirPath - Path to directory. | ||
| * @returns {Promise} Promise resolving child paths needing signing in order. | ||
| * @internal | ||
| */ | ||
| export async function walkAsync(dirPath) { | ||
| debugLog('Walking... ' + dirPath); | ||
| async function _walkAsync(dirPath) { | ||
| const children = await fs.readdir(dirPath); | ||
| return await Promise.all(children.map(async (child) => { | ||
| const filePath = path.resolve(dirPath, child); | ||
| const stat = await fs.stat(filePath); | ||
| if (stat.isFile()) { | ||
| switch (path.extname(filePath)) { | ||
| case '.cstemp': // Temporary file generated from past codesign | ||
| debugLog('Removing... ' + filePath); | ||
| await fs.remove(filePath); | ||
| return null; | ||
| default: | ||
| return await getFilePathIfBinary(filePath); | ||
| } | ||
| } | ||
| else if (stat.isDirectory() && !stat.isSymbolicLink()) { | ||
| const walkResult = await _walkAsync(filePath); | ||
| switch (path.extname(filePath)) { | ||
| case '.app': // Application | ||
| case '.framework': // Framework | ||
| walkResult.push(filePath); | ||
| } | ||
| return walkResult; | ||
| } | ||
| return null; | ||
| })); | ||
| } | ||
| const allPaths = await _walkAsync(dirPath); | ||
| return compactFlattenedList(allPaths); | ||
| } | ||
| //# sourceMappingURL=util.js.map |
| {"version":3,"file":"util.js","sourceRoot":"","sources":["../../src/util.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,KAAK,MAAM,eAAe,CAAC;AACvC,OAAO,KAAK,EAAE,MAAM,UAAU,CAAC;AAC/B,OAAO,EAAE,YAAY,EAAE,MAAM,cAAc,CAAC;AAC5C,OAAO,KAAK,IAAI,MAAM,MAAM,CAAC;AAE7B,OAAO,KAAK,MAAM,OAAO,CAAC;AAG1B,MAAM,CAAC,MAAM,QAAQ,GAAG,KAAK,CAAC,mBAAmB,CAAC,CAAC;AACnD,QAAQ,CAAC,GAAG,GAAG,OAAO,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAEzC,MAAM,CAAC,MAAM,SAAS,GAAG,KAAK,CAAC,wBAAwB,CAAC,CAAC;AACzD,SAAS,CAAC,GAAG,GAAG,OAAO,CAAC,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AAE3C,MAAM,cAAc,GAAG,UAAU,KAAa;IAC5C,OAAO,KAAK,CAAC,OAAO,CAAC,+BAA+B,EAAE,UAAU,CAAC,EAAE,EAAE;QACnE,OAAO,GAAG,EAAE,KAAK,CAAC;IACpB,CAAC,CAAC,CAAC;AACL,CAAC,CAAC;AAEF,MAAM,CAAC,KAAK,UAAU,aAAa,CACjC,IAAY,EACZ,IAAc,EACd,UAAiC,EAAE;IAEnC,IAAI,QAAQ,CAAC,OAAO,EAAE;QACpB,QAAQ,CACN,cAAc,EACd,IAAI,EACJ,IAAI,IAAI,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,CAAC,CAAC,CAAC,cAAc,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,CAAC,CAAC,CAAC,EAAE,CAClE,CAAC;KACH;IAED,OAAO,IAAI,OAAO,CAAC,UAAU,OAAO,EAAE,MAAM;QAC1C,KAAK,CAAC,QAAQ,CAAC,IAAI,EAAE,IAAI,EAAE,OAAO,EAAE,UAAU,GAAG,EAAE,MAAM,EAAE,MAAM;YAC/D,IAAI,GAAG,EAAE;gBACP,QAAQ,CAAC,uBAAuB,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,EAAE,IAAI,EAAE,WAAW,EAAE,MAAM,CAAC,CAAC;gBACxF,MAAM,CAAC,GAAG,CAAC,CAAC;gBACZ,OAAO;aACR;YACD,OAAO,CAAC,MAAM,CAAC,CAAC;QAClB,CAAC,CAAC,CAAC;IACL,CAAC,CAAC,CAAC;AACL,CAAC;AAKD,MAAM,UAAU,oBAAoB,CAAK,IAAiB;IACxD,MAAM,MAAM,GAAQ,EAAE,CAAC;IAEvB,SAAS,cAAc,CAAE,IAAqB;QAC5C,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,IAAI,CAAC,EAAE;YACxB,IAAI,IAAI;gBAAE,MAAM,CAAC,IAAI,CAAC,IAAI,CAAC,CAAC;SAC7B;aAAM,IAAI,IAAI,CAAC,MAAM,GAAG,CAAC,EAAE;YAC1B,KAAK,MAAM,IAAI,IAAI,IAAI;gBAAE,IAAI,IAAI;oBAAE,cAAc,CAAC,IAAI,CAAC,CAAC;SACzD;IACH,CAAC;IAED,cAAc,CAAC,IAAI,CAAC,CAAC;IACrB,OAAO,MAAM,