
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
cordova-app-loader
Advanced tools
Remote update your Cordova App
A little later...
CordovaAppLoader
to
Based on cordova-promise-fs and cordova-file-cache.
Download and include CordovaPromiseFS.js, CordovaAppLoader.js and bootstrap.js.
With npm or bower:
bower install cordova-app-loader cordova-promise-fs
npm install cordova-app-loader cordova-promise-fs
cordova platform add ios@3.7.0
cordova plugin add org.apache.cordova.file
cordova plugin add org.apache.cordova.file-transfer
IMPORTANT: For iOS, use Cordova 3.7.0 or higher (due to a bug that affects requestFileSystem).
Check out Cordova App Loader in Chrome for a demo! (Chrome only!)
Or run on your own computer:
git clone git@github.com:markmarijnissen/cordova-app-loader.git
cd cordova-app-loader
cordova platform add ios@3.7.0
cordova plugin add org.apache.cordova.file
cordova plugin add org.apache.cordova.file-transfer
cordova run ios
Note: Want to run your own server? Modify serverRoot
in www/app.js
!
CordovaAppLoader
Describe which files to download and which files to load during bootstrap.
{
"files": { // these files are downloaded (only when "version" is different from current version!)
"jquery": {
"version": "afb90752e0a90c24b7f724faca86c5f3d15d1178",
"filename": "lib/jquery.min.js"
},
"bluebird": {
"version": "f37ff9832449594d1cefe98260cae9fdc13e0749",
"filename": "lib/bluebird.js"
},
"CordovaPromiseFS": {
"version": "635bd29385fe6664b1cf86dc16fb3d801aa9461a",
"filename": "lib/CordovaPromiseFS.js"
},
"CordovaAppLoader": {
"version": "76f1eecd3887e69d7b08c60be4f14f90069ca8b8",
"filename": "lib/CordovaAppLoader.js"
},
"template": {
"version": "3e70f2873de3d9c91e31271c1a59b32e8002ac23",
"filename": "template.html"
},
"app": {
"version": "8c99369a825644e68e21433d78ed8b396351cc7d",
"filename": "app.js"
},
"style": {
"version": "6e76f36f27bf29402a70c8adfee0f84b8a595973",
"filename": "style.css"
}
},
"load": [ // these files are loaded in your index.html
"lib/jquery.min.js",
"lib/bluebird.js",
"lib/CordovaPromiseFS.js",
"lib/CordovaAppLoader.js",
"app.js",
"style.css"
],
"root":"./", // root location of files to be loaded. Defaults to current location: `./`
}
Workflow tip: You can update your existing manifest like this:
node bin/update-manifest www www/manifest.json
node bin/update-manifest [root-directory] [manifest.json]
It will update the version of only changed files (with a hash of the content).
Retrieves manifest.json and dynamically inserts JS/CSS to the current page.
<script type="text/javascript" timeout="5000" manifest="manifest.json" src="bootstrap.js"></script>
On the second run, the manifest.json is retrieved from localStorage.
If after timeout
milliseconds window.BOOTSTRAP_OK
is not true, the (corrupt?) manifest in localStorage is destroyed, and the page will reload. So make sure you set window.BOOTSTRAP_OK = true
when your app has succesfully loaded!
Tip:
Bundle a manifest.json with your app. This way, your app will also launch when not connected to the internet. When your app is updated, it will write a new manifest.json to localStorage. If this update is corrupt, it can safely revert to the bundled manifest.json
var fs = new CordovaPromiseFS({});
var loader = window.loader = new CordovaAppLoader({
fs: fs,
serverRoot: 'http://data.madebymark.nl/cordova-app-loader/',
localRoot: 'app',
mode: 'mirror', // use same directories and filenames as in manifest (instead of using a hash)
cacheBuster: true // make sure we're not downloading cached files.
checkTimeout: 10000 // timeout for the "check" function - when you loose internet connection
});
// download manifest from: serverRoot+'manifest.json'
loader.check().then(function(updateAvailable) { ... })
// download from custom url
loader.check('http://yourserver.com/manifest.json').then( ... )
// or just check an actual Manifest object.
loader.check({ files: { ... } }).then( ... )
Implementation Note: Only file versions are compared! If you, for example, update manifest.load
then the promise will return false
!
loader.download(onprogress)
.then(function(manifest){ ... },function(failedDownloadUrlArray){ ... });
Note: When downloading, invalid files are deleted first. This invalidates the current manifest. Therefore, the current manifest is removed from localStorage. The app is reverted to "factory settings" (the manifest.json that comes bundled with the app).
This writes the new manifest to localStorage and reloads the page to bootstrap the updated app.
// write manifest to localStorage and reload page:
loader.update() // returns `true` when update can be applied
// write manifest to localStorage, but DO NOT reload page:
loader.update(false)
Implementation Note: CordovaAppLoader changes the manifest.root
to point to your file cache - otherwise the bootstrap script can't find the downloaded files!
I want CordovaAppLoader to be fast, responsive, reliable and safe. In order to do this, I've made the following decisions:
First, I wanted to download 'index.html' to storage, then redirect the app to this new index.html.
This has a few problems:
cordova.js
and plugin javascript cannot be found.cordova.js
in the manifest because it is platform specific.Dynamically inserting CSS and JS allows you for almost the same freedom in updates, without all these problems.
loader.download()
for the second time, old downloads are aborted.check
and download
return a promise. These promises should always resolve - i.e. don't wait forever for a "deviceready" or for a "manifest.json" AJAX call to return.
I am assuming the following promises resolve or reject sometime:
requestFileSystem
CordovaPromiseFS methods:
fs.root.getFile
)fs.root.getDirectory
)getDirectory
)dirReader.readEntries
)fileEntry.remove
)filetransfer.download()
to resolve the promise)XHR-request to fetch manifest.json (Rejected after timeout)
As you see, most methods rely on the succes/error callbacks of native/Cordova methods.
Only for deviceready
and the XHR-request I've added timeouts to ensure a timely response.
When using check
: The XHR will timeout.
When using download
: I am assuming Cordova will invoke the error callback. The download has a few retry-attempts. If the connetion isn't restored before the last retry-attemt, the download will fail.
The only critical moment is during a download. Old files are removed while new files aren't fully downloaded yet. This makes the current manifest point to missing or corrupt files. Therefore, before downloading, the current manifest is destroyed.
If the app crashes during a download, it will restart using the original manifest.
BOOTSTRAP_OK
is not set to true
after a timeout, the app will destroy the current manifest and revert back to the original manifest.Let me know if you find bugs. Report an issue!
Convert CommonJS to a browser-version:
npm install webpack -g
npm run-script prepublish
Feel free to contribute to this project in any way. The easiest way to support this project is by giving it a star.
© 2014 - Mark Marijnissen
FAQs
Cordova App Loader - remote update your cordova app
The npm package cordova-app-loader receives a total of 4 weekly downloads. As such, cordova-app-loader popularity was classified as not popular.
We found that cordova-app-loader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.