Compare commits

..
19 Commits
Author SHA1 Message Date
jared d1993f2084 Merge pull request 'Device-security nudge: verify this device / key backup (#110, #123)' (#258) from security-nudge into lotus
CI / Build & Quality Checks (push) Successful in 1m44s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 6s
CI / Trigger Desktop Build (push) Successful in 2s
CI / Playwright smoke (e2e) (push) Successful in 11m5s
Merge pull request #258
2026-09-30 21:03:23 -04:00
Lotus CIandClaude Opus 5.5 6a7627fa26 feat: device-security nudge — verify this device / key backup (#110, #123)
CI / Build & Quality Checks (pull_request) Successful in 1m48s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 12s
CI / Playwright smoke (e2e) (pull_request) Successful in 11m38s
One "security" strip, in the same top slot and style as the status banner
(#124), for this device, in priority order:
- "Verify this device" — cross-signing exists but this device isn't
  verified (can't unlock backed-up history, untrusted to others). First,
  because verifying with the recovery key also connects the backup.
- "Connect this device to your key backup" — a backup exists, this device
  isn't using it.
- "Set up key backup" — no backup at all (includes accounts without
  cross-signing; the setup flow does both).
The button opens Settings → Devices (existing flows); "Not now" snoozes.

Rules: nothing in a device's first 24 h; "Not now" snoozes that nudge 7
days; 3 dismissals stop it; never on a healthy device; waits until sync
has settled (never under "Connecting…"); outage/maintenance/connection
strips win. Per-device record in localStorage, wiped on logout. Mounted
inside the Matrix client context and an error boundary (an early version
outside the context crashed the app on load — caught before pushing).

Also: the status strip wraps its text on phones instead of truncating it
when there's no Details button (benefits #124's strips too).

Design approved on #123 (real-client screenshots there). Tests: 4 unit
(the #123 state table, loading, timing, stored record); e2e: nothing during
the grace period, "Set up key backup" → Settings → Devices, "Not now"
holds across a reload. Unit 1319, Playwright 29 passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-30 20:28:32 -04:00
jared 8e30c73e2f Merge pull request 'Desktop updates: Linux package installs update via their package manager' (#256) from linux-package-updates into lotus
CI / Build & Quality Checks (push) Successful in 1m44s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 7s
CI / Trigger Desktop Build (push) Successful in 11s
CI / Playwright smoke (e2e) (push) Successful in 12m6s
Merge pull request #256
2026-09-30 20:09:50 -04:00
Lotus CIandClaude Opus 5.5 6acdd439d5 fix(desktop updates): pacman command downloads first, installs the local file
CI / Build & Quality Checks (pull_request) Successful in 1m44s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 6s
CI / Playwright smoke (e2e) (pull_request) Successful in 10m38s
`sudo pacman -U <url>` also fetches `<url>.sig` and failed (404) on
CachyOS: remote packages fall under RemoteFileSigLevel (signature
required) and we don't sign the package. A downloaded file installs under
LocalFileSigLevel (optional): `curl -LO <url> && sudo pacman -U ./…`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-30 19:57:12 -04:00
Lotus CI 9aec3691ac Merge remote-tracking branch 'origin/lotus' into linux-package-updates
CI / Build & Quality Checks (pull_request) Successful in 1m38s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 6s
CI / Playwright smoke (e2e) (pull_request) Canceled after 2m32s
2026-09-30 19:41:39 -04:00
jared 4c36c03066 Merge pull request 'deps: brace-expansion 1.1.21 (unblocks CI audit)' (#257) from audit-brace-expansion into lotus
CI / Build & Quality Checks (push) Successful in 1m37s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 6s
CI / Trigger Desktop Build (push) Successful in 2s
CI / Playwright smoke (e2e) (push) Successful in 9m31s
Merge pull request #257
2026-09-30 19:41:38 -04:00
Lotus CIandClaude Opus 5.5 fbdac30d18 deps: brace-expansion 1.1.18 → 1.1.21 (GHSA-q2hr-2g5m-vwhr and two related DoS advisories)
CI / Build & Quality Checks (pull_request) Successful in 1m44s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 7s
CI / Playwright smoke (e2e) (pull_request) Successful in 11m56s
npm audit --omit=dev started failing every PR: brace-expansion <=1.1.20
(via @eslint/eslintrc → minimatch 3) has three high-severity DoS
advisories. Lockfile-only patch bump; nothing else changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-30 19:04:47 -04:00
Lotus CIandClaude Opus 5.5 27d659118f fix(desktop updates): Linux package installs update via their package manager
CI / Build & Quality Checks (pull_request) Failing after 1m40s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Playwright smoke (e2e) (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 6s
Reported on CachyOS: "Check for Updates → The update downloaded but
couldn't be installed … Permission denied (os error 13) at path
/usr/bin/tauri_current_app…". The app was installed from the Arch package;
Tauri's Linux updater can only replace an AppImage.

With cinny-desktop's new update_install_kind command:
- pacman / deb installs: the toast says the update is available and opens
  Settings → General → App Updates, which shows the package-manager command
  (`sudo pacman -U …pkg.tar.zst`, or the .deb + `sudo apt install`) with
  Copy command and Download package — no Install & Restart that can't work.
  "Copied" only when the clipboard write actually succeeded.
- other distros: a link to the downloads page.
- Windows, AppImage, and desktop builds without the command: unchanged
  in-app update.
- a native "package-managed" refusal shows the same help.

Tests: unit (kinds, commands, refusal detection); in the real client with a
simulated desktop bridge: pacman → toast + Settings command/buttons,
install never attempted; older desktop → in-app flow as before. Unit 1321,
Playwright 26 passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-30 19:00:10 -04:00
jared 747400ea25 Merge pull request 'Homeserver status banner from Uptime Kuma (#124)' (#255) from server-status-banner into lotus
CI / Build & Quality Checks (push) Successful in 4m10s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 11s
CI / Trigger Desktop Build (push) Successful in 2s
CI / Playwright smoke (e2e) (push) Successful in 14m59s
Merge pull request #255: homeserver status banner from Uptime Kuma (#124)
2026-09-29 12:29:00 -04:00
Lotus CIandClaude Opus 5.5 6ae0087213 feat: homeserver status banner from Uptime Kuma (#124)
CI / Build & Quality Checks (pull_request) Successful in 4m12s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 10s
CI / Playwright smoke (e2e) (pull_request) Successful in 11m58s
When the homeserver, voice calls or sign-in break, or maintenance is under
way, say so in the app — driven by the Kuma status page
(isitup.lotusguild.org/status/matrix), managed from Kuma's UI. The client
asks Kuma directly (not via our servers) so it still hears "the server is
down" when our servers can't tell it.

- config.json `statusPages`, keyed by homeserver: users of other servers
  never contact Kuma.
- utils/kumaStatus.ts (pure, unit-tested): parse Kuma 2.x's public JSON;
  a group is down when any monitor fails two checks in a row (down+down or
  pending+down); maintenance = windows under way; announcements = incidents.
  One strip at a time: server down (connection lost AND Kuma confirms) >
  server having problems > maintenance > calls down > announcement;
  sign-in problems on the login screen only.
- Wording about the user's own connection: "Connection lost … our status
  checks say the server is up, so it may be your internet connection" ONLY
  when Kuma checked the server after this client's connection dropped and
  it passed; a stale "up" (Kuma needs a minute or two to notice an outage)
  keeps the plain "Connection Lost!".
- useServerStatus: polls only while visible; 5 min, 60 s while something is
  wrong or the connection is lost, at once when it drops; backoff; any
  failure = no banner (Kuma being unreachable never looks like Matrix
  being down); GET only, no cookies.
- UI in the existing banner slot and style (ContainerColor/Line like the
  sync and clock banners); Details expands; dismiss for calls-down and
  announcements (an edited announcement comes back); calls-down note above
  Join; phone: one line + Details.

Needs the CSP connect-src to allow https://isitup.lotusguild.org (matrix
repo) before it can fetch in production; until then it fails quiet.

Tests: 15 unit tests (live page layout, two-check rule, any-monitor rule,
unknown/garbage, UTC beat times, stale-vs-fresh "up", priorities, login vs
client, maintenance, announcements + dismiss/edit); e2e (fixtures for Kuma):
calls-down strip + dismiss across reload, other homeservers make no
requests, Kuma 500 → nothing, lost connection + Kuma down → critical strip
instead of "Connection Lost", + fresh "up" → "may be your connection",
+ stale "up" → plain "Connection Lost". Unit 1315, Playwright 26 passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-29 12:08:08 -04:00
jared d6548c56fd Merge pull request 'Desktop: mirror the login tokens into the OS keychain (#105, step 1)' (#254) from desktop-keychain-mirror into lotus
CI / Build & Quality Checks (push) Successful in 3m14s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 7s
CI / Trigger Desktop Build (push) Successful in 5s
CI / Playwright smoke (e2e) (push) Successful in 9m10s
Merge pull request #254: desktop keychain mirror (#105, step 1)
2026-09-29 09:34:57 -04:00
jared 23f059d9a4 Merge pull request 'Desktop: call page on its own loopback origin, opt-in (#43)' (#252) from desktop-call-origin into lotus
CI / Build & Quality Checks (push) Canceled after 8s
CI / Trigger Desktop Build (push) Canceled after 0s
CI / Secret scan (gitleaks) (push) Canceled after 0s
CI / Docker image build & smoke test (push) Canceled after 0s
CI / Playwright smoke (e2e) (push) Canceled after 0s
Merge pull request #252: desktop call page on its own loopback origin, opt-in (#43)
2026-09-29 09:34:48 -04:00
Lotus CIandClaude Opus 5.5 9b9f33b270 feat(desktop): mirror the login tokens into the OS keychain (#105, step 1)
CI / Build & Quality Checks (pull_request) Successful in 1m46s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 8s
CI / Playwright smoke (e2e) (pull_request) Successful in 8m44s
Step 1 of moving the desktop app's login out of the webview's plaintext
localStorage: keep a verified copy of the tokens in the OS keychain
(Windows Credential Manager, via cinny-desktop's new secure_session_*
commands). The session is still read from localStorage exactly as before,
so nothing about login changes and a keychain problem can't log anyone out.
Step 2 (a later release, once this has run on real installs) switches reads
to the keychain and drops the tokens from localStorage.

- sessions.ts: onSessionPersisted — listeners told about every session
  write (login, token rotation) and removal (logout); a throwing listener
  can't break the write.
- keychainMirror.ts: desktop only. Mirrors userId/deviceId/accessToken/
  refreshToken (not the rest of the session); reads first and writes only
  when the copy differs, then verifies by reading back; serialized, 5 s
  timeouts; no session → clear (also covers a logout whose reload beat the
  clear). Every failure is a status, never an exception. A desktop build
  without the commands reads as "unsupported", so this can ship before the
  desktop side.
- Settings → General (desktop): "Login in the system keychain" status.

Tested: unit tests (fake keychain: store, no rewrite when current, rotation,
clear, unsupported, missing commands, denied write, read-back mismatch,
timeout); a simulated desktop app with a fake keychain, 14/14 (login
mirrors only the secrets, Settings status, reload verifies without
rewriting, logout clears, an existing session is mirrored after upgrade,
Linux/denied show an honest status and stay logged in); the real Linux
desktop binary (commands answer "unsupported", login unaffected, Settings
says so). Unit 1295 pass, Playwright 20 passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-29 00:24:46 -04:00
Lotus CIandClaude Opus 5.5 7d7a379ce0 feat(desktop): call page on its own loopback origin, opt-in (#43)
CI / Build & Quality Checks (pull_request) Successful in 1m46s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 8s
CI / Playwright smoke (e2e) (pull_request) Successful in 10m24s
The desktop app loads the bundled Element Call page from its own origin
(http://localhost:<port>), so the call frame can read the app's storage
(login token) and DOM — the hole #43 closed on the web by moving the page
to call.chat.lotusguild.org.

The desktop's local server can also answer on http://127.0.0.1:<port>: the
same server and bundle, but a different origin (and still a secure
context). resolveDesktopCallPageUrl loads the bundled page from there when
the desktop config sets `desktopCallOrigin`:
- only a loopback http origin on the SAME port as the app, no path, query
  or credentials;
- only when the app itself runs on http://localhost (release builds; debug
  builds on tauri:// keep the same-origin page);
- unset (every desktop build until cinny-desktop opts in, together with the
  server bind, CSP and permission changes it needs): unchanged.

The web app is unchanged (elementCallUrl as before).

Tested in a simulated desktop app (Tauri bridge stub + the desktop
config.json, served on localhost and 127.0.0.1) against a local Synapse +
LiveKit, two users: call page from http://127.0.0.1:<port>, parentUrl =
the app origin; the frame gets SecurityError on parent.localStorage and
parent.document (same-origin control: readable); join, speaking indicator,
mic off/on, screenshare start/stop, layout switch and hang-up all work, no
page errors — 12/12 in 5 of 6 runs, like the same-origin control (3 of 4;
the misses on both sides were the local LiveKit connection).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-29 00:09:27 -04:00
jared 91f82d60e3 Merge pull request 'A stalled server no longer reads as "your clock is ahead"' (#251) from clock-skew-lag into lotus
CI / Build & Quality Checks (push) Successful in 3m4s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 8s
CI / Trigger Desktop Build (push) Successful in 4s
CI / Playwright smoke (e2e) (push) Successful in 10m32s
Merge pull request #251: a stalled server no longer reads as a wrong clock
2026-09-28 22:40:13 -04:00
Lotus CI f0865115a4 Merge remote-tracking branch 'origin/lotus' into clock-skew-lag
CI / Build & Quality Checks (pull_request) Successful in 3m7s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 7s
CI / Playwright smoke (e2e) (pull_request) Successful in 10m59s
2026-09-28 22:11:31 -04:00
jared 899e160aed Merge pull request 'Offline outbox: unsent messages survive reload and retry (#112)' (#250) from offline-outbox into lotus
CI / Build & Quality Checks (push) Successful in 2m58s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 12s
CI / Trigger Desktop Build (push) Successful in 9s
CI / Playwright smoke (e2e) (push) Successful in 10m52s
Merge pull request #250: Offline outbox (#112)
2026-09-28 22:08:28 -04:00
Lotus CIandClaude Opus 5.5 3e5fdd0dab test(e2e): clock-ahead warning needs a minute of samples (#158)
CI / Build & Quality Checks (pull_request) Successful in 2m57s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 10s
CI / Playwright smoke (e2e) (pull_request) Canceled after 0s
"Ahead" is now reported only once it has held for a minute of fresh
samples (a stalled server delivers late and reads as ahead). The test sends
its ticks, checks nothing is shown yet, fast-forwards the page clock past a
minute and sends two more.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-28 22:08:13 -04:00
Lotus CIandClaude Opus 5.5 bb569d69a2 fix: a stalled server no longer reads as "your clock is ahead"
CI / Build & Quality Checks (pull_request) Successful in 3m1s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 7s
CI / Playwright smoke (e2e) (pull_request) Failing after 11m28s
Incident 2026-09-29: the homeserver's host ran out of memory and stalled for
~2 minutes. The /sync that finally went out carried events whose `age` was
computed ~30 s before it arrived, so every client showed "Your computer's
clock is 30 seconds ahead of the server" while the real problem was the
server (all host clocks were within 0.25 s the whole evening).

The skew estimate was the median of the last 5 samples, and a sample is
local skew + delivery delay, so one late /sync with a handful of events
tripped it.

- Estimate = the LOWEST sample of the last 5 minutes: delay only ever adds,
  so the fastest-delivered event is the truest.
- "Behind" (which a delay can't cause) is reported as soon as there are 3
  samples, like before. "Ahead" must hold across samples received at least
  a minute apart, so a single late burst never trips it.
- Samples are aged on the monotonic clock, and a change of the local clock
  (someone fixing it) resets the measurement, so the warning clears at once.
- Only events stamped by our own homeserver are sampled: a federated event's
  origin_server_ts is the other server's clock.
- Wording: "This device's clock is … Voice calls and encrypted messages can
  fail until it's corrected." / call bar "Device clock … : calls may fail"
  (was "will fail").

Unit tests: the incident (late burst after normal traffic, and a fresh
client whose first samples are all late), mixed slow/fast deliveries,
ahead only after a minute, behind at once, hysteresis, clock fixed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-28 21:40:02 -04:00
36 changed files with 2414 additions and 187 deletions
+12 -1
View File
@@ -12,5 +12,16 @@
"enabled": false, "enabled": false,
"basename": "/" "basename": "/"
}, },
"gifApiKey": "" "gifApiKey": "",
"statusPages": {
"matrix.lotusguild.org": {
"url": "https://isitup.lotusguild.org",
"slug": "matrix",
"groups": {
"homeserver": "Homeserver",
"calls": "Voice calls",
"login": "Login"
}
}
}
} }
+10 -1
View File
@@ -257,12 +257,21 @@ test.describe('local homeserver regression', () => {
await page.clock.install({ time: Date.now() + 14 * 60 * 1000 }); await page.clock.install({ time: Date.now() + 14 * 60 * 1000 });
await loginUI(page, alice); await loginUI(page, alice);
await openRoom(page, room); await openRoom(page, room);
for (let i = 0; i < 4; i += 1) { const ticks = async (from: number, n: number) => {
for (let i = from; i < from + n; i += 1) {
// eslint-disable-next-line no-await-in-loop // eslint-disable-next-line no-await-in-loop
await sendText(bob, room, `tick ${i}`); await sendText(bob, room, `tick ${i}`);
// eslint-disable-next-line no-await-in-loop // eslint-disable-next-line no-await-in-loop
await page.waitForTimeout(500); await page.waitForTimeout(500);
} }
};
await ticks(0, 4);
// "Ahead" could be a late delivery (a stalled server), so it is only
// reported once it has held for a minute of fresh samples.
await page.waitForTimeout(2000);
await expect(page.getByText(/clock is .*ahead of the server/)).toHaveCount(0);
await page.clock.fastForward('01:05');
await ticks(4, 2);
await expect(page.getByText(/clock is .*14 minutes ahead of the server/)).toBeVisible(); await expect(page.getByText(/clock is .*14 minutes ahead of the server/)).toBeVisible();
await page.getByRole('button', { name: 'Dismiss for 24 h' }).click(); await page.getByRole('button', { name: 'Dismiss for 24 h' }).click();
await expect(page.getByText(/clock is .*ahead of the server/)).toHaveCount(0); await expect(page.getByText(/clock is .*ahead of the server/)).toHaveCount(0);
+74
View File
@@ -0,0 +1,74 @@
import { test, expect, Page } from '@playwright/test';
import { HS, ensureUser, hsReachable, loginUI, TestUser, uniq } from './localHs';
// [Gitea #110, #123] The device-security nudge. A fresh account has no key
// backup and no cross-signing → "Set up key backup", but only after the 24 h
// grace period on this device; "Not now" snoozes it.
const strip = (page: Page) => page.getByRole('status').filter({ hasText: /encryption keys/ });
/** Back-date this device's first-seen record past the 24 h grace period, then reload. */
async function pastGrace(page: Page) {
await page.evaluate(() => {
const { deviceId } = JSON.parse(localStorage.getItem('cinny_session_v1') ?? '{}');
localStorage.setItem(
`lotus-security-nudge-${deviceId}`,
JSON.stringify({ firstSeen: Date.now() - 2 * 86_400_000, dismissals: {} }),
);
});
await page.reload();
}
/** The nudge waits until sync has settled (after "Connecting…"). */
async function settled(page: Page) {
await page
.getByText('Connecting...')
.first()
.waitFor({ timeout: 30_000 })
.catch(() => undefined);
await page.getByText('Connecting...').first().waitFor({ state: 'detached', timeout: 90_000 });
await page.waitForTimeout(2000);
}
test.describe('security nudge (#110, #123)', () => {
let user: TestUser;
test.beforeAll(async () => {
test.skip(!(await hsReachable()), `no local homeserver at ${HS} (set E2E_LOCAL_HS)`);
});
test.beforeEach(async () => {
user = await ensureUser(uniq('e2e_nudge_'));
});
test('nothing during the first 24 h on a device', async ({ page }) => {
test.setTimeout(150_000);
await loginUI(page, user);
await settled(page);
// Past the point where the nudge shows once the grace period is over (~5 s).
await page.waitForTimeout(8000);
await expect(strip(page)).toHaveCount(0);
});
test('no key backup: "Set up key backup" opens Settings → Devices', async ({ page }) => {
test.setTimeout(150_000);
await loginUI(page, user);
await pastGrace(page);
await settled(page);
const nudge = strip(page);
await expect(nudge).toContainText("Your encryption keys aren't backed up");
await nudge.getByRole('button', { name: 'Set up' }).click();
await expect(page.getByText('Device Verification').first()).toBeVisible();
});
test('"Not now" snoozes it across a reload', async ({ page }) => {
test.setTimeout(200_000);
await loginUI(page, user);
await pastGrace(page);
await settled(page);
await strip(page).getByRole('button', { name: 'Not now' }).click();
await expect(strip(page)).toHaveCount(0);
await page.reload();
await settled(page);
await expect(strip(page)).toHaveCount(0);
});
});
+162
View File
@@ -0,0 +1,162 @@
import { test, expect, Page } from '@playwright/test';
import {
HS,
createRoom,
ensureUser,
hsReachable,
loginUI,
openRoom,
uniq,
TestUser,
} from './localHs';
// [Gitea #124] Status banner from the homeserver's Uptime Kuma page. Kuma is
// answered by fixtures here; nothing contacts a real Kuma.
const KUMA = 'https://isitup.lotusguild.org';
const PAGE_CFG = { url: KUMA, slug: 'matrix' };
const UP = 1;
const DOWN = 0;
type Fixture = { hs?: number; calls?: number; staleMinutes?: number; fail?: boolean };
const kumaTime = (ms: number) => new Date(ms).toISOString().replace('T', ' ').slice(0, 23);
/** Serve config.json with a status page for `serverName` and answer Kuma from `fx()`. */
async function mockKuma(page: Page, serverName: string | null, fx: () => Fixture) {
const kumaRequests: string[] = [];
await page.route(/\/config\.json(\?.*)?$/, async (route) => {
const res = await route.fetch();
const cfg = await res.json();
cfg.statusPages = serverName ? { [serverName]: PAGE_CFG } : {};
await route.fulfill({ response: res, json: cfg });
});
await page.route(/isitup\.lotusguild\.org\/api\/status-page\//, async (route) => {
const url = route.request().url();
kumaRequests.push(url);
const f = fx();
if (f.fail) {
await route.fulfill({ status: 500, body: 'oops' });
return;
}
const cors = { 'access-control-allow-origin': '*' };
if (url.includes('/heartbeat/')) {
// Two checks, the latest `staleMinutes` ago (0 = just now).
const last = Date.now() - (f.staleMinutes ?? 0) * 60_000;
const beats = (s: number) => [
{ status: s, time: kumaTime(last - 60_000) },
{ status: s, time: kumaTime(last) },
];
await route.fulfill({
headers: cors,
json: { heartbeatList: { 1: beats(f.hs ?? UP), 2: beats(f.calls ?? UP) }, uptimeList: {} },
});
return;
}
await route.fulfill({
headers: cors,
json: {
config: { slug: 'matrix' },
incidents: [],
maintenanceList: [],
publicGroupList: [
{ name: 'Homeserver', monitorList: [{ id: 1 }] },
{ name: 'Voice calls', monitorList: [{ id: 2 }] },
],
},
});
});
return kumaRequests;
}
const serverOf = (u: TestUser) => u.userId.split(':').slice(1).join(':');
const strip = (page: Page, text: RegExp) =>
page.locator('[role="status"], [role="alert"]').filter({ hasText: text });
const cutSync = (page: Page) =>
page.route(/\/_matrix\/client\/v3\/sync/, (route) => route.abort('connectionfailed'));
test.describe('server status banner (#124)', () => {
let alice: TestUser;
let room: string;
test.beforeAll(async () => {
test.skip(!(await hsReachable()), `no local homeserver at ${HS} (set E2E_LOCAL_HS)`);
alice = await ensureUser(uniq('e2e_status_'));
room = await createRoom(alice, 'Status Room');
});
test('calls down: amber strip, dismiss sticks across a reload', async ({ page }) => {
await mockKuma(page, serverOf(alice), () => ({ calls: DOWN }));
await loginUI(page, alice);
await openRoom(page, room);
const calls = strip(page, /Voice calls are down right now\. Messages still work\./);
await expect(calls).toBeVisible();
await calls.getByRole('button', { name: 'Dismiss' }).click();
await expect(calls).toHaveCount(0);
await page.reload();
await openRoom(page, room);
await page.waitForTimeout(2000);
await expect(calls).toHaveCount(0);
});
test('other homeservers never contact Kuma', async ({ page }) => {
const requests = await mockKuma(page, 'some.other.server', () => ({ hs: DOWN }));
await loginUI(page, alice);
await openRoom(page, room);
await page.waitForTimeout(3000);
expect(requests).toEqual([]);
});
test('Kuma failing shows nothing (fail quiet)', async ({ page }) => {
const requests = await mockKuma(page, serverOf(alice), () => ({ fail: true }));
await loginUI(page, alice);
await openRoom(page, room);
await expect.poll(() => requests.length).toBeGreaterThan(0);
await page.waitForTimeout(1500);
await expect(strip(page, /server|Voice calls|Maintenance/i)).toHaveCount(0);
});
test('connection lost + Kuma says the server is down: critical strip, not "Connection Lost"', async ({
page,
}) => {
test.setTimeout(150_000);
await mockKuma(page, serverOf(alice), () => ({ hs: DOWN }));
await loginUI(page, alice);
await openRoom(page, room);
// Connected: the server is "having problems" for others, not for us.
await expect(strip(page, /server is having problems/)).toBeVisible();
await cutSync(page);
const down = page.getByRole('alert').filter({ hasText: /server is down\. We're on it/ });
await expect(down).toBeVisible({ timeout: 120_000 });
await expect(page.getByText('Connection Lost! Reconnecting...')).toHaveCount(0);
});
test('connection lost + Kuma checked since and the server is up: "may be your connection"', async ({
page,
}) => {
test.setTimeout(150_000);
await mockKuma(page, serverOf(alice), () => ({ hs: UP }));
await loginUI(page, alice);
await openRoom(page, room);
await cutSync(page);
await expect(page.getByText(/server is up, so it may be your internet connection/)).toBeVisible(
{
timeout: 120_000,
},
);
});
test('connection lost + only a stale "up" from Kuma: plain "Connection Lost"', async ({
page,
}) => {
test.setTimeout(150_000);
await mockKuma(page, serverOf(alice), () => ({ hs: UP, staleMinutes: 10 }));
await loginUI(page, alice);
await openRoom(page, room);
await cutSync(page);
await expect(page.getByText('Connection Lost! Reconnecting...')).toBeVisible({
timeout: 120_000,
});
await page.waitForTimeout(3000);
await expect(page.getByText(/may be your internet connection/)).toHaveCount(0);
});
});
+3 -3
View File
@@ -5026,9 +5026,9 @@
"license": "MIT" "license": "MIT"
}, },
"node_modules/brace-expansion": { "node_modules/brace-expansion": {
"version": "1.1.18", "version": "1.1.21",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz",
"integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "integrity": "sha512-9zeA+KLZNNzglF2TPKRQEDyx6Yby7daAkuy8MiPzpXPsYDWi/DRM8jmwUDxokQjYqBpv5DgPiwD4h4ZZSy1Ujw==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"balanced-match": "^1.0.0", "balanced-match": "^1.0.0",
+2 -2
View File
@@ -72,9 +72,9 @@ export function CallStatus({ callEmbed }: CallStatusProps) {
size="T200" size="T200"
truncate truncate
style={{ color: color.Warning.Main }} style={{ color: color.Warning.Main }}
title="Fix your computer's clock — calls and encryption depend on it" title="This device's clock is off. Calls and encryption depend on it: turn on automatic time in your system settings."
> >
Clock {describeSkewVsServer(clockSkew.skewMs)} — calls will fail Device clock {describeSkewVsServer(clockSkew.skewMs)}: calls may fail
</Text> </Text>
</> </>
)} )}
@@ -8,6 +8,7 @@ import { useCallEmbed, useCallJoined, useCallStart } from '../../hooks/useCallEm
import { useCallPreferences } from '../../state/hooks/callPreferences'; import { useCallPreferences } from '../../state/hooks/callPreferences';
import { useSetting } from '../../state/hooks/settings'; import { useSetting } from '../../state/hooks/settings';
import { settingsAtom } from '../../state/settings'; import { settingsAtom } from '../../state/settings';
import { useCallsDown } from '../server-status/ServerStatusBanner';
type MediaPermState = 'granted' | 'denied' | 'prompt' | 'unknown'; type MediaPermState = 'granted' | 'denied' | 'prompt' | 'unknown';
@@ -61,6 +62,7 @@ export function PrescreenControls({ canJoin }: PrescreenControlsProps) {
const micPermission = useMediaPermissions(); const micPermission = useMediaPermissions();
const micDenied = micPermission === 'denied'; const micDenied = micPermission === 'denied';
const callsDown = useCallsDown();
const disabled = inOtherCall || !canJoin || micDenied; const disabled = inOtherCall || !canJoin || micDenied;
@@ -91,6 +93,11 @@ export function PrescreenControls({ canJoin }: PrescreenControlsProps) {
<ChatButton /> <ChatButton />
</Box> </Box>
<Box grow="Yes" direction="Column" gap="200"> <Box grow="Yes" direction="Column" gap="200">
{callsDown && (
<Text size="T200" style={{ color: color.Warning.Main, textAlign: 'center' }}>
Voice calls are down right now, so joining may fail.
</Text>
)}
{micDenied && ( {micDenied && (
<Text size="T200" style={{ color: color.Critical.Main, textAlign: 'center' }}> <Text size="T200" style={{ color: color.Critical.Main, textAlign: 'center' }}>
Microphone access is blocked. Enable it in your browser settings to join. Microphone access is blocked. Enable it in your browser settings to join.
@@ -0,0 +1,137 @@
import React, { useCallback, useEffect, useState } from 'react';
import { useAtomValue, useSetAtom } from 'jotai';
import { SyncState } from 'matrix-js-sdk';
import { CryptoApi } from 'matrix-js-sdk/lib/crypto-api';
import { Icons } from 'folds';
import { ErrorBoundary } from 'react-error-boundary';
import { useMatrixClient } from '../../hooks/useMatrixClient';
import { useCrossSigningActive } from '../../hooks/useCrossSigning';
import {
useDeviceVerificationStatus,
VerificationStatus,
} from '../../hooks/useDeviceVerificationStatus';
import { useKeyBackupInfo, useKeyBackupStatusChange } from '../../hooks/useKeyBackup';
import { useAlive } from '../../hooks/useAlive';
import { useSyncState } from '../../hooks/useSyncState';
import { settingsRequestAtom } from '../../state/settingsRequest';
import { serverStatusAtom } from '../../state/serverStatus';
import { pickBanner } from '../../utils/kumaStatus';
import {
dismissNudge,
NUDGE_COPY,
NUDGE_KEY_PREFIX,
nudgeFor,
NudgeRecord,
parseNudgeRecord,
shouldShowNudge,
} from '../../utils/securityNudge';
import { StatusStrip } from '../server-status/ServerStatusBanner';
/** This device's backup connection: undefined until known, then true/false. */
const useBackupActive = (crypto: CryptoApi): boolean | undefined => {
const alive = useAlive();
const [active, setActive] = useState<boolean>();
useEffect(() => {
crypto.getActiveSessionBackupVersion().then((v) => {
if (alive()) setActive(typeof v === 'string');
});
}, [crypto, alive]);
useKeyBackupStatusChange(useCallback((enabled: boolean) => setActive(enabled), []));
return active;
};
const readRecord = (key: string): NudgeRecord => {
let raw: string | null = null;
try {
raw = localStorage.getItem(key);
} catch {
/* storage unavailable */
}
const record = parseNudgeRecord(raw, Date.now());
if (!raw) {
try {
localStorage.setItem(key, JSON.stringify(record));
} catch {
/* best effort */
}
}
return record;
};
function SecurityBannerFor({ crypto }: { crypto: CryptoApi }) {
const mx = useMatrixClient();
const deviceId = mx.getDeviceId() ?? undefined;
const crossSigning = useCrossSigningActive();
const status = useDeviceVerificationStatus(crypto, mx.getSafeUserId(), deviceId);
const backupInfo = useKeyBackupInfo(crypto);
const backupActive = useBackupActive(crypto);
const { status: serverStatus, syncLost } = useAtomValue(serverStatusAtom);
const requestSettings = useSetAtom(settingsRequestAtom);
// Not urgent: wait until sync has settled (two SYNCING in a row), so it
// never stacks under the "Connecting…" strip at startup.
const [settled, setSettled] = useState(false);
useSyncState(
mx,
useCallback((state: SyncState | null, prev?: SyncState | null) => {
setSettled(state === SyncState.Syncing && prev === SyncState.Syncing);
}, []),
);
const key = `${NUDGE_KEY_PREFIX}${deviceId ?? 'unknown'}`;
const [record, setRecord] = useState(() => readRecord(key));
let deviceVerified: boolean | undefined;
if (status === VerificationStatus.Verified) deviceVerified = true;
else if (status === VerificationStatus.Unverified) deviceVerified = false;
const kind = nudgeFor({
crossSigning,
deviceVerified,
backupOnServer: backupInfo === undefined ? undefined : backupInfo !== null,
backupActive,
});
// One strip at a time: outages, maintenance and a lost connection win.
const otherStrip = syncLost || !!pickBanner(serverStatus, { syncLost, where: 'client' });
if (!settled || !deviceId || !kind || otherStrip || !shouldShowNudge(kind, record, Date.now()))
return null;
const copy = NUDGE_COPY[kind];
const dismiss = () => {
const next = dismissNudge(kind, record, Date.now());
try {
localStorage.setItem(key, JSON.stringify(next));
} catch {
/* dismissed for this session only */
}
setRecord(next);
};
return (
<StatusStrip
banner={{ key: kind, tone: 'Primary', text: copy.text, dismissable: true }}
icon={Icons.ShieldUser}
action={{ label: copy.action, onClick: () => requestSettings('devices') }}
dismissLabel="Not now"
onDismiss={dismiss}
/>
);
}
/**
* [Gitea #110, #123] The device-security nudge: verify this device, connect
* it to the key backup, or set up key backup. See utils/securityNudge.ts.
*/
function SecurityBannerInner() {
const mx = useMatrixClient();
const crypto = mx.getCrypto();
if (!crypto) return null;
return <SecurityBannerFor crypto={crypto} />;
}
// A nudge must never take the app down: any error just hides it.
export function SecurityBanner() {
return (
<ErrorBoundary fallback={null}>
<SecurityBannerInner />
</ErrorBoundary>
);
}
@@ -0,0 +1,208 @@
import React, { useCallback, useEffect, useMemo, useState } from 'react';
import { useAtomValue, useSetAtom } from 'jotai';
import { MatrixClient, SyncState } from 'matrix-js-sdk';
import { Box, Button, config, Icon, IconButton, Icons, IconSrc, Line, Text } from 'folds';
import { ContainerColor } from '../../styles/ContainerColor.css';
import { useClientConfig } from '../../hooks/useClientConfig';
import { useSyncState } from '../../hooks/useSyncState';
import { useServerStatus } from '../../hooks/useServerStatus';
import { ScreenSize, useScreenSizeContext } from '../../hooks/useScreenSize';
import { serverStatusAtom } from '../../state/serverStatus';
import { pickBanner, resolveStatusPage, StatusBanner } from '../../utils/kumaStatus';
const DISMISS_KEY = 'lotus-status-banner-dismissed';
const DISMISS_MAX = 50;
const readDismissed = (): string[] => {
try {
const v = JSON.parse(localStorage.getItem(DISMISS_KEY) ?? '[]');
return Array.isArray(v) ? v.filter((k): k is string => typeof k === 'string') : [];
} catch {
return [];
}
};
const bannerIcon = (b: StripContent): IconSrc => {
if (b.kind === 'maintenance') return Icons.Setting;
if (b.tone === 'Primary') return Icons.Info;
return Icons.Warning;
};
/**
* [Gitea #124] One status strip, in the same slot and style as the sync and
* clock banners. Presentational: the caller picks the banner.
*/
export type StripContent = Pick<
StatusBanner,
'key' | 'tone' | 'text' | 'detail' | 'dismissable'
> & {
kind?: StatusBanner['kind'];
};
export function StatusStrip({
banner,
onDismiss,
icon,
action,
dismissLabel,
}: {
banner: StripContent;
onDismiss?: () => void;
/** Overrides the icon picked from the banner's tone/kind. */
icon?: IconSrc;
/** A primary action button (e.g. "Verify"). */
action?: { label: string; onClick: () => void };
/** A text button instead of the ✕ for dismissing (e.g. "Not now"). */
dismissLabel?: string;
}) {
const [open, setOpen] = useState(false);
const mobile = useScreenSizeContext() === ScreenSize.Mobile;
useEffect(() => setOpen(false), [banner.key]);
const critical = banner.tone === 'Critical';
return (
<Box direction="Column" shrink="No">
<Box
className={ContainerColor({ variant: banner.tone })}
style={{ padding: `${config.space.S100} ${config.space.S300}` }}
direction="Column"
gap="100"
role={critical ? 'alert' : 'status'}
aria-live={critical ? 'assertive' : 'polite'}
>
<Box
alignItems="Center"
justifyContent={mobile ? 'Start' : 'Center'}
gap="200"
style={{ minHeight: config.size.X300 }}
>
<Icon size="100" src={icon ?? bannerIcon(banner)} />
<Text size="L400" truncate={mobile && !!banner.detail && !open} style={{ minWidth: 0 }}>
{banner.text}
</Text>
{banner.detail && (
<Button
size="300"
variant={banner.tone}
fill="None"
radii="300"
aria-expanded={open}
onClick={() => setOpen((v) => !v)}
style={{ flexShrink: 0 }}
>
<Text size="B300" style={{ textDecoration: 'underline' }}>
{open ? 'Hide' : 'Details'}
</Text>
</Button>
)}
{action && (
<Button
size="300"
variant={banner.tone}
fill="Solid"
radii="300"
onClick={action.onClick}
style={{ flexShrink: 0 }}
>
<Text size="B300">{action.label}</Text>
</Button>
)}
{banner.dismissable && onDismiss && dismissLabel && (
<Button
size="300"
variant={banner.tone}
fill="None"
radii="300"
onClick={onDismiss}
style={{ flexShrink: 0 }}
>
<Text size="B300">{dismissLabel}</Text>
</Button>
)}
{banner.dismissable && onDismiss && !dismissLabel && (
<IconButton
size="300"
variant={banner.tone}
fill="None"
radii="300"
aria-label="Dismiss"
onClick={onDismiss}
style={{ flexShrink: 0 }}
>
<Icon size="100" src={Icons.Cross} />
</IconButton>
)}
</Box>
{banner.detail && open && (
<Box justifyContent={mobile ? 'Start' : 'Center'}>
<Text size="T200" style={{ maxWidth: 680, whiteSpace: 'pre-line' }}>
{banner.detail}
</Text>
</Box>
)}
</Box>
<Line variant={banner.tone} size="300" />
</Box>
);
}
/** Runs the Kuma poller for the logged-in homeserver and publishes it. */
export function ServerStatusFeature({ mx }: { mx: MatrixClient }) {
const { statusPages } = useClientConfig();
const page = useMemo(
() => resolveStatusPage(statusPages, mx.getDomain() ?? undefined),
[statusPages, mx],
);
const [lostAt, setLostAt] = useState<number | null>(null);
useSyncState(
mx,
useCallback((state: SyncState | null) => {
const lost = state === SyncState.Reconnecting || state === SyncState.Error;
setLostAt((prev) => {
if (!lost) return null;
return prev ?? Date.now();
});
}, []),
);
const syncLost = lostAt !== null;
const status = useServerStatus(page, syncLost);
const setAtom = useSetAtom(serverStatusAtom);
useEffect(() => setAtom({ status, syncLost, lostAt }), [setAtom, status, syncLost, lostAt]);
return null;
}
/** The logged-in app's status strip. */
export function ServerStatusBanner() {
const { status, syncLost } = useAtomValue(serverStatusAtom);
const [dismissed, setDismissed] = useState(readDismissed);
const banner = pickBanner(status, {
syncLost,
where: 'client',
dismissed: new Set(dismissed),
});
if (!banner) return null;
const dismiss = () => {
const next = [...dismissed.filter((k) => k !== banner.key), banner.key].slice(-DISMISS_MAX);
try {
localStorage.setItem(DISMISS_KEY, JSON.stringify(next));
} catch {
// storage unavailable — dismissed for this session only
}
setDismissed(next);
};
return <StatusStrip banner={banner} onDismiss={dismiss} />;
}
/** The sign-in screen's strip, for the homeserver being signed in to. */
export function LoginStatusBanner({ serverName }: { serverName: string }) {
const { statusPages } = useClientConfig();
const page = useMemo(() => resolveStatusPage(statusPages, serverName), [statusPages, serverName]);
const status = useServerStatus(page);
const banner = pickBanner(status, { syncLost: false, where: 'login' });
return banner ? <StatusStrip banner={banner} /> : null;
}
/** Calls-down note for the call Join controls (null when calls are fine). */
export function useCallsDown(): boolean {
const { status } = useAtomValue(serverStatusAtom);
return status?.calls === 'down' && status.homeserver !== 'down';
}
+102 -9
View File
@@ -112,8 +112,15 @@ import {
import { chromeTranslationEngine } from '../../../utils/translation/chromeEngine'; import { chromeTranslationEngine } from '../../../utils/translation/chromeEngine';
import { SequenceCardStyle } from '../styles.css'; import { SequenceCardStyle } from '../styles.css';
import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater'; import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater';
import { describeUpdateError, manualDownloadUrl } from '../../../utils/updateErrors'; import {
describeUpdateError,
isPackageManagedError,
manualDownloadUrl,
packageUpdateHelp,
} from '../../../utils/updateErrors';
import { copyToClipboard } from '../../../utils/dom';
import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri'; import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri';
import { useKeychainMirrorStatus } from '../../../state/keychainMirror';
import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys'; import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys';
import { customWindowChromeAtom } from '../../../state/customWindowChrome'; import { customWindowChromeAtom } from '../../../state/customWindowChrome';
import { useDateFormatItems } from '../../../hooks/useDateFormat'; import { useDateFormatItems } from '../../../hooks/useDateFormat';
@@ -238,6 +245,27 @@ function AutostartSetting() {
); );
} }
// [Gitea #105] Desktop: whether the login is also kept in the OS keychain.
function KeychainMirrorSetting() {
const status = useKeychainMirrorStatus();
if (!isTauriEnv() || status.state === 'idle' || status.state === 'cleared') return null;
let description: string;
if (status.state === 'ok') {
description =
"A copy of your login is kept in the system keychain (Windows Credential Manager). A later update will keep it only there, out of the app's data folder.";
} else if (status.state === 'unsupported') {
description =
"Not available on this system yet. Your login is saved in the app's data folder, as before.";
} else {
description = `Couldn't save a copy to the system keychain (${status.error}). You stay logged in; your login is saved in the app's data folder, as before.`;
}
return (
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
<SettingTile title="Login in the system keychain" description={description} />
</SequenceCard>
);
}
type ThemeSelectorProps = { type ThemeSelectorProps = {
themeNames: Record<string, string>; themeNames: Record<string, string>;
themes: Theme[]; themes: Theme[];
@@ -570,6 +598,7 @@ function Appearance() {
<DesktopChromeSetting /> <DesktopChromeSetting />
<AutostartSetting /> <AutostartSetting />
<KeychainMirrorSetting />
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column"> <SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
<SettingTile <SettingTile
@@ -2771,12 +2800,76 @@ function updateProgressText(progress: UpdateProgress | undefined): string {
return `Downloading update… ${pct}% (${formatMb(downloaded)} of ${formatMb(total)})${attempt}`; return `Downloading update… ${pct}% (${formatMb(downloaded)} of ${formatMb(total)})${attempt}`;
} }
function AppUpdates() { /**
const { isTauri, status, check, install } = useTauriUpdater(); * A Linux package install is updated with its package manager (the in-app
if (!isTauri) return null; * updater can't write to /usr/bin): the command, Copy and a download link.
*/
function PackageUpdate({ help }: { help: NonNullable<ReturnType<typeof packageUpdateHelp>> }) {
const [copied, setCopied] = useState<'no' | 'yes' | 'failed'>('no');
const copy = () => {
const text = help.command ?? '';
if (!navigator.clipboard) {
copyToClipboard(text);
setCopied('yes');
return;
}
navigator.clipboard.writeText(text).then(
() => setCopied('yes'),
() => setCopied('failed'),
);
};
let copyLabel = 'Copy command';
if (copied === 'yes') copyLabel = 'Copied';
else if (copied === 'failed') copyLabel = 'Copy failed: select it above';
return (
<Box direction="Column" gap="200">
<Text size="T200">
Lotus Chat was installed as a system package, so update it the same way
{help.command ? ' (your chats and settings are kept):' : '.'}
</Text>
{help.command && (
<Text
size="T200"
style={{ fontFamily: 'monospace', wordBreak: 'break-all', userSelect: 'all' }}
>
{help.command}
</Text>
)}
<Box gap="200" wrap="Wrap">
{help.command && (
<Button size="300" radii="300" variant="Secondary" onClick={copy}>
<Text size="B300">{copyLabel}</Text>
</Button>
)}
<Button
size="300"
radii="300"
variant="Secondary"
fill="None"
outlined
onClick={() => window.open(help.url, '_blank')}
>
<Text size="B300">{help.download}</Text>
</Button>
</Box>
</Box>
);
}
const description = function AppUpdates() {
status.state === 'checking' const { isTauri, status, check, install, installKind } = useTauriUpdater();
if (!isTauri) return null;
const packageHelp = packageUpdateHelp(installKind);
const packageUpdate =
!!packageHelp &&
(status.state === 'available' ||
(status.state === 'error' && isPackageManagedError(status.message)));
const description = packageUpdate
? status.state === 'available'
? `Update available: v${status.version}`
: 'An update is available.'
: status.state === 'checking'
? 'Checking for updates...' ? 'Checking for updates...'
: status.state === 'up-to-date' : status.state === 'up-to-date'
? 'Lotus Chat is up to date.' ? 'Lotus Chat is up to date.'
@@ -2793,8 +2886,7 @@ function AppUpdates() {
else check(); else check();
}; };
const after = const after = packageUpdate ? undefined : status.state === 'available' ? (
status.state === 'available' ? (
<Button size="300" radii="300" onClick={() => install()}> <Button size="300" radii="300" onClick={() => install()}>
<Text size="B300">Install &amp; Restart</Text> <Text size="B300">Install &amp; Restart</Text>
</Button> </Button>
@@ -2829,7 +2921,8 @@ function AppUpdates() {
<Text size="L400">App Updates</Text> <Text size="L400">App Updates</Text>
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column"> <SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
<SettingTile title="Check for Updates" description={description} after={after} /> <SettingTile title="Check for Updates" description={description} after={after} />
{status.state === 'error' && ( {packageUpdate && packageHelp && <PackageUpdate help={packageHelp} />}
{status.state === 'error' && !packageUpdate && (
<Text size="T200" priority="300" style={{ wordBreak: 'break-word' }}> <Text size="T200" priority="300" style={{ wordBreak: 'break-word' }}>
Details: {status.message} Details: {status.message}
</Text> </Text>
+16
View File
@@ -26,6 +26,22 @@ export type ClientConfig = {
*/ */
elementCallUrl?: string; elementCallUrl?: string;
/**
* [Gitea #43] Desktop only: the loopback origin the desktop app's local
* server also answers on (e.g. "http://127.0.0.1:44548"), to load the
* bundled call page from a different origin than the app
* ("http://localhost:44548"). Set by cinny-desktop together with the server
* and CSP changes it needs; unset keeps the same-origin call page.
*/
desktopCallOrigin?: string;
/**
* [Gitea #124] Uptime Kuma status page per homeserver, for the status banner:
* { "<server name>": { url, slug, groups?: { homeserver, calls, login } } }.
* Homeservers not listed never contact Kuma.
*/
statusPages?: Record<string, unknown>;
/** /**
* Absolute https URL of the public web app (e.g. https://chat.lotusguild.org). * Absolute https URL of the public web app (e.g. https://chat.lotusguild.org).
* The desktop app sets it so it can hand calls it can't make to the browser. * The desktop app sets it so it can hand calls it can't make to the browser.
+98
View File
@@ -0,0 +1,98 @@
import { useEffect, useState } from 'react';
import { kumaUrls, parseKumaStatus, ServerStatus, StatusPageConfig } from '../utils/kumaStatus';
/** Normal poll, and while a problem is showing (so recovery clears quickly). */
export const STATUS_POLL_MS = 5 * 60 * 1000;
export const STATUS_POLL_PROBLEM_MS = 60 * 1000;
const STATUS_FETCH_TIMEOUT_MS = 10 * 1000;
const STATUS_BACKOFF_MAX_MS = 15 * 60 * 1000;
const fetchJson = async (url: string, signal: AbortSignal): Promise<unknown> => {
const res = await fetch(url, { cache: 'no-store', credentials: 'omit', signal });
if (!res.ok) throw new Error(`HTTP ${res.status}`);
return res.json();
};
export const hasProblem = (s: ServerStatus | null): boolean =>
!!s &&
(s.homeserver === 'down' || s.calls === 'down' || s.login === 'down' || s.maintenance.length > 0);
/**
* [Gitea #124] Poll the homeserver's Kuma status page (none configured → no
* requests, null). Only while the page is visible; every 5 min, every 60 s
* while something is wrong, and at once when `urgent` turns true (this
* client's connection dropped). Any failure → null ("no banner"), with
* backoff: Kuma being unreachable must never look like Matrix being down.
*/
export const useServerStatus = (
page: StatusPageConfig | undefined,
urgent = false,
): ServerStatus | null => {
const [status, setStatus] = useState<ServerStatus | null>(null);
const pageKey = page ? `${page.url}/${page.slug}` : '';
useEffect(() => {
if (!page) {
setStatus(null);
return undefined;
}
const urls = kumaUrls(page);
let timer: ReturnType<typeof setTimeout> | undefined;
let controller: AbortController | undefined;
let failures = 0;
let stopped = false;
let last: ServerStatus | null = null;
const schedule = (ms: number) => {
if (timer) clearTimeout(timer);
timer = setTimeout(poll, ms);
};
async function poll() {
if (stopped) return;
if (typeof document !== 'undefined' && document.visibilityState === 'hidden') return;
controller?.abort();
controller = new AbortController();
const abort = controller;
const timeout = setTimeout(() => abort.abort(), STATUS_FETCH_TIMEOUT_MS);
try {
const [pageJson, heartbeatJson] = await Promise.all([
fetchJson(urls.page, abort.signal),
fetchJson(urls.heartbeat, abort.signal),
]);
if (stopped) return;
failures = 0;
last = parseKumaStatus(pageJson, heartbeatJson, page!.groups);
setStatus(last);
// While this client's connection is lost, keep asking every minute: that
// is how it learns Kuma has checked the server since the drop.
schedule(hasProblem(last) || urgent ? STATUS_POLL_PROBLEM_MS : STATUS_POLL_MS);
} catch {
if (stopped) return;
failures += 1;
last = null;
setStatus(null);
schedule(Math.min(STATUS_POLL_PROBLEM_MS * 2 ** failures, STATUS_BACKOFF_MAX_MS));
} finally {
clearTimeout(timeout);
}
}
const onVisible = () => {
if (document.visibilityState === 'visible') poll();
};
document.addEventListener('visibilitychange', onVisible);
poll();
return () => {
stopped = true;
if (timer) clearTimeout(timer);
controller?.abort();
document.removeEventListener('visibilitychange', onVisible);
};
// pageKey identifies the page; the object itself is rebuilt from config.
// eslint-disable-next-line react-hooks/exhaustive-deps
}, [pageKey, urgent]);
return status;
};
+18 -3
View File
@@ -1,7 +1,7 @@
import { useCallback } from 'react'; import { useCallback, useEffect } from 'react';
import { atom, useAtom, useSetAtom } from 'jotai'; import { atom, useAtom, useSetAtom } from 'jotai';
import { useTauriEvent } from './useTauri'; import { useTauriEvent } from './useTauri';
import { UpdatePhase, parseUpdateError } from '../utils/updateErrors'; import { InstallKind, UpdatePhase, parseUpdateError, toInstallKind } from '../utils/updateErrors';
type TauriInternals = { invoke: (cmd: string, args?: Record<string, unknown>) => Promise<unknown> }; type TauriInternals = { invoke: (cmd: string, args?: Record<string, unknown>) => Promise<unknown> };
const tauriInvoke = (): TauriInternals['invoke'] | undefined => const tauriInvoke = (): TauriInternals['invoke'] | undefined =>
@@ -36,6 +36,11 @@ export type UpdateFailure = { phase: UpdatePhase; message: string };
// mid-request by the resolve/reject below, so nothing gets stuck. // mid-request by the resolve/reject below, so nothing gets stuck.
const updateStatusAtom = atom<UpdateStatus>({ state: 'idle' }); const updateStatusAtom = atom<UpdateStatus>({ state: 'idle' });
// How this install gets updated; asked once. A desktop build without the
// command (older than it) rejects the call: keep the old in-app behaviour.
const installKindAtom = atom<InstallKind | undefined>(undefined);
let installKindRequested = false;
/** /**
* Mirror native download progress into the status. Mounted once (in * Mirror native download progress into the status. Mounted once (in
* TauriUpdateFeature) so the listener isn't duplicated per consumer. * TauriUpdateFeature) so the listener isn't duplicated per consumer.
@@ -50,6 +55,16 @@ export function useTauriUpdateProgress(): void {
export function useTauriUpdater() { export function useTauriUpdater() {
const isTauri = !!tauriInvoke(); const isTauri = !!tauriInvoke();
const [status, setStatus] = useAtom(updateStatusAtom); const [status, setStatus] = useAtom(updateStatusAtom);
const [installKind, setInstallKind] = useAtom(installKindAtom);
useEffect(() => {
const invoke = tauriInvoke();
if (!invoke || installKindRequested) return;
installKindRequested = true;
invoke('update_install_kind')
.then((kind) => setInstallKind(toInstallKind(kind)))
.catch(() => setInstallKind('in-app'));
}, [setInstallKind]);
const check = useCallback(async () => { const check = useCallback(async () => {
const invoke = tauriInvoke(); const invoke = tauriInvoke();
@@ -89,5 +104,5 @@ export function useTauriUpdater() {
} }
}, [setStatus]); }, [setStatus]);
return { isTauri, status, check, install }; return { isTauri, status, check, install, installKind: installKind ?? 'in-app' };
} }
+14 -2
View File
@@ -36,7 +36,11 @@ import { applyCustomAccent, removeCustomAccent } from '../utils/accentColor';
import { zIndices } from '../styles/zIndex'; import { zIndices } from '../styles/zIndex';
import { OIDC_CALLBACK_PATH } from './paths'; import { OIDC_CALLBACK_PATH } from './paths';
import { OidcCallback } from './auth/oidc/OidcCallback'; import { OidcCallback } from './auth/oidc/OidcCallback';
import { resolveCallPageUrl, setCallPageUrl } from '../plugins/call/callPageUrl'; import {
resolveCallPageUrl,
resolveDesktopCallPageUrl,
setCallPageUrl,
} from '../plugins/call/callPageUrl';
// The emoji families (Twemoji when "Twitter emoji" is on, Twemoji flags on // The emoji families (Twemoji when "Twitter emoji" is on, Twemoji flags on
// Windows — see SystemEmojiFeature) must sit before the generic family, or the // Windows — see SystemEmojiFeature) must sit before the generic family, or the
@@ -223,7 +227,15 @@ function App() {
> >
{(clientConfig) => { {(clientConfig) => {
// [Gitea #43] Idempotent: where the call page is loaded from. // [Gitea #43] Idempotent: where the call page is loaded from.
setCallPageUrl(resolveCallPageUrl(clientConfig.elementCallUrl, isTauri())); setCallPageUrl(
isTauri()
? resolveDesktopCallPageUrl(
clientConfig.desktopCallOrigin,
window.location.origin,
import.meta.env.BASE_URL,
)
: resolveCallPageUrl(clientConfig.elementCallUrl, false),
);
return ( return (
<ClientConfigProvider value={clientConfig}> <ClientConfigProvider value={clientConfig}>
<QueryClientProvider client={queryClient}> <QueryClientProvider client={queryClient}>
+4
View File
@@ -30,6 +30,7 @@ import { AuthFlowsLoader } from '../../components/AuthFlowsLoader';
import { AuthFlowsProvider } from '../../hooks/useAuthFlows'; import { AuthFlowsProvider } from '../../hooks/useAuthFlows';
import { AuthServerProvider } from '../../hooks/useAuthServer'; import { AuthServerProvider } from '../../hooks/useAuthServer';
import { tryDecodeURIComponent } from '../../utils/dom'; import { tryDecodeURIComponent } from '../../utils/dom';
import { LoginStatusBanner } from '../../features/server-status/ServerStatusBanner';
const LotusLogo = withOriginBaseUrl(getOriginBaseUrl(), '/public/res/lotus-logo.png'); const LotusLogo = withOriginBaseUrl(getOriginBaseUrl(), '/public/res/lotus-logo.png');
@@ -125,6 +126,8 @@ export function AuthLayout() {
discoveryState.status === AsyncStatus.Success ? discoveryState.data.response : []; discoveryState.status === AsyncStatus.Success ? discoveryState.data.response : [];
return ( return (
<Box direction="Column" style={{ height: '100%' }}>
<LoginStatusBanner serverName={server} />
<Scroll variant="Background" visibility="Hover" size="300" hideTrack> <Scroll variant="Background" visibility="Hover" size="300" hideTrack>
<Box <Box
className={classNames(css.AuthLayout, PatternsCss.BackgroundDotPattern)} className={classNames(css.AuthLayout, PatternsCss.BackgroundDotPattern)}
@@ -209,5 +212,6 @@ export function AuthLayout() {
<AuthFooter /> <AuthFooter />
</Box> </Box>
</Scroll> </Scroll>
</Box>
); );
} }
+16 -4
View File
@@ -69,6 +69,7 @@ import { dismissToastAtom, toastQueueAtom } from '../../state/toast';
import { useReminders } from '../../hooks/useReminders'; import { useReminders } from '../../hooks/useReminders';
import { getRoomRetentionMs, isExpired } from '../../utils/retention'; import { getRoomRetentionMs, isExpired } from '../../utils/retention';
import { useTauriUpdateProgress, useTauriUpdater } from '../../hooks/useTauriUpdater'; import { useTauriUpdateProgress, useTauriUpdater } from '../../hooks/useTauriUpdater';
import { settingsRequestAtom } from '../../state/settingsRequest';
import { isNetworkUpdateError } from '../../utils/updateErrors'; import { isNetworkUpdateError } from '../../utils/updateErrors';
import { invokeTauri, isTauri as isTauriApp, useTauriEvent } from '../../hooks/useTauri'; import { invokeTauri, isTauri as isTauriApp, useTauriEvent } from '../../hooks/useTauri';
import { CloseBehaviorPrompt } from '../../components/CloseBehaviorPrompt'; import { CloseBehaviorPrompt } from '../../components/CloseBehaviorPrompt';
@@ -913,7 +914,8 @@ const UPDATE_PROGRESS_TOAST = 'tauri-update-progress';
const UPDATE_FAILED_TOAST = 'tauri-update-failed'; const UPDATE_FAILED_TOAST = 'tauri-update-failed';
function TauriUpdateFeature() { function TauriUpdateFeature() {
const { isTauri, status, check, install } = useTauriUpdater(); const { isTauri, status, check, install, installKind } = useTauriUpdater();
const requestSettings = useSetAtom(settingsRequestAtom);
useTauriUpdateProgress(); useTauriUpdateProgress();
const setToast = useSetAtom(toastQueueAtom); const setToast = useSetAtom(toastQueueAtom);
const dismissToast = useSetAtom(dismissToastAtom); const dismissToast = useSetAtom(dismissToastAtom);
@@ -972,18 +974,24 @@ function TauriUpdateFeature() {
if (status.state !== 'available') return; if (status.state !== 'available') return;
if (firedRef.current === status.version) return; if (firedRef.current === status.version) return;
firedRef.current = status.version; firedRef.current = status.version;
// A Linux package install can't be updated in place: point at the
// package-manager command in Settings instead of an install that fails.
const viaPackage = installKind !== 'in-app';
setToast({ setToast({
id: `tauri-update-${status.version}`, id: `tauri-update-${status.version}`,
displayName: '⬆ Update Available', displayName: '⬆ Update Available',
body: `Lotus Chat ${status.version} is ready. Click to install and restart.`, body: viaPackage
? `Lotus Chat ${status.version} is available. Click for the command to update it with your package manager.`
: `Lotus Chat ${status.version} is ready. Click to install and restart.`,
roomName: 'System', roomName: 'System',
roomId: '', roomId: '',
onClick: () => { onClick: () => {
installFromToast(); if (viaPackage) requestSettings('general');
else installFromToast();
}, },
sticky: true, sticky: true,
}); });
}, [status, setToast, installFromToast]); }, [status, setToast, installFromToast, installKind, requestSettings]);
// [cinny-desktop #6] Mirror a pending update into the tray ("Restart to // [cinny-desktop #6] Mirror a pending update into the tray ("Restart to
// update" + tooltip) so a dismissed toast isn't the only reminder. Kept while // update" + tooltip) so a dismissed toast isn't the only reminder. Kept while
@@ -1072,6 +1080,10 @@ function ClockSkewFeature() {
data, data,
) => { ) => {
if (!data.liveEvent) return; if (!data.liveEvent) return;
// Only events our homeserver stamped: a federated event's
// origin_server_ts is the other server's clock.
const senderServer = mEvent.getSender()?.split(':').slice(1).join(':');
if (senderServer !== mx.getDomain()) return;
monitor.sample(mEvent.getTs(), mEvent.getAge(), mEvent.localTimestamp); monitor.sample(mEvent.getTs(), mEvent.getAge(), mEvent.localTimestamp);
}; };
mx.on(RoomEvent.Timeline, onTimeline); mx.on(RoomEvent.Timeline, onTimeline);
+9
View File
@@ -44,6 +44,11 @@ import { useSyncState } from '../../hooks/useSyncState';
import { stopPropagation } from '../../utils/keyboard'; import { stopPropagation } from '../../utils/keyboard';
import { SyncStatus } from './SyncStatus'; import { SyncStatus } from './SyncStatus';
import { ClockSkewBanner } from './ClockSkewBanner'; import { ClockSkewBanner } from './ClockSkewBanner';
import {
ServerStatusBanner,
ServerStatusFeature,
} from '../../features/server-status/ServerStatusBanner';
import { SecurityBanner } from '../../features/security-nudge/SecurityBanner';
import { AuthMetadataProvider } from '../../hooks/useAuthMetadata'; import { AuthMetadataProvider } from '../../hooks/useAuthMetadata';
import { getFallbackSession, removeFallbackSession } from '../../state/sessions'; import { getFallbackSession, removeFallbackSession } from '../../state/sessions';
import { pushSessionToSW } from '../../../sw-session'; import { pushSessionToSW } from '../../../sw-session';
@@ -245,6 +250,8 @@ export function ClientRoot({ children }: ClientRootProps) {
return ( return (
<AutoDiscovery userId={userId!} baseUrl={baseUrl!}> <AutoDiscovery userId={userId!} baseUrl={baseUrl!}>
<SpecVersions baseUrl={baseUrl!}> <SpecVersions baseUrl={baseUrl!}>
{mx && <ServerStatusFeature mx={mx} />}
{mx && !syncError && <ServerStatusBanner />}
{mx && !syncError && <SyncStatus mx={mx} />} {mx && !syncError && <SyncStatus mx={mx} />}
{mx && !syncError && <ClockSkewBanner />} {mx && !syncError && <ClockSkewBanner />}
{loading && <ClientRootOptions mx={mx} />} {loading && <ClientRootOptions mx={mx} />}
@@ -307,6 +314,8 @@ export function ClientRoot({ children }: ClientRootProps) {
<ClientRootLoading /> <ClientRootLoading />
) : ( ) : (
<MatrixClientProvider value={mx}> <MatrixClientProvider value={mx}>
{/* [Gitea #110/#123] Needs the client context (its hooks read it). */}
{!syncError && <SecurityBanner />}
<ServerConfigsLoader> <ServerConfigsLoader>
{(serverConfigs) => ( {(serverConfigs) => (
<CapabilitiesProvider value={serverConfigs.capabilities ?? {}}> <CapabilitiesProvider value={serverConfigs.capabilities ?? {}}>
+3 -3
View File
@@ -19,7 +19,7 @@ const readDismissedUntil = (): number => {
}; };
/** /**
* [Gitea #158] "Your computer's clock is 14 minutes ahead of the server." * [Gitea #158] "This device's clock is 14 minutes ahead of the server."
* Same slot and style as the sync banners. Shown while the skew monitor is * Same slot and style as the sync banners. Shown while the skew monitor is
* over its threshold; the direction matters, so it is said. Dismissable for * over its threshold; the direction matters, so it is said. Dismissable for
* 24 h; never auto-corrects anything. * 24 h; never auto-corrects anything.
@@ -53,8 +53,8 @@ export function ClockSkewBanner() {
> >
<Box alignItems="Center" gap="300" wrap="Wrap" justifyContent="Center"> <Box alignItems="Center" gap="300" wrap="Wrap" justifyContent="Center">
<Text size="L400" align="Center"> <Text size="L400" align="Center">
Your computer&apos;s clock is <b>{describeSkewVsServer(skewMs)}</b>. Encrypted messages This device&apos;s clock is <b>{describeSkewVsServer(skewMs)}</b>. Voice calls and
and voice calls will fail until it is fixed. encrypted messages can fail until it&apos;s corrected.
</Text> </Text>
<Button <Button
size="300" size="300"
+23 -4
View File
@@ -1,8 +1,11 @@
import { MatrixClient, SyncState } from 'matrix-js-sdk'; import { MatrixClient, SyncState } from 'matrix-js-sdk';
import React, { useCallback, useState } from 'react'; import React, { useCallback, useState } from 'react';
import { useAtomValue } from 'jotai';
import { Box, config, Line, Text } from 'folds'; import { Box, config, Line, Text } from 'folds';
import { useSyncState } from '../../hooks/useSyncState'; import { useSyncState } from '../../hooks/useSyncState';
import { ContainerColor } from '../../styles/ContainerColor.css'; import { ContainerColor } from '../../styles/ContainerColor.css';
import { serverStatusAtom } from '../../state/serverStatus';
import { serverConfirmedUpSince } from '../../utils/kumaStatus';
type StateData = { type StateData = {
current: SyncState | null; current: SyncState | null;
@@ -13,6 +16,7 @@ type SyncStatusProps = {
mx: MatrixClient; mx: MatrixClient;
}; };
export function SyncStatus({ mx }: SyncStatusProps) { export function SyncStatus({ mx }: SyncStatusProps) {
const serverStatus = useAtomValue(serverStatusAtom);
const [stateData, setStateData] = useState<StateData>({ const [stateData, setStateData] = useState<StateData>({
current: null, current: null,
previous: undefined, previous: undefined,
@@ -53,7 +57,14 @@ export function SyncStatus({ mx }: SyncStatusProps) {
); );
} }
if (stateData.current === SyncState.Reconnecting) { // [Gitea #124] When Kuma confirms the homeserver is down, the status banner
// says so ("Lotus Chat's server is down…") instead of "Connection Lost!".
const serverDown = serverStatus.status?.homeserver === 'down';
// Only blame the user's connection when Kuma has checked the server since
// the drop and it was fine (a stale "up" from before proves nothing).
const serverUp = serverConfirmedUpSince(serverStatus.status, serverStatus.lostAt);
if (stateData.current === SyncState.Reconnecting && !serverDown) {
return ( return (
<Box direction="Column" shrink="No"> <Box direction="Column" shrink="No">
<Box <Box
@@ -64,14 +75,18 @@ export function SyncStatus({ mx }: SyncStatusProps) {
role="status" role="status"
aria-live="polite" aria-live="polite"
> >
<Text size="L400">Connection Lost! Reconnecting...</Text> <Text size="L400">
{serverUp
? "Connection lost. Our status checks say Lotus Chat's server is up, so it may be your internet connection. Reconnecting…"
: 'Connection Lost! Reconnecting...'}
</Text>
</Box> </Box>
<Line variant="Warning" size="300" /> <Line variant="Warning" size="300" />
</Box> </Box>
); );
} }
if (stateData.current === SyncState.Error) { if (stateData.current === SyncState.Error && !serverDown) {
return ( return (
<Box direction="Column" shrink="No"> <Box direction="Column" shrink="No">
<Box <Box
@@ -82,7 +97,11 @@ export function SyncStatus({ mx }: SyncStatusProps) {
role="alert" role="alert"
aria-live="assertive" aria-live="assertive"
> >
<Text size="L400">Connection Lost!</Text> <Text size="L400">
{serverUp
? "Connection lost. Our status checks say Lotus Chat's server is up, so check your internet connection."
: 'Connection Lost!'}
</Text>
</Box> </Box>
<Line variant="Critical" size="300" /> <Line variant="Critical" size="300" />
</Box> </Box>
+42 -1
View File
@@ -1,6 +1,6 @@
import { test } from 'node:test'; import { test } from 'node:test';
import assert from 'node:assert/strict'; import assert from 'node:assert/strict';
import { resolveCallPageUrl } from './callPageUrl'; import { resolveCallPageUrl, resolveDesktopCallPageUrl } from './callPageUrl';
const URL_OK = 'https://call.chat.example.org/public/element-call/index.html'; const URL_OK = 'https://call.chat.example.org/public/element-call/index.html';
@@ -38,3 +38,44 @@ test('anything else falls back to the bundled page', () => {
'data:text/html,x', 'data:text/html,x',
].forEach((v) => assert.equal(resolveCallPageUrl(v, false), undefined, String(v))); ].forEach((v) => assert.equal(resolveCallPageUrl(v, false), undefined, String(v)));
}); });
const APP = 'http://localhost:44548';
const PAGE = '/public/element-call/index.html';
test('desktop: the bundled page from the loopback origin on the same port', () => {
assert.equal(
resolveDesktopCallPageUrl('http://127.0.0.1:44548', APP, '/'),
`http://127.0.0.1:44548${PAGE}`,
);
assert.equal(
resolveDesktopCallPageUrl('http://127.0.0.1:44548/', APP, '/app/'),
`http://127.0.0.1:44548/app${PAGE}`,
);
});
test('desktop: unset or anything but same-port loopback http keeps the same-origin page', () => {
[
undefined,
'',
'http://127.0.0.1:44549',
'http://127.0.0.1',
'https://127.0.0.1:44548',
'http://localhost:44548',
'http://[::1]:44548',
'http://10.0.0.5:44548',
'https://call.chat.lotusguild.org',
'http://127.0.0.1:44548/evil/',
'http://127.0.0.1:44548/?x=1',
'http://user:pw@127.0.0.1:44548',
'not a url',
42,
].forEach((v) => assert.equal(resolveDesktopCallPageUrl(v, APP, '/'), undefined, String(v)));
});
test('desktop: only when the app itself runs on http://localhost (release builds)', () => {
const v = 'http://127.0.0.1:44548';
assert.equal(resolveDesktopCallPageUrl(v, 'tauri://localhost', '/'), undefined);
assert.equal(resolveDesktopCallPageUrl(v, 'http://tauri.localhost', '/'), undefined);
assert.equal(resolveDesktopCallPageUrl(v, 'https://chat.lotusguild.org', '/'), undefined);
assert.equal(resolveDesktopCallPageUrl(v, 'http://localhost', '/'), undefined);
});
+37 -3
View File
@@ -7,9 +7,9 @@
* app loads it from that origin instead, so the call frame can no longer * app loads it from that origin instead, so the call frame can no longer
* reach this origin's storage (login token, crypto store) or service worker. * reach this origin's storage (login token, crypto store) or service worker.
* *
* Web only: the desktop app keeps its bundled copy (its CSP doesn't allow * Web only: the desktop app keeps its bundled copy (a network copy could
* another frame origin, and a network copy could drift from the bundle). * drift from the bundle); see resolveDesktopCallPageUrl for how it isolates
* Anything that isn't an absolute https URL (http only on localhost, for * it. Anything that isn't an absolute https URL (http only on localhost, for
* development) is ignored, so a bad value falls * development) is ignored, so a bad value falls
* back to the bundled page instead of breaking calls. * back to the bundled page instead of breaking calls.
*/ */
@@ -28,6 +28,40 @@ export const resolveCallPageUrl = (value: unknown, desktop: boolean): string | u
} }
}; };
/**
* [Gitea #43] Desktop: the bundled call page from a second origin.
*
* The desktop app is served by its local server at http://localhost:<port>.
* The same server answers on http://127.0.0.1:<port>, which is a different
* origin (and still a secure context), so loading the bundled call page from
* there cuts the call frame off from the app's storage (login token, crypto
* store) without a network copy that could drift from the bundle.
*
* Only used when cinny-desktop sets `desktopCallOrigin` (it ships the server
* and CSP changes this needs in the same release), only for a loopback http
* origin on the SAME port as the app, and only when the app itself runs on
* http://localhost (release builds). Anything else keeps the same-origin page.
*/
export const resolveDesktopCallPageUrl = (
value: unknown,
appOrigin: string,
basePath: string,
): string | undefined => {
if (typeof value !== 'string' || value.trim() === '') return undefined;
try {
const app = new URL(appOrigin);
const call = new URL(value);
if (app.protocol !== 'http:' || app.hostname !== 'localhost' || !app.port) return undefined;
if (call.protocol !== 'http:' || call.hostname !== '127.0.0.1') return undefined;
if (call.port !== app.port || call.username || call.password) return undefined;
if (call.pathname !== '/' || call.search || call.hash) return undefined;
const base = basePath.replace(/\/+$/, '');
return `${call.origin}${base}/public/element-call/index.html`;
} catch {
return undefined;
}
};
let callPageUrl: string | undefined; let callPageUrl: string | undefined;
export const setCallPageUrl = (url: string | undefined): void => { export const setCallPageUrl = (url: string | undefined): void => {
+117
View File
@@ -0,0 +1,117 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { KeychainInvoke, sameTokens, syncKeychain, tokensOf } from './keychainMirror';
import type { Session } from './sessions';
const session: Session = {
baseUrl: 'https://matrix.example.org',
userId: '@alice:example.org',
deviceId: 'DEV1',
accessToken: 'syt_token',
refreshToken: 'mar_refresh',
};
/** An in-memory keychain behind the same commands the desktop app exposes. */
const fakeKeychain = (opts: { supported?: boolean; failSet?: boolean; corrupt?: boolean } = {}) => {
let stored: unknown = null;
const calls: string[] = [];
const invoke: KeychainInvoke = async (cmd, args) => {
calls.push(cmd);
switch (cmd) {
case 'secure_session_supported':
return opts.supported ?? true;
case 'secure_session_get':
return stored;
case 'secure_session_set':
if (opts.failSet) throw new Error('Access is denied.');
stored = opts.corrupt ? { ...(args?.tokens as object), accessToken: 'x' } : args?.tokens;
return null;
case 'secure_session_clear':
stored = null;
return null;
default:
throw new Error(`unknown ${cmd}`);
}
};
return { invoke, calls, get: () => stored };
};
test('stores the tokens (not the whole session) and verifies them', async () => {
const kc = fakeKeychain();
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
assert.deepEqual(kc.get(), {
userId: '@alice:example.org',
deviceId: 'DEV1',
accessToken: 'syt_token',
refreshToken: 'mar_refresh',
});
assert.deepEqual(kc.calls, [
'secure_session_supported',
'secure_session_get',
'secure_session_set',
'secure_session_get',
]);
});
test('an up-to-date copy is not rewritten', async () => {
const kc = fakeKeychain();
await syncKeychain(kc.invoke, session);
kc.calls.length = 0;
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
assert.deepEqual(kc.calls, ['secure_session_supported', 'secure_session_get']);
});
test('a token rotation rewrites; no session clears', async () => {
const kc = fakeKeychain();
await syncKeychain(kc.invoke, session);
await syncKeychain(kc.invoke, { ...session, accessToken: 'syt_new', refreshToken: undefined });
assert.equal((kc.get() as { accessToken: string }).accessToken, 'syt_new');
assert.equal('refreshToken' in (kc.get() as object), false);
assert.deepEqual(await syncKeychain(kc.invoke, null), { state: 'cleared' });
assert.equal(kc.get(), null);
});
test('unsupported platform: nothing is touched', async () => {
const kc = fakeKeychain({ supported: false });
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'unsupported' });
assert.deepEqual(kc.calls, ['secure_session_supported']);
});
test('failures become a status, never an exception', async () => {
assert.deepEqual(await syncKeychain(fakeKeychain({ failSet: true }).invoke, session), {
state: 'error',
error: 'Access is denied.',
});
assert.deepEqual(await syncKeychain(fakeKeychain({ corrupt: true }).invoke, session), {
state: 'error',
error: 'read-back did not match',
});
// The credential store hangs (the support check itself is instant).
const hung: KeychainInvoke = async (cmd) =>
cmd === 'secure_session_supported'
? true
: new Promise(() => {
/* never settles */
});
assert.deepEqual(await syncKeychain(hung, session, 50), {
state: 'error',
error: 'keychain timed out',
});
});
test('a desktop build without the commands reads as unsupported, not an error', async () => {
const missingCommand: KeychainInvoke = async (cmd) => {
throw new Error(`Command ${cmd} not found`);
};
assert.deepEqual(await syncKeychain(missingCommand, session), { state: 'unsupported' });
});
test('sameTokens compares only the secrets, treating a missing refresh token as absent', () => {
const t = tokensOf({ ...session, refreshToken: undefined });
assert.equal(sameTokens({ ...t }, t), true);
assert.equal(sameTokens({ ...t, refreshToken: undefined }, t), true);
assert.equal(sameTokens({ ...t, accessToken: 'other' }, t), false);
assert.equal(sameTokens({ ...t, refreshToken: 'r' }, t), false);
assert.equal(sameTokens(null, t), false);
assert.equal(sameTokens('string', t), false);
});
+141
View File
@@ -0,0 +1,141 @@
import { useEffect, useState } from 'react';
import { getFallbackSession, onSessionPersisted, Session } from './sessions';
/**
* [Gitea #105] Desktop, step 1: mirror the login tokens into the OS keychain.
*
* The session is still read from localStorage exactly as before; this only
* keeps a copy in the keychain (Windows Credential Manager) and checks it by
* reading it back, so real installs prove the keychain works before step 2
* switches reads over to it. Nothing here can log anyone out: every failure
* just records a status for Settings.
*
* Writes are serialized (a token rotation right after login must not race
* the login's write) and time out, so a hung credential store can't pile up.
* When there's no session the keychain entry is cleared, which also covers a
* logout whose page reload beat the clear.
*/
export type KeychainTokens = {
userId: string;
deviceId: string;
accessToken: string;
refreshToken?: string;
};
export type KeychainMirrorStatus =
| { state: 'idle' }
| { state: 'unsupported' }
| { state: 'ok' }
| { state: 'cleared' }
| { state: 'error'; error: string };
export type KeychainInvoke = (cmd: string, args?: Record<string, unknown>) => Promise<unknown>;
export const KEYCHAIN_TIMEOUT_MS = 5000;
export const tokensOf = (session: Session): KeychainTokens => ({
userId: session.userId,
deviceId: session.deviceId,
accessToken: session.accessToken,
...(session.refreshToken ? { refreshToken: session.refreshToken } : {}),
});
export const sameTokens = (a: unknown, b: KeychainTokens): boolean => {
if (!a || typeof a !== 'object') return false;
const t = a as Partial<KeychainTokens>;
return (
t.userId === b.userId &&
t.deviceId === b.deviceId &&
t.accessToken === b.accessToken &&
(t.refreshToken ?? undefined) === (b.refreshToken ?? undefined)
);
};
const withTimeout = <T>(p: Promise<T>, ms: number): Promise<T> =>
new Promise<T>((resolve, reject) => {
const timer = setTimeout(() => reject(new Error('keychain timed out')), ms);
p.then(
(v) => {
clearTimeout(timer);
resolve(v);
},
(e) => {
clearTimeout(timer);
reject(e);
},
);
});
const errorText = (e: unknown): string =>
(e instanceof Error ? e.message : String(e)).slice(0, 200);
/**
* Bring the keychain in line with `session` (null = no session). Reads first
* and only writes when the stored copy differs, then verifies by reading back.
*/
export const syncKeychain = async (
invoke: KeychainInvoke,
session: Session | null,
timeoutMs = KEYCHAIN_TIMEOUT_MS,
): Promise<KeychainMirrorStatus> => {
// A desktop build without the commands (older than this feature) rejects
// the call: that is "not supported", not an error to show the user.
let supported: unknown;
try {
supported = await withTimeout(invoke('secure_session_supported'), timeoutMs);
} catch {
supported = false;
}
if (supported !== true) return { state: 'unsupported' };
try {
if (!session) {
await withTimeout(invoke('secure_session_clear'), timeoutMs);
return { state: 'cleared' };
}
const tokens = tokensOf(session);
const stored = await withTimeout(invoke('secure_session_get'), timeoutMs);
if (sameTokens(stored, tokens)) return { state: 'ok' };
await withTimeout(invoke('secure_session_set', { tokens }), timeoutMs);
const back = await withTimeout(invoke('secure_session_get'), timeoutMs);
if (!sameTokens(back, tokens)) return { state: 'error', error: 'read-back did not match' };
return { state: 'ok' };
} catch (e) {
return { state: 'error', error: errorText(e) };
}
};
let status: KeychainMirrorStatus = { state: 'idle' };
const statusListeners = new Set<(s: KeychainMirrorStatus) => void>();
const setStatus = (next: KeychainMirrorStatus): void => {
status = next;
statusListeners.forEach((cb) => cb(next));
};
export const getKeychainMirrorStatus = (): KeychainMirrorStatus => status;
let started = false;
/** Start mirroring (desktop only; call once at boot). */
export const startKeychainMirror = (invoke: KeychainInvoke | undefined): void => {
if (!invoke || started) return;
started = true;
let chain: Promise<unknown> = Promise.resolve();
const enqueue = (session: Session | null) => {
chain = chain.then(async () => setStatus(await syncKeychain(invoke, session)));
};
enqueue(getFallbackSession() ?? null);
onSessionPersisted((session) => enqueue(session));
};
export const useKeychainMirrorStatus = (): KeychainMirrorStatus => {
const [value, setValue] = useState(status);
useEffect(() => {
setValue(status);
statusListeners.add(setValue);
return () => {
statusListeners.delete(setValue);
};
}, []);
return value;
};
+6 -1
View File
@@ -8,6 +8,7 @@ import { clearNavToActivePathStore } from './navToActivePath';
import { DRAFT_MSG_KEY_PREFIX } from '../utils/draft'; import { DRAFT_MSG_KEY_PREFIX } from '../utils/draft';
import { clearCallSession } from '../utils/callRejoin'; import { clearCallSession } from '../utils/callRejoin';
import { clearOutbox } from '../utils/outbox'; import { clearOutbox } from '../utils/outbox';
import { NUDGE_KEY_PREFIX } from '../utils/securityNudge';
/** /**
* [Gitea #41] Wipe every persisted composer draft (`draft-msg-<roomId>`). Drafts * [Gitea #41] Wipe every persisted composer draft (`draft-msg-<roomId>`). Drafts
@@ -77,7 +78,11 @@ const clearStatusMessage = (): void => {
return; return;
} }
keys.forEach((key) => { keys.forEach((key) => {
if (key.startsWith('lotus-status-msg-') || key.startsWith('lotus-status-expiry-')) { if (
key.startsWith('lotus-status-msg-') ||
key.startsWith('lotus-status-expiry-') ||
key.startsWith(NUDGE_KEY_PREFIX)
) {
try { try {
localStorage.removeItem(key); localStorage.removeItem(key);
} catch { } catch {
+18
View File
@@ -0,0 +1,18 @@
import { atom } from 'jotai';
import { ServerStatus } from '../utils/kumaStatus';
/**
* [Gitea #124] The homeserver's status from its Kuma status page (null: none
* configured, not fetched yet, or Kuma unreachable — all mean "no banner"),
* plus whether this client's own connection is currently lost.
*/
export const serverStatusAtom = atom<{
status: ServerStatus | null;
syncLost: boolean;
/** When this client's connection dropped (ms), null while connected. */
lostAt: number | null;
}>({
status: null,
syncLost: false,
lostAt: null,
});
+17
View File
@@ -432,3 +432,20 @@ test('subscribeSessionChanges ignores unrelated storage keys', () => {
listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' })); listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' }));
assert.equal(fired, false); assert.equal(fired, false);
}); });
test('onSessionPersisted: told about writes and removals; a throwing listener is harmless', async () => {
installStorage();
const { onSessionPersisted } = await import('./sessions');
const seen: (string | null)[] = [];
const offBad = onSessionPersisted(() => {
throw new Error('boom');
});
const off = onSessionPersisted((s) => seen.push(s ? s.accessToken : null));
setFallbackSession('tok-a', 'DEV', '@a:hs', 'https://hs', { refreshToken: 'ref-a' });
removeFallbackSession();
off();
offBad();
setFallbackSession('tok-b', 'DEV', '@a:hs', 'https://hs');
assert.deepEqual(seen, ['tok-a', null]);
assert.equal(getFallbackSession()?.accessToken, 'tok-b', 'write still happened');
});
+23
View File
@@ -233,6 +233,27 @@ export type SessionStoreName = {
// crypto: 'crypto-store', // crypto: 'crypto-store',
// } as const; // } as const;
// [Gitea #105] Listeners told about every session write in THIS tab (login,
// token rotation) and removal (logout), e.g. the desktop keychain mirror.
// A throwing listener never breaks the write.
type PersistListener = (session: Session | null) => void;
const persistListeners = new Set<PersistListener>();
const notifyPersisted = (session: Session | null): void => {
persistListeners.forEach((cb) => {
try {
cb(session);
} catch {
/* listener errors must not affect login/logout */
}
});
};
export const onSessionPersisted = (cb: PersistListener): (() => void) => {
persistListeners.add(cb);
return () => {
persistListeners.delete(cb);
};
};
// Persist the session. Writes the atomic blob FIRST (so the consistent, // Persist the session. Writes the atomic blob FIRST (so the consistent,
// never-torn copy is established before the multi-key legacy write), then // never-torn copy is established before the multi-key legacy write), then
// dual-writes the legacy keys for rollback safety. Signature is unchanged — // dual-writes the legacy keys for rollback safety. Signature is unchanged —
@@ -249,6 +270,7 @@ export function setFallbackSession(
localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted)); localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted));
// Dual-write the legacy keys (removal of this half is a future release). // Dual-write the legacy keys (removal of this half is a future release).
writeLegacyKeys(persisted); writeLegacyKeys(persisted);
notifyPersisted(sessionFromPersisted(persisted));
} }
// Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring // Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring
@@ -257,6 +279,7 @@ export const removeFallbackSession = () => {
localStorage.removeItem(SESSION_BLOB_KEY); localStorage.removeItem(SESSION_BLOB_KEY);
Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key)); Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key));
Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key)); Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key));
notifyPersisted(null);
}; };
// Read the session, preferring the atomic blob. If the blob is absent or // Read the session, preferring the atomic blob. If the blob is absent or
+76 -27
View File
@@ -8,44 +8,96 @@ import {
formatSkew, formatSkew,
} from './clockSkew'; } from './clockSkew';
// A live event received when the local clock is `skew` ms ahead of the server: const T = 1_700_000_000_000;
// origin_server_ts = T (server clock), age = a, localTimestamp = (T + a + skew) - a.
const feed = (m: ClockSkewMonitor, skew: number, age = 500, t = 1_700_000_000_000) =>
m.sample(t, age, t + skew);
test('needs three samples, then reports the median with direction', () => { /**
* A live event received `atSec` seconds into the test, when the local clock is
* `skew` ms off the server and the response took `delay` ms to arrive:
* localTimestamp − origin_server_ts = skew + delay.
*/
const feed = (m: ClockSkewMonitor, skew: number, atSec = 0, delay = 0, wallJump = 0) =>
m.sample(T, 500, T + skew + delay, { wall: T + atSec * 1000 + wallJump, mono: atSec * 1000 });
test('behind: reported as soon as there are three samples', () => {
const m = new ClockSkewMonitor(); const m = new ClockSkewMonitor();
assert.equal(feed(m, 60_000).skewMs, null); assert.equal(feed(m, -60_000, 0).skewMs, null);
assert.equal(feed(m, 61_000).skewMs, null); assert.equal(feed(m, -61_000, 1).skewMs, null);
const s = feed(m, 59_000); const s = feed(m, -59_000, 2);
assert.equal(s.skewMs, 60_000); assert.equal(s.skewMs, -61_000);
assert.equal(s.warning, true); assert.equal(s.warning, true);
assert.equal(formatSkew(s.skewMs!), '60 seconds ahead'); assert.equal(formatSkew(s.skewMs!), '61 seconds behind');
}); });
test('one bad sample cannot trip the warning (median) and hysteresis clears only under 15 s', () => { test('ahead: only once it has held for a minute', () => {
const m = new ClockSkewMonitor(); const m = new ClockSkewMonitor();
feed(m, 1000); feed(m, 60_000, 0);
feed(m, 1500); feed(m, 60_000, 10);
assert.equal(feed(m, 90_000).warning, false); // outlier assert.equal(feed(m, 60_000, 20).warning, false);
assert.equal(m.getState().skewMs, 1500); assert.equal(m.getState().skewMs, 60_000);
assert.equal(feed(m, 60_000, 59).warning, false);
assert.equal(feed(m, 60_000, 61).warning, true);
});
test('server stall (2026-09-29): a burst of late events does not read as a wrong clock', () => {
const m = new ClockSkewMonitor();
// Normal traffic, then the homeserver stalls and one /sync arrives 30 s late
// with a pile of events, then normal traffic again.
feed(m, 200, 0);
feed(m, 150, 5);
feed(m, 300, 10);
[1, 2, 3, 4, 5, 6].forEach(() => feed(m, 0, 130, 31_000));
assert.equal(m.getState().warning, false);
assert.ok(m.getState().skewMs! < 1000);
// Fresh client whose first samples are all from the late burst.
const fresh = new ClockSkewMonitor();
[1, 2, 3, 4, 5, 6].forEach(() => feed(fresh, 0, 0, 31_000));
assert.equal(fresh.getState().warning, false);
// …and the next timely event brings the estimate back down.
feed(fresh, 0, 70, 100);
assert.equal(fresh.getState().warning, false);
assert.equal(fresh.getState().skewMs, 100);
});
test('slow deliveries mixed with fast ones: the fastest one wins', () => {
const m = new ClockSkewMonitor();
[0, 20, 40, 60, 80].forEach((at, i) => feed(m, 45_000, at, i === 2 ? 0 : 20_000));
assert.equal(m.getState().skewMs, 45_000);
assert.equal(m.getState().warning, true);
});
test('hysteresis: once on, clears only under 15 s', () => {
const w = new ClockSkewMonitor(); const w = new ClockSkewMonitor();
[40_000, 41_000, 39_000, 40_000, 40_000].forEach((s) => feed(w, s)); [0, 1, 2].forEach((at) => feed(w, -40_000, at));
assert.equal(w.getState().warning, true); assert.equal(w.getState().warning, true);
// drifting down to 20 s: still >= 15 s → stays on // Samples expire after 5 minutes; drifting to -20 s keeps it on (>= 15 s).
[20_000, 20_000, 20_000, 20_000, 20_000].forEach((s) => feed(w, s)); [400, 401, 402].forEach((at) => feed(w, -20_000, at));
assert.equal(w.getState().skewMs, -20_000);
assert.equal(w.getState().warning, true); assert.equal(w.getState().warning, true);
[10_000, 10_000, 10_000, 10_000, 10_000].forEach((s) => feed(w, s)); [800, 801, 802].forEach((at) => feed(w, -10_000, at));
assert.equal(w.getState().warning, false); assert.equal(w.getState().warning, false);
}); });
test('fixing the local clock starts the measurement afresh', () => {
const m = new ClockSkewMonitor();
[0, 1, 2].forEach((at) => feed(m, -14 * 60_000, at));
assert.equal(m.getState().warning, true);
// The user sets the clock forward 14 minutes: wall jumps vs the monotonic clock.
const jump = 14 * 60_000;
feed(m, 0, 10, 0, jump);
assert.equal(m.getState().warning, false);
assert.equal(m.getState().skewMs, null);
feed(m, 0, 11, 0, jump);
feed(m, 0, 12, 0, jump);
assert.equal(m.getState().skewMs, 0);
assert.equal(m.getState().warning, false);
});
test('stale or missing age is ignored (cache replay must not read as skew)', () => { test('stale or missing age is ignored (cache replay must not read as skew)', () => {
const m = new ClockSkewMonitor(); const m = new ClockSkewMonitor();
const t = 1_700_000_000_000; m.sample(T, undefined, T + 3_600_000);
m.sample(t, undefined, t + 3_600_000); m.sample(T, 40 * 24 * 60 * 60 * 1000, T + 3_600_000);
m.sample(t, 40 * 24 * 60 * 60 * 1000, t + 3_600_000); m.sample(T, -5, T);
m.sample(t, -5, t);
assert.equal(m.getState().skewMs, null); assert.equal(m.getState().skewMs, null);
}); });
@@ -53,10 +105,7 @@ test('subscribe fires on change only; reset clears', () => {
const m = new ClockSkewMonitor(); const m = new ClockSkewMonitor();
const seen: (number | null)[] = []; const seen: (number | null)[] = [];
m.subscribe((s) => seen.push(s.skewMs)); m.subscribe((s) => seen.push(s.skewMs));
feed(m, -120_000); [0, 1, 2, 3].forEach((at) => feed(m, -120_000, at));
feed(m, -120_000);
feed(m, -120_000);
feed(m, -120_000);
assert.deepEqual(seen, [-120_000]); assert.deepEqual(seen, [-120_000]);
assert.equal(formatSkew(-120_000), '2 minutes behind'); assert.equal(formatSkew(-120_000), '2 minutes behind');
m.reset(); m.reset();
+56 -11
View File
@@ -22,8 +22,23 @@
export const SKEW_WARN_MS = 30_000; export const SKEW_WARN_MS = 30_000;
export const SKEW_CLEAR_MS = 15_000; export const SKEW_CLEAR_MS = 15_000;
export const SKEW_SAMPLES = 5;
export const SKEW_MIN_SAMPLES = 3; export const SKEW_MIN_SAMPLES = 3;
/** Samples older than this are forgotten. */
export const SKEW_WINDOW_MS = 5 * 60 * 1000;
export const SKEW_MAX_SAMPLES = 30;
/**
* "Ahead" must hold across samples received at least this far apart.
*
* Incident 2026-09-29: the homeserver's host ran out of memory and stalled for
* ~2 minutes; the /sync that finally went out carried events whose `age` was
* computed ~30 s before it arrived, so every client read "your clock is 30 s
* ahead" — while the real problem was the server. A late delivery can only make
* the local clock look AHEAD (never behind), so the estimate is the LOWEST
* recent sample (the one delivered fastest), and "ahead" has to persist across
* a minute of fresh samples before it is reported. "Behind" can't come from a
* delay and is reported as soon as there are enough samples.
*/
export const SKEW_AHEAD_SPAN_MS = 60_000;
/** /**
* Sanity cap on `age`. Old events are still valid samples (the server computes * Sanity cap on `age`. Old events are still valid samples (the server computes
* `age` at response time, so `ts + age` is its clock regardless of the event's * `age` at response time, so `ts + age` is its clock regardless of the event's
@@ -38,14 +53,21 @@ export type ClockSkewState = {
warning: boolean; warning: boolean;
}; };
const median = (xs: number[]): number => { /** A wall-clock change larger than this (vs the monotonic clock) resets the samples. */
const s = [...xs].sort((a, b) => a - b); export const CLOCK_JUMP_MS = 5_000;
const mid = Math.floor(s.length / 2);
return s.length % 2 ? s[mid] : (s[mid - 1] + s[mid]) / 2; type Sample = { skew: number; at: number };
const currentClock = (): { wall: number; mono: number } => {
const wall = Date.now();
const mono = typeof performance !== 'undefined' ? performance.now() : wall;
return { wall, mono };
}; };
export class ClockSkewMonitor { export class ClockSkewMonitor {
private samples: number[] = []; private samples: Sample[] = [];
private clockOffset: number | undefined;
private state: ClockSkewState = { skewMs: null, warning: false }; private state: ClockSkewState = { skewMs: null, warning: false };
@@ -64,25 +86,47 @@ export class ClockSkewMonitor {
/** /**
* Feed one live event. `originServerTs` + `age` come from the event; * Feed one live event. `originServerTs` + `age` come from the event;
* `localTimestamp` is the SDK's `Date.now() − age` at construction. * `localTimestamp` is the SDK's `Date.now() − age` at construction; `clock`
* is when the sample was taken: wall clock and a monotonic clock
* (performance.now()), so samples are aged by real elapsed time and a change
* of the local clock (someone fixing it) starts the measurement afresh.
* Only feed events stamped by OUR homeserver: another server's
* `origin_server_ts` carries that server's clock.
* Returns the new state (unchanged object when nothing moved). * Returns the new state (unchanged object when nothing moved).
*/ */
public sample( public sample(
originServerTs: number, originServerTs: number,
age: number | undefined, age: number | undefined,
localTimestamp: number, localTimestamp: number,
clock: { wall: number; mono: number } = currentClock(),
): ClockSkewState { ): ClockSkewState {
if (age === undefined || !Number.isFinite(age) || age < 0 || age > SKEW_MAX_AGE_MS) { if (age === undefined || !Number.isFinite(age) || age < 0 || age > SKEW_MAX_AGE_MS) {
return this.state; return this.state;
} }
if (!Number.isFinite(originServerTs) || !Number.isFinite(localTimestamp)) return this.state; if (!Number.isFinite(originServerTs) || !Number.isFinite(localTimestamp)) return this.state;
this.samples.push(localTimestamp - originServerTs); const now = clock.mono;
if (this.samples.length > SKEW_SAMPLES) this.samples.shift(); const offset = clock.wall - clock.mono;
if (this.clockOffset !== undefined && Math.abs(offset - this.clockOffset) > CLOCK_JUMP_MS) {
// The local clock was changed: earlier samples measured the old clock.
this.reset();
}
this.clockOffset = offset;
this.samples.push({ skew: localTimestamp - originServerTs, at: now });
this.samples = this.samples.filter((s) => now - s.at <= SKEW_WINDOW_MS);
if (this.samples.length > SKEW_MAX_SAMPLES) this.samples.shift();
if (this.samples.length < SKEW_MIN_SAMPLES) return this.state; if (this.samples.length < SKEW_MIN_SAMPLES) return this.state;
const skewMs = median(this.samples); // Delivery delay only ever adds to a sample: the smallest is the truest.
const skewMs = Math.min(...this.samples.map((s) => s.skew));
const abs = Math.abs(skewMs); const abs = Math.abs(skewMs);
const warning = this.state.warning ? abs >= SKEW_CLEAR_MS : abs > SKEW_WARN_MS; let warning: boolean;
if (this.state.warning) warning = abs >= SKEW_CLEAR_MS;
else if (skewMs < -SKEW_WARN_MS) warning = true;
else if (skewMs > SKEW_WARN_MS) {
// Ahead: only if the fastest-delivered samples stayed high for a minute.
const span = now - Math.min(...this.samples.map((s) => s.at));
warning = span >= SKEW_AHEAD_SPAN_MS;
} else warning = false;
if (skewMs === this.state.skewMs && warning === this.state.warning) return this.state; if (skewMs === this.state.skewMs && warning === this.state.warning) return this.state;
this.state = { skewMs, warning }; this.state = { skewMs, warning };
this.listeners.forEach((cb) => cb(this.state)); this.listeners.forEach((cb) => cb(this.state));
@@ -91,6 +135,7 @@ export class ClockSkewMonitor {
public reset(): void { public reset(): void {
this.samples = []; this.samples = [];
this.clockOffset = undefined;
if (this.state.skewMs !== null || this.state.warning) { if (this.state.skewMs !== null || this.state.warning) {
this.state = { skewMs: null, warning: false }; this.state = { skewMs: null, warning: false };
this.listeners.forEach((cb) => cb(this.state)); this.listeners.forEach((cb) => cb(this.state));
+262
View File
@@ -0,0 +1,262 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import {
DEFAULT_GROUPS,
kumaBeatTime,
kumaUrls,
parseKumaStatus,
pickBanner,
resolveStatusPage,
serverConfirmedUpSince,
ServerStatus,
} from './kumaStatus';
// The live `matrix` status page's groups (captured 2026-09-29).
const PAGE = {
publicGroupList: [
{ name: 'Homeserver', monitorList: [{ id: 30, name: 'Synapse HTTP' }] },
{
name: 'Voice calls',
monitorList: [
{ id: 37, name: 'Matrix: LiveKit (public /rtc)' },
{ id: 38, name: 'Matrix: call tokens (public /sfu/get)' },
{ id: 39, name: 'Matrix: call page (call.chat)' },
],
},
{ name: 'Login', monitorList: [{ id: 15, name: 'Authentication Server' }] },
],
maintenanceList: [],
incidents: [],
};
const UP = 1;
const DOWN = 0;
const PENDING = 2;
/** Kuma's beat format: "YYYY-MM-DD HH:MM:SS.mmm" in UTC, oldest first. */
const beats = (...statuses: number[]) =>
statuses.map((status, i) => ({
status,
time: `2026-09-29 14:${String(10 + i).padStart(2, '0')}:00.000`,
msg: '',
}));
const hb = (over: Record<number, number[]> = {}) => ({
heartbeatList: {
30: beats(...(over[30] ?? [UP, UP, UP])),
37: beats(...(over[37] ?? [UP, UP])),
38: beats(...(over[38] ?? [UP, UP])),
39: beats(...(over[39] ?? [UP, UP])),
15: beats(...(over[15] ?? [UP, UP])),
},
uptimeList: {},
});
const parse = (page: unknown, heartbeat: unknown) =>
parseKumaStatus(page, heartbeat, DEFAULT_GROUPS);
test('config: only a valid page for the listed homeserver', () => {
const cfg = {
'matrix.lotusguild.org': { url: 'https://isitup.lotusguild.org/', slug: 'matrix' },
};
const page = resolveStatusPage(cfg, 'matrix.lotusguild.org');
assert.deepEqual(page, {
url: 'https://isitup.lotusguild.org',
slug: 'matrix',
groups: DEFAULT_GROUPS,
});
assert.deepEqual(kumaUrls(page!), {
page: 'https://isitup.lotusguild.org/api/status-page/matrix',
heartbeat: 'https://isitup.lotusguild.org/api/status-page/heartbeat/matrix',
});
assert.equal(resolveStatusPage(cfg, 'matrix.org'), undefined, 'other homeservers: nothing');
assert.equal(resolveStatusPage(cfg, undefined), undefined);
assert.equal(resolveStatusPage(undefined, 'matrix.lotusguild.org'), undefined);
for (const bad of [
{ url: 'http://isitup.lotusguild.org', slug: 'matrix' },
{ url: ['javascript', 'alert(1)'].join(':'), slug: 'matrix' },
{ url: 'https://isitup.lotusguild.org', slug: '../admin' },
{ url: 'https://isitup.lotusguild.org', slug: '' },
{ url: 'not a url', slug: 'matrix' },
]) {
assert.equal(resolveStatusPage({ hs: bad }, 'hs'), undefined, JSON.stringify(bad));
}
assert.equal(
resolveStatusPage({ hs: { url: 'http://localhost:3001', slug: 'm' } }, 'hs')?.url,
'http://localhost:3001',
'http allowed for local development',
);
});
test('all green on the live page layout', () => {
const s = parse(PAGE, hb());
assert.equal(s.homeserver, 'up');
assert.equal(s.calls, 'up');
assert.equal(s.login, 'up');
assert.equal(pickBanner(s, { syncLost: false, where: 'client' }), undefined);
assert.equal(pickBanner(s, { syncLost: true, where: 'client' }), undefined);
});
test('down needs two failing checks: down+down or pending+down; one blip is not down', () => {
assert.equal(parse(PAGE, hb({ 30: [UP, UP, DOWN] })).homeserver, 'up', 'single failure');
assert.equal(parse(PAGE, hb({ 30: [UP, PENDING] })).homeserver, 'up', 'pending only');
assert.equal(parse(PAGE, hb({ 30: [UP, DOWN, DOWN] })).homeserver, 'down');
assert.equal(parse(PAGE, hb({ 30: [UP, PENDING, DOWN] })).homeserver, 'down');
assert.equal(parse(PAGE, hb({ 30: [DOWN, DOWN, UP] })).homeserver, 'up', 'recovered');
});
test('any failing monitor takes its group down (one piece breaks calls)', () => {
const s = parse(PAGE, hb({ 38: [DOWN, DOWN] }));
assert.equal(s.calls, 'down');
assert.equal(s.homeserver, 'up');
});
test('unknown when the group or its beats are missing, and unknown shows nothing', () => {
const s = parse({ publicGroupList: [] }, hb());
assert.deepEqual([s.homeserver, s.calls, s.login], ['unknown', 'unknown', 'unknown']);
assert.equal(parse(PAGE, { heartbeatList: {} }).homeserver, 'unknown');
assert.equal(pickBanner(s, { syncLost: true, where: 'client' }), undefined);
});
test('garbage from Kuma never throws and never shows a banner', () => {
for (const [page, heartbeat] of [
[null, null],
['<html>', 42],
[{ publicGroupList: 'x', maintenanceList: {}, incidents: 7 }, { heartbeatList: [] }],
[{ publicGroupList: [{ name: 'Homeserver', monitorList: [{ id: {} }] }] }, hb()],
]) {
const s = parse(page, heartbeat);
assert.equal(pickBanner(s, { syncLost: true, where: 'client' }), undefined);
}
assert.equal(pickBanner(null, { syncLost: true, where: 'client' }), undefined);
});
test('beat times are read as UTC; checkedAt is the oldest latest beat', () => {
assert.equal(kumaBeatTime('2026-09-29 14:16:11.804'), Date.UTC(2026, 8, 29, 14, 16, 11, 804));
assert.equal(kumaBeatTime('nope'), undefined);
const s = parse(PAGE, hb());
assert.equal(s.homeserverCheckedAt, Date.UTC(2026, 8, 29, 14, 12));
});
test('"your connection" only when Kuma checked AFTER the drop and the server was up', () => {
const s = parse(PAGE, hb());
const checked = s.homeserverCheckedAt!;
assert.equal(serverConfirmedUpSince(s, checked - 60_000), true, 'checked after the drop');
assert.equal(serverConfirmedUpSince(s, checked + 1), false, 'stale: checked before the drop');
assert.equal(serverConfirmedUpSince(s, null), false, 'not disconnected');
const down = parse(PAGE, hb({ 30: [UP, DOWN, DOWN] }));
assert.equal(serverConfirmedUpSince(down, checked - 60_000), false);
assert.equal(serverConfirmedUpSince(null, 1), false);
});
test('server down vs having problems depends on this client’s own connection', () => {
const s = parse(PAGE, hb({ 30: [DOWN, DOWN] }));
assert.equal(pickBanner(s, { syncLost: true, where: 'client' })?.kind, 'server-down');
assert.equal(pickBanner(s, { syncLost: true, where: 'client' })?.tone, 'Critical');
assert.equal(pickBanner(s, { syncLost: false, where: 'client' })?.kind, 'server-problems');
assert.equal(pickBanner(s, { syncLost: false, where: 'login' })?.kind, 'server-down');
assert.equal(pickBanner(s, { syncLost: true, where: 'client' })?.dismissable, false);
});
test('priority: server > maintenance > calls > announcement; one strip only', () => {
const s: ServerStatus = {
...parse(PAGE, hb({ 30: [DOWN, DOWN], 37: [DOWN, DOWN] })),
maintenance: [{ id: '1', title: 'Upgrade', description: '' }],
incidents: [{ id: '2', title: 'Heads up', content: '', style: 'info', updated: 'x' }],
};
assert.equal(pickBanner(s, { syncLost: true, where: 'client' })?.kind, 'server-down');
assert.equal(
pickBanner({ ...s, homeserver: 'up' }, { syncLost: false, where: 'client' })?.kind,
'maintenance',
);
assert.equal(
pickBanner({ ...s, homeserver: 'up', maintenance: [] }, { syncLost: false, where: 'client' })
?.kind,
'calls-down',
);
assert.equal(
pickBanner(
{ ...s, homeserver: 'up', maintenance: [], calls: 'up' },
{ syncLost: false, where: 'client' },
)?.kind,
'announcement',
);
});
test('calls-down is not shown on the login screen or when the whole server is down', () => {
const calls = parse(PAGE, hb({ 37: [DOWN, DOWN] }));
assert.equal(pickBanner(calls, { syncLost: false, where: 'login' }), undefined);
const both = parse(PAGE, hb({ 30: [DOWN, DOWN], 37: [DOWN, DOWN] }));
assert.equal(pickBanner(both, { syncLost: false, where: 'client' })?.kind, 'server-problems');
});
test('login-down only on the login screen', () => {
const s = parse(PAGE, hb({ 15: [DOWN, DOWN] }));
assert.equal(pickBanner(s, { syncLost: false, where: 'login' })?.kind, 'login-down');
assert.equal(pickBanner(s, { syncLost: false, where: 'client' }), undefined);
});
test('maintenance: title, end time and plain-text description', () => {
const end = '2026-09-29T22:15:00.000Z';
const s = parse(
{
...PAGE,
maintenanceList: [
{
id: 7,
title: 'Homeserver upgrade',
description: '**Synapse 1.160**, see [notes](https://x)',
status: 'under-maintenance',
timeslotList: [{ startDate: '2026-09-29T22:00:00.000Z', endDate: end }],
},
{ id: 8, title: 'Later', status: 'scheduled' },
],
},
hb(),
);
assert.equal(s.maintenance.length, 1, 'only windows under maintenance');
assert.equal(s.maintenance[0].end, Date.parse(end));
const b = pickBanner(s, { syncLost: false, where: 'client' })!;
assert.equal(b.kind, 'maintenance');
assert.match(b.text, /^Maintenance in progress until .+: Homeserver upgrade\. /);
assert.equal(b.detail, 'Synapse 1.160, see notes');
assert.equal(b.dismissable, false);
});
test('announcements: tone from style, dismissable, a new edit comes back', () => {
const incident = {
id: 3,
style: 'danger',
title: 'Planned maintenance tonight',
content: 'Calls will drop briefly.',
active: true,
createdDate: '2026-09-29 15:00:00',
lastUpdatedDate: null,
};
const s = parse({ ...PAGE, incidents: [incident] }, hb());
const b = pickBanner(s, { syncLost: false, where: 'client' })!;
assert.equal(b.kind, 'announcement');
assert.equal(b.tone, 'Critical');
assert.equal(b.dismissable, true);
const dismissed = new Set([b.key]);
assert.equal(pickBanner(s, { syncLost: false, where: 'client', dismissed }), undefined);
const edited = parse(
{ ...PAGE, incidents: [{ ...incident, lastUpdatedDate: '2026-09-29 16:00:00' }] },
hb(),
);
assert.equal(
pickBanner(edited, { syncLost: false, where: 'client', dismissed })?.kind,
'announcement',
);
const inactive = parse({ ...PAGE, incidents: [{ ...incident, active: false }] }, hb());
assert.equal(pickBanner(inactive, { syncLost: false, where: 'client' }), undefined);
const info = parse({ ...PAGE, incidents: [{ ...incident, style: 'info' }] }, hb());
assert.equal(pickBanner(info, { syncLost: false, where: 'client' })?.tone, 'Primary');
});
test('a dismissed calls-down banner lets the next one through, never hides server-down', () => {
const s = parse(PAGE, hb({ 37: [DOWN, DOWN] }));
const dismissed = new Set(['calls-down', 'server-down', 'server-problems']);
assert.equal(pickBanner(s, { syncLost: false, where: 'client', dismissed }), undefined);
const down = parse(PAGE, hb({ 30: [DOWN, DOWN] }));
assert.equal(
pickBanner(down, { syncLost: true, where: 'client', dismissed })?.kind,
'server-down',
);
});
+332
View File
@@ -0,0 +1,332 @@
/**
* [Gitea #124] Homeserver status from an Uptime Kuma status page.
*
* config.json maps a homeserver to a Kuma status page:
* "statusPages": { "matrix.lotusguild.org": { "url": "https://isitup.lotusguild.org",
* "slug": "matrix", "groups": { "homeserver": "Homeserver", "calls": "Voice calls",
* "login": "Login" } } }
* Users of any other homeserver never contact Kuma.
*
* Kuma 2.x public JSON:
* - GET /api/status-page/<slug>: publicGroupList[{name, monitorList[{id}]}],
* maintenanceList (only windows UNDER maintenance right now), incidents
* (announcements posted on the page).
* - GET /api/status-page/heartbeat/<slug>: heartbeatList{<monitorId>: [{status, time}]},
* status 0 down, 1 up, 2 pending, 3 maintenance.
*
* Everything here is pure and defensive: anything unexpected reads as
* "unknown", and unknown never shows a banner.
*/
export type StatusGroups = { homeserver?: string; calls?: string; login?: string };
export type StatusPageConfig = { url: string; slug: string; groups: StatusGroups };
export type ServiceState = 'up' | 'down' | 'unknown';
export type KumaMaintenance = { id: string; title: string; description: string; end?: number };
export type KumaIncident = {
id: string;
title: string;
content: string;
style: string;
updated: string;
};
export type ServerStatus = {
homeserver: ServiceState;
/**
* When Kuma last checked every homeserver monitor (the OLDEST of their
* latest beats, ms). Lets the client tell "Kuma has looked since my
* connection dropped and the server was fine" from a stale "up".
*/
homeserverCheckedAt?: number;
calls: ServiceState;
login: ServiceState;
maintenance: KumaMaintenance[];
incidents: KumaIncident[];
};
export const DEFAULT_GROUPS: Required<StatusGroups> = {
homeserver: 'Homeserver',
calls: 'Voice calls',
login: 'Login',
};
const obj = (v: unknown): Record<string, unknown> | undefined =>
v && typeof v === 'object' && !Array.isArray(v) ? (v as Record<string, unknown>) : undefined;
const str = (v: unknown): string => (typeof v === 'string' ? v : '');
/** The status page for `serverName`, if config.json names a valid one. */
export const resolveStatusPage = (
statusPages: unknown,
serverName: string | undefined,
): StatusPageConfig | undefined => {
if (!serverName) return undefined;
const entry = obj(obj(statusPages)?.[serverName]);
if (!entry) return undefined;
const slug = str(entry.slug);
if (!/^[a-z0-9-]{1,64}$/i.test(slug)) return undefined;
try {
const url = new URL(str(entry.url));
const local = url.hostname === 'localhost' || url.hostname === '127.0.0.1';
if (url.protocol !== 'https:' && !(url.protocol === 'http:' && local)) return undefined;
const g = obj(entry.groups) ?? {};
return {
url: url.origin,
slug,
groups: {
homeserver: str(g.homeserver) || DEFAULT_GROUPS.homeserver,
calls: str(g.calls) || DEFAULT_GROUPS.calls,
login: str(g.login) || DEFAULT_GROUPS.login,
},
};
} catch {
return undefined;
}
};
export const kumaUrls = (page: StatusPageConfig) => ({
page: `${page.url}/api/status-page/${page.slug}`,
heartbeat: `${page.url}/api/status-page/heartbeat/${page.slug}`,
});
const DOWN = 0;
const PENDING = 2;
/** Kuma beat time ("2026-09-29 14:16:11.804", UTC) → ms. */
export const kumaBeatTime = (time: unknown): number | undefined => {
const t = Date.parse(`${str(time).trim().replace(' ', 'T')}Z`);
return Number.isFinite(t) ? t : undefined;
};
const sortedBeats = (list: unknown): Record<string, unknown>[] =>
(Array.isArray(list) ? list : [])
.map((b) => obj(b))
.filter((b): b is Record<string, unknown> => !!b && typeof b.status === 'number')
.sort((a, b) => str(a.time).localeCompare(str(b.time)));
/**
* A group is down when ANY of its monitors is failing across two checks in a
* row: its latest beat is down and the one before is down or pending (Kuma
* marks a first failure "pending" when the monitor has a retry). One piece
* down, say the call token service, already breaks the feature; two checks so
* a single blip doesn't flash a banner. Up when every monitor we have beats
* for is fine; unknown when the group or its beats are missing.
*/
const groupState = (
groupName: string | undefined,
groups: Map<string, string[]>,
beats: Record<string, unknown>,
): ServiceState => {
if (!groupName) return 'unknown';
const ids = groups.get(groupName);
if (!ids || ids.length === 0) return 'unknown';
let known = 0;
let down = false;
ids.forEach((id) => {
const statuses = sortedBeats(beats[id]).map((b) => b.status as number);
if (statuses.length === 0) return;
known += 1;
const [prev, last] = statuses.slice(-2);
if (statuses.length >= 2 && last === DOWN && (prev === DOWN || prev === PENDING)) down = true;
});
if (down) return 'down';
return known > 0 ? 'up' : 'unknown';
};
export const parseKumaStatus = (
pageJson: unknown,
heartbeatJson: unknown,
groupNames: StatusGroups,
): ServerStatus => {
const page = obj(pageJson) ?? {};
const groups = new Map<string, string[]>();
(Array.isArray(page.publicGroupList) ? page.publicGroupList : []).forEach((g) => {
const group = obj(g);
if (!group) return;
const ids = (Array.isArray(group.monitorList) ? group.monitorList : [])
.map((m) => obj(m)?.id)
.filter((id): id is number | string => typeof id === 'number' || typeof id === 'string')
.map(String);
groups.set(str(group.name), ids);
});
const beats = obj(obj(heartbeatJson)?.heartbeatList) ?? {};
const maintenance: KumaMaintenance[] = (
Array.isArray(page.maintenanceList) ? page.maintenanceList : []
)
.map((m) => obj(m))
.filter((m): m is Record<string, unknown> => !!m && str(m.title) !== '')
.filter((m) => !m.status || m.status === 'under-maintenance')
.map((m) => {
const slot = obj((Array.isArray(m.timeslotList) ? m.timeslotList : [])[0]);
const end = Date.parse(str(slot?.endDate));
return {
id: String(m.id ?? str(m.title)),
title: str(m.title),
description: str(m.description),
...(Number.isFinite(end) ? { end } : {}),
};
});
const incidents: KumaIncident[] = (Array.isArray(page.incidents) ? page.incidents : [])
.map((i) => obj(i))
.filter((i): i is Record<string, unknown> => !!i && str(i.title) !== '' && i.active !== false)
.map((i) => ({
id: String(i.id ?? str(i.title)),
title: str(i.title),
content: str(i.content),
style: str(i.style) || 'info',
updated: str(i.lastUpdatedDate) || str(i.createdDate),
}));
const hsIds = (groupNames.homeserver && groups.get(groupNames.homeserver)) || [];
const hsLatest = hsIds.map((id) => kumaBeatTime(sortedBeats(beats[id]).slice(-1)[0]?.time));
const homeserverCheckedAt =
hsLatest.length > 0 && hsLatest.every((t): t is number => t !== undefined)
? Math.min(...hsLatest)
: undefined;
return {
homeserver: groupState(groupNames.homeserver, groups, beats),
...(homeserverCheckedAt !== undefined ? { homeserverCheckedAt } : {}),
calls: groupState(groupNames.calls, groups, beats),
login: groupState(groupNames.login, groups, beats),
maintenance,
incidents,
};
};
/**
* Kuma checked the homeserver AFTER this client lost its connection, and it
* was fine: the problem is more likely on the user's side. A stale "up" from
* before the drop proves nothing (Kuma takes a minute or two to notice an
* outage), so it doesn't count.
*/
export const serverConfirmedUpSince = (
status: ServerStatus | null | undefined,
lostAt: number | null | undefined,
): boolean =>
!!status &&
!!lostAt &&
status.homeserver === 'up' &&
status.homeserverCheckedAt !== undefined &&
status.homeserverCheckedAt > lostAt;
export type BannerTone = 'Critical' | 'Warning' | 'Primary';
export type BannerKind =
| 'server-down'
| 'server-problems'
| 'maintenance'
| 'calls-down'
| 'announcement'
| 'login-down';
export type StatusBanner = {
kind: BannerKind;
/** Stable id for dismissing (announcements come back when edited). */
key: string;
tone: BannerTone;
text: string;
detail?: string;
dismissable: boolean;
};
const formatTime = (ms: number): string =>
new Date(ms).toLocaleTimeString(undefined, { hour: 'numeric', minute: '2-digit' });
const incidentTone = (style: string): BannerTone => {
if (style === 'danger') return 'Critical';
if (style === 'warning') return 'Warning';
return 'Primary';
};
/** Markdown-ish incident text as plain text for the Details line. */
const plain = (s: string): string =>
s
.replace(/!\[[^\]]*\]\([^)]*\)/g, '')
.replace(/\[([^\]]+)\]\([^)]*\)/g, '$1')
.replace(/[*_`#>]/g, '')
.replace(/\s+\n/g, '\n')
.trim();
/**
* The one strip to show, highest priority first. `syncLost`: this client's
* connection is reconnecting/erroring. `where`: the logged-in app or the
* login screen.
*/
export const pickBanner = (
status: ServerStatus | null | undefined,
opts: { syncLost: boolean; where: 'client' | 'login'; dismissed?: ReadonlySet<string> },
): StatusBanner | undefined => {
if (!status) return undefined;
const dismissed = opts.dismissed ?? new Set<string>();
const candidates: StatusBanner[] = [];
if (status.homeserver === 'down') {
if (opts.syncLost || opts.where === 'login') {
candidates.push({
kind: 'server-down',
key: 'server-down',
tone: 'Critical',
text:
opts.where === 'login'
? "Lotus Chat's server is down. We're on it."
: "Lotus Chat's server is down. We're on it, reconnecting…",
dismissable: false,
});
} else {
candidates.push({
kind: 'server-problems',
key: 'server-problems',
tone: 'Warning',
text: "Lotus Chat's server is having problems. Messages may be slow to send or arrive.",
dismissable: false,
});
}
}
const maint = status.maintenance[0];
if (maint) {
const until = maint.end ? ` until ${formatTime(maint.end)}` : '';
candidates.push({
kind: 'maintenance',
key: `maintenance:${maint.id}`,
tone: 'Warning',
text: `Maintenance in progress${until}: ${maint.title}. Messages and calls may be interrupted.`,
detail: plain(maint.description) || undefined,
dismissable: false,
});
}
if (opts.where === 'login' && status.login === 'down') {
candidates.push({
kind: 'login-down',
key: 'login-down',
tone: 'Warning',
text: "Sign-in is having problems right now. If it doesn't work, try again in a few minutes.",
dismissable: false,
});
}
if (opts.where === 'client' && status.calls === 'down' && status.homeserver !== 'down') {
candidates.push({
kind: 'calls-down',
key: 'calls-down',
tone: 'Warning',
text: 'Voice calls are down right now. Messages still work.',
dismissable: true,
});
}
status.incidents.forEach((i) => {
candidates.push({
kind: 'announcement',
key: `announcement:${i.id}:${i.updated}`,
tone: incidentTone(i.style),
text: i.title,
detail: plain(i.content) || undefined,
dismissable: true,
});
});
return candidates.find((b) => !(b.dismissable && dismissed.has(b.key)));
};
+81
View File
@@ -0,0 +1,81 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import {
dismissNudge,
NUDGE_GRACE_MS,
NUDGE_SNOOZE_MS,
nudgeFor,
parseNudgeRecord,
SecurityState,
shouldShowNudge,
} from './securityNudge';
const healthy: SecurityState = {
crossSigning: true,
deviceVerified: true,
backupOnServer: true,
backupActive: true,
};
test('the #123 table: which nudge for which state', () => {
// E: healthy → nothing, ever.
assert.equal(nudgeFor(healthy), undefined);
// B: cross-signing, this device unverified, backup on server → verify first.
assert.equal(nudgeFor({ ...healthy, deviceVerified: false }), 'verify-device');
// C: cross-signing, unverified, no backup → still verify first.
assert.equal(
nudgeFor({ ...healthy, deviceVerified: false, backupOnServer: false }),
'verify-device',
);
// D: verified, no backup → #110's set-up nudge.
assert.equal(nudgeFor({ ...healthy, backupOnServer: false }), 'setup-backup');
// #110 state 2: backup exists, this device not using it.
assert.equal(nudgeFor({ ...healthy, backupActive: false }), 'connect-backup');
// A: never set up cross-signing, no backup → set up (the flow does both).
assert.equal(
nudgeFor({
crossSigning: false,
deviceVerified: false,
backupOnServer: false,
backupActive: false,
}),
'setup-backup',
);
});
test('nothing while crypto is still loading (F)', () => {
assert.equal(nudgeFor({ ...healthy, deviceVerified: undefined }), undefined);
assert.equal(nudgeFor({ ...healthy, backupOnServer: undefined }), undefined);
assert.equal(nudgeFor({ ...healthy, backupActive: undefined }), undefined);
// Unknown backup connection doesn't hide a known "no backup at all".
assert.equal(
nudgeFor({ ...healthy, backupOnServer: false, backupActive: undefined }),
'setup-backup',
);
});
test('timing: 24 h grace, 7-day snooze, stop after 3 dismissals', () => {
const t0 = 1_700_000_000_000;
let record = parseNudgeRecord(null, t0);
assert.equal(shouldShowNudge('verify-device', record, t0), false, 'first launch');
assert.equal(shouldShowNudge('verify-device', record, t0 + NUDGE_GRACE_MS - 1), false);
let now = t0 + NUDGE_GRACE_MS;
assert.equal(shouldShowNudge('verify-device', record, now), true, 'after 24 h');
for (let i = 1; i <= 3; i += 1) {
record = dismissNudge('verify-device', record, now);
assert.equal(shouldShowNudge('verify-device', record, now), false, `snoozed after #${i}`);
now += NUDGE_SNOOZE_MS;
assert.equal(shouldShowNudge('verify-device', record, now), i < 3, `after 7 days (#${i})`);
}
// Dismissing one nudge doesn't hide another.
assert.equal(shouldShowNudge('setup-backup', record, now), true);
});
test('stored record: round trip, and garbage starts a fresh grace period', () => {
const t0 = 1_700_000_000_000;
const r = dismissNudge('setup-backup', parseNudgeRecord(null, t0 - 5), t0);
assert.deepEqual(parseNudgeRecord(JSON.stringify(r), t0 + 1), r);
for (const bad of ['{', 'null', '"x"', '{"firstSeen":"yesterday"}', '{"firstSeen":1}']) {
assert.deepEqual(parseNudgeRecord(bad, t0), { firstSeen: t0, dismissals: {} }, bad);
}
});
+94
View File
@@ -0,0 +1,94 @@
/**
* [Gitea #110, #123] One "security" nudge for this device, in priority order:
*
* - verify-device: the account has cross-signing but THIS device isn't signed.
* It can't unlock backed-up history and shows as untrusted to others.
* Verifying with the recovery key also connects the backup, so it comes first.
* - connect-backup: a key backup exists on the server but this device isn't
* backing up to it (`getActiveSessionBackupVersion()` null).
* - setup-backup: no key backup at all (includes accounts that never set up
* cross-signing: the setup flow does both).
*
* Anything not yet known (crypto still loading) → no nudge. Timing: not in
* the first 24 h on a device (onboarding), "Not now" snoozes 7 days, three
* dismissals of a nudge stop it for good; a healthy device never sees one.
*/
export type NudgeKind = 'verify-device' | 'connect-backup' | 'setup-backup';
export type SecurityState = {
/** m.cross_signing.master account data present. */
crossSigning: boolean;
/** This device cross-signing-verified; undefined while crypto isn't ready. */
deviceVerified: boolean | undefined;
/** A key backup version on the server; undefined while loading. */
backupOnServer: boolean | undefined;
/** This device is backing up to it; undefined while loading. */
backupActive: boolean | undefined;
};
export const nudgeFor = (s: SecurityState): NudgeKind | undefined => {
if (s.crossSigning) {
if (s.deviceVerified === undefined) return undefined;
if (!s.deviceVerified) return 'verify-device';
}
if (s.backupOnServer === undefined) return undefined;
if (!s.backupOnServer) return 'setup-backup';
if (s.backupActive === undefined) return undefined;
return s.backupActive ? undefined : 'connect-backup';
};
export const NUDGE_GRACE_MS = 24 * 60 * 60 * 1000;
export const NUDGE_SNOOZE_MS = 7 * 24 * 60 * 60 * 1000;
export const NUDGE_MAX_DISMISSALS = 3;
export type NudgeRecord = {
/** When this device was first seen by the nudge (ms). */
firstSeen: number;
dismissals: Partial<Record<NudgeKind, { count: number; last: number }>>;
};
export const shouldShowNudge = (kind: NudgeKind, record: NudgeRecord, now: number): boolean => {
if (now - record.firstSeen < NUDGE_GRACE_MS) return false;
const d = record.dismissals[kind];
if (!d) return true;
return d.count < NUDGE_MAX_DISMISSALS && now - d.last >= NUDGE_SNOOZE_MS;
};
export const dismissNudge = (kind: NudgeKind, record: NudgeRecord, now: number): NudgeRecord => ({
...record,
dismissals: {
...record.dismissals,
[kind]: { count: (record.dismissals[kind]?.count ?? 0) + 1, last: now },
},
});
export const NUDGE_KEY_PREFIX = 'lotus-security-nudge-';
/** Parse a stored record; anything unexpected starts a fresh one (grace period from now). */
export const parseNudgeRecord = (raw: string | null, now: number): NudgeRecord => {
try {
const v = JSON.parse(raw ?? '');
if (v && typeof v.firstSeen === 'number' && v.dismissals && typeof v.dismissals === 'object') {
return { firstSeen: v.firstSeen, dismissals: v.dismissals };
}
} catch {
/* fresh record below */
}
return { firstSeen: now, dismissals: {} };
};
export const NUDGE_COPY: Record<NudgeKind, { text: string; action: string }> = {
'verify-device': {
text: 'Verify this device so you can read your older encrypted messages and others see it as trusted.',
action: 'Verify',
},
'connect-backup': {
text: "This device isn't using your key backup yet. Connect it so your encrypted messages stay readable if you lose it.",
action: 'Connect',
},
'setup-backup': {
text: "Your encryption keys aren't backed up. Set up key backup so you don't lose your encrypted messages if you log out or lose this device.",
action: 'Set up',
},
};
+33
View File
@@ -55,3 +55,36 @@ test('manual download link: Windows gets the installer, others the release page'
); );
assert.equal(manualDownloadUrl('Mozilla/5.0 (X11; Linux x86_64)'), MANUAL_DOWNLOAD_URL.other); assert.equal(manualDownloadUrl('Mozilla/5.0 (X11; Linux x86_64)'), MANUAL_DOWNLOAD_URL.other);
}); });
test('install kinds: anything unknown keeps the in-app updater', async () => {
const { toInstallKind } = await import('./updateErrors');
assert.equal(toInstallKind('pacman'), 'pacman');
assert.equal(toInstallKind('deb'), 'deb');
assert.equal(toInstallKind('manual'), 'manual');
assert.equal(toInstallKind('in-app'), 'in-app');
assert.equal(toInstallKind(undefined), 'in-app', 'older desktop build without the command');
assert.equal(toInstallKind('rpm'), 'in-app');
});
test('package installs get their package manager’s command, not an Install button', async () => {
const { packageUpdateHelp, isPackageManagedError } = await import('./updateErrors');
const pacman = packageUpdateHelp('pacman')!;
// Not `pacman -U <url>`: that also wants `<url>.sig`, which we don't publish.
assert.equal(
pacman.command,
'curl -LO https://code.lotusguild.org/LotusGuild/cinny-desktop/releases/download/latest/LotusChat-x86_64.pkg.tar.zst && sudo pacman -U ./LotusChat-x86_64.pkg.tar.zst',
);
assert.match(pacman.url, /LotusChat-x86_64\.pkg\.tar\.zst$/);
const deb = packageUpdateHelp('deb')!;
assert.match(deb.command!, /sudo apt install \.\/LotusChat-x86_64\.deb$/);
assert.equal(packageUpdateHelp('manual')?.command, undefined);
assert.equal(packageUpdateHelp('in-app'), undefined);
assert.equal(
isPackageManagedError('package-managed (pacman): update Lotus Chat with your package manager'),
true,
);
assert.equal(
isPackageManagedError('Permission denied (os error 13) at path "/usr/bin/tauri_current_app"'),
false,
);
});
+43
View File
@@ -47,3 +47,46 @@ export const describeUpdateError = (phase: UpdatePhase, message: string): string
} }
return 'The update downloaded but couldn’t be installed. Download the installer yourself and run it; your chats and settings are kept.'; return 'The update downloaded but couldn’t be installed. Download the installer yourself and run it; your chats and settings are kept.';
}; };
/**
* How this desktop install gets updated (cinny-desktop `update_install_kind`).
* Linux package installs can't be replaced in place by the in-app updater
* (it tried to write into /usr/bin: "Permission denied (os error 13)"), so
* they get their package manager's command instead of an Install button.
*/
export type InstallKind = 'in-app' | 'pacman' | 'deb' | 'manual';
const RELEASE_DOWNLOAD =
'https://code.lotusguild.org/LotusGuild/cinny-desktop/releases/download/latest';
export const toInstallKind = (value: unknown): InstallKind =>
value === 'pacman' || value === 'deb' || value === 'manual' ? value : 'in-app';
export type PackageUpdateHelp = { command?: string; url: string; download: string };
export const packageUpdateHelp = (kind: InstallKind): PackageUpdateHelp | undefined => {
if (kind === 'pacman') {
const url = `${RELEASE_DOWNLOAD}/LotusChat-x86_64.pkg.tar.zst`;
// Download first, then install the local file: `pacman -U <url>` also
// fetches `<url>.sig` and fails without it (we don't sign packages),
// while a local file falls under LocalFileSigLevel (signature optional).
return {
command: `curl -LO ${url} && sudo pacman -U ./LotusChat-x86_64.pkg.tar.zst`,
url,
download: 'Download package',
};
}
if (kind === 'deb') {
const url = `${RELEASE_DOWNLOAD}/LotusChat-x86_64.deb`;
return {
command: `curl -LO ${url} && sudo apt install ./LotusChat-x86_64.deb`,
url,
download: 'Download package',
};
}
if (kind === 'manual') return { url: MANUAL_DOWNLOAD_URL.other, download: 'Open downloads' };
return undefined;
};
/** The native side refuses an in-app install on a package install. */
export const isPackageManagedError = (message: string): boolean => /package-managed/.test(message);
+6
View File
@@ -17,10 +17,16 @@ import App from './app/pages/App';
import './app/i18n'; import './app/i18n';
import { pushSessionToSW } from './sw-session'; import { pushSessionToSW } from './sw-session';
import { getFallbackSession } from './app/state/sessions'; import { getFallbackSession } from './app/state/sessions';
import { startKeychainMirror } from './app/state/keychainMirror';
import { tauriInvoke } from './app/hooks/useTauri';
import { cleanupSearchCacheIfSignedOut } from './client/initMatrix'; import { cleanupSearchCacheIfSignedOut } from './client/initMatrix';
document.body.classList.add(configClass, varsClass); document.body.classList.add(configClass, varsClass);
// [Gitea #105] Desktop: keep a copy of the login tokens in the OS keychain
// (step 1: mirror only; the session is still read from localStorage).
startKeychainMirror(tauriInvoke());
// Register Service Worker // Register Service Worker
// Service workers only register on http(s) pages. The desktop app loads from // Service workers only register on http(s) pages. The desktop app loads from
// `tauri://localhost` in debug builds (and on any platform where the localhost // `tauri://localhost` in debug builds (and on any platform where the localhost