CAAC;AAChB,CAAC;AAED;;GAEG;AACH,MAAM,UAAU,kBAAkB,CAAE,IAAqB;IACvD,OAAO,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE,UAAU,CAAC,CAAC;AACzC,CAAC;AAED;;GAEG;AACH,MAAM,UAAU,oBAAoB,CAAE,IAAqB;IACzD,OAAO,IAAI,CAAC,IAAI,CAAC,kBAAkB,CAAC,IAAI,CAAC,EAAE,YAAY,CAAC,CAAC;AAC3D,CAAC;AAED,MAAM,CAAC,KAAK,UAAU,sBAAsB,CAAE,IAAqB;IACjE,MAAM,iBAAiB,GAAG,oBAAoB,CAAC,IAAI,CAAC,CAAC;IACrD,IAAI,MAAM,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,OAAO,CAAC,iBAAiB,EAAE,oBAAoB,CAAC,CAAC,EAAE;QAC9E,OAAO,QAAQ,CAAC;KACjB;SAAM;QACL,OAAO,KAAK,CAAC;KACd;AACH,CAAC;AAED;;GAEG;AACH,KAAK,UAAU,mBAAmB,CAAE,QAAgB;IAClD,IAAI,MAAM,YAAY,CAAC,QAAQ,CAAC,EAAE;QAChC,OAAO,QAAQ,CAAC;KACjB;IACD,OAAO,IAAI,CAAC;AACd,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,eAAe,CAAE,IAAqB;IAC1D,IAAI,CAAC,IAAI,CAAC,GAAG,EAAE;QACb,MAAM,IAAI,KAAK,CAAC,wCAAwC,CAAC,CAAC;KAC3D;IACD,IAAI,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,GAAG,CAAC,KAAK,MAAM,EAAE;QACrC,MAAM,IAAI,KAAK,CAAC,0CAA0C,CAAC,CAAC;KAC7D;IACD,IAAI,CAAC,CAAC,MAAM,EAAE,CAAC,UAAU,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,EAAE;QACpC,MAAM,IAAI,KAAK,CAAC,wBAAwB,IAAI,CAAC,GAAG,sBAAsB,CAAC,CAAC;KACzE;AACH,CAAC;AAED;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,oBAAoB,CAAE,IAAqB;IAC/D,IAAI,IAAI,CAAC,QAAQ,EAAE;QACjB,IAAI,IAAI,CAAC,QAAQ,KAAK,KAAK,IAAI,IAAI,CAAC,QAAQ,KAAK,QAAQ,EAAE;YACzD,OAAO,IAAI,CAAC,QAAQ,CAAC;SACtB;aAAM;YACL,SAAS,CAAC,6EAA6E,CAAC,CAAC;SAC1F;KACF;SAAM;QACL,SAAS,CAAC,kEAAkE,CAAC,CAAC;KAC/E;IAED,OAAO,MAAM,sBAAsB,CAAC,IAAI,CAAC,CAAC;AAC5C,CAAC;AAED;;;;;;GAMG;AACH,MAAM,CAAC,KAAK,UAAU,SAAS,CAAE,OAAe;IAC9C,QAAQ,CAAC,aAAa,GAAG,OAAO,CAAC,CAAC;IAElC,KAAK,UAAU,UAAU,CAAE,OAAe;QACxC,MAAM,QAAQ,GAAG,MAAM,EAAE,CAAC,OAAO,CAAC,OAAO,CAAC,CAAC;QAC3C,OAAO,MAAM,OAAO,CAAC,GAAG,CACtB,QAAQ,CAAC,GAAG,CAAC,KAAK,EAAE,KAAK,EAAE,EAAE;YAC3B,MAAM,QAAQ,GAAG,IAAI,CAAC,OAAO,CAAC,OAAO,EAAE,KAAK,CAAC,CAAC;YAE9C,MAAM,IAAI,GAAG,MAAM,EAAE,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;YACrC,IAAI,IAAI,CAAC,MAAM,EAAE,EAAE;gBACjB,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE;oBAC9B,KAAK,SAAS,EAAE,8CAA8C;wBAC5D,QAAQ,CAAC,cAAc,GAAG,QAAQ,CAAC,CAAC;wBACpC,MAAM,EAAE,CAAC,MAAM,CAAC,QAAQ,CAAC,CAAC;wBAC1B,OAAO,IAAI,CAAC;oBACd;wBACE,OAAO,MAAM,mBAAmB,CAAC,QAAQ,CAAC,CAAC;iBAC9C;aACF;iBAAM,IAAI,IAAI,CAAC,WAAW,EAAE,IAAI,CAAC,IAAI,CAAC,cAAc,EAAE,EAAE;gBACvD,MAAM,UAAU,GAAG,MAAM,UAAU,CAAC,QAAQ,CAAC,CAAC;gBAC9C,QAAQ,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE;oBAC9B,KAAK,MAAM,CAAC,CAAC,cAAc;oBAC3B,KAAK,YAAY,EAAE,YAAY;wBAC7B,UAAU,CAAC,IAAI,CAAC,QAAQ,CAAC,CAAC;iBAC7B;gBACD,OAAO,UAAU,CAAC;aACnB;YACD,OAAO,IAAI,CAAC;QACd,CAAC,CAAC,CACH,CAAC;IACJ,CAAC;IAED,MAAM,QAAQ,GAAG,MAAM,UAAU,CAAC,OAAO,CAAC,CAAC;IAC3C,OAAO,oBAAoB,CAAC,QAAQ,CAAC,CAAC;AACxC,CAAC"} |
Major refactor
Supply chain riskPackage has recently undergone a major refactor. It may be unstable or indicate significant internal changes. Use caution when updating to versions that include significant changes.
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
20
-13.04%3
-25%Yes
NaN100700
-48.75%37
-39.34%1295
-54.03%236
-16.61%+ Added
+ Added
+ Added
+ Added
+ Added
+ Added
+ Added
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed