2 Commits
v1.18 ... v1.22

Author SHA1 Message Date
marcuspaico
18a66aba58 feat(desktop): Tauri mac shell around the web export
Some checks failed
Build & Release APK / check (push) Has been cancelled
Build & Release APK / build (push) Has been cancelled
Black screen root cause: Tauri injects nonces into style-src, which
makes WebKit drop 'unsafe-inline' and block react-native-web's inline
style attributes. style-src is now excluded from CSP modification.
Window opens on the home screen so the section menu is reachable.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wmf3K9nCoEsXvvwkmMnuiM
2026-09-05 01:36:42 +10:00
marcuspaico
4dd8d743a7 ci: sign with the EAS-managed keystore (new alias + separate key password)
Some checks failed
Build & Release APK / check (push) Has been cancelled
Build & Release APK / build (push) Has been cancelled
Requires updated repo secrets KEYSTORE_B64, KEYSTORE_PASSWORD, KEY_PASSWORD.
Until they are set, CI release builds fail instead of shipping an APK signed
with the old key that Obtainium would reject.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YE5FmDZmFnWxH6RXCZLcjj
2026-09-02 21:29:14 +10:00
20 changed files with 4732 additions and 1 deletions

View File

@@ -83,7 +83,10 @@ jobs:
env: env:
KEYSTORE_FILE: /tmp/release.jks KEYSTORE_FILE: /tmp/release.jks
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }} KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
KEY_ALIAS: gtd # EAS-managed keystore (since v1.16) — alias is EAS-generated, and the
# key password can differ from the store password.
KEY_ALIAS: a5ff13aa8571055bcaecbaca29a548ae
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
VERSION_CODE: ${{ github.run_number }} VERSION_CODE: ${{ github.run_number }}
VERSION_NAME: 1.${{ github.run_number }} VERSION_NAME: 1.${{ github.run_number }}
run: | run: |

2
.gitignore vendored
View File

@@ -5,3 +5,5 @@ server/.env
server/.env.token.local server/.env.token.local
*.log *.log
.DS_Store .DS_Store
credentials.json
*.jks

22
desktop/scripts/dev-web.sh Executable file
View File

@@ -0,0 +1,22 @@
#!/bin/sh
# Start the Expo web dev server for `tauri dev`.
#
# Runs from src-tauri/ as Tauri's beforeDevCommand, or from desktop/ by hand.
# Serves the GTD web UI on :8081 (devUrl in tauri.conf.json) with hot reload;
# the Tauri window loads it and talks to https://gtd.rehbock.xyz/api.
set -eu
if [ -x "$HOME/.hermes/node/bin/node" ]; then
export PATH="$HOME/.hermes/node/bin:$PATH"
fi
HERE="$(cd "$(dirname "$0")" && pwd)"
case "$HERE" in
*/desktop/src-tauri/scripts) REPO="$(cd "$HERE/../../.." && pwd)" ;;
*/desktop/scripts) REPO="$(cd "$HERE/../.." && pwd)" ;;
*) REPO="$(cd "$HERE/../.." && pwd)" ;;
esac
APP_DIR="$REPO/app"
cd "$APP_DIR"
exec npx expo start --web --port 8081

37
desktop/scripts/export-web.sh Executable file
View File

@@ -0,0 +1,37 @@
#!/bin/sh
# Re-export the Expo web frontend for the Tauri desktop shell.
#
# Runs from src-tauri/ as Tauri's beforeBuildCommand, or from desktop/ by hand.
# `frontendDist` points at ../app/dist in the repo root, so a plain release
# build of an unchanged tree simply re-bundles the last committed export —
# exactly like the web deploy copies app/dist to the VPS.
#
# Node 22 only (matches app/.nvmrc and CI): newer npm writes lockfiles that
# CI's npm 10 refuses, so force the hermes node 22 toolchain if present.
set -eu
HERE="$(cd "$(dirname "$0")" && pwd)"
case "$HERE" in
*/desktop/src-tauri/scripts)
# invoked as src-tauri/scripts/export-web.sh (Tauri hook cwd): repo is two up
ROOT="$(cd "$HERE/../../.." && pwd)" ;;
*/desktop/scripts)
# invoked as desktop/scripts/export-web.sh: repo is two up
ROOT="$(cd "$HERE/../.." && pwd)" ;;
*)
ROOT="$(cd "$HERE/../.." && pwd)" ;;
esac
if [ -x "$HOME/.hermes/node/bin/node" ]; then
export PATH="$HOME/.hermes/node/bin:$PATH"
fi
NODE_MAJOR="$(node -p 'process.versions.node.split(".")[0]')"
if [ "$NODE_MAJOR" != "22" ]; then
echo "export-web.sh: need node 22 (have $(node -v)); refusing to run" >&2
exit 1
fi
cd "$ROOT/app"
npx expo export --platform web
echo "export-web.sh: exported to $ROOT/app/dist"

2
desktop/src-tauri/.gitignore vendored Normal file
View File

@@ -0,0 +1,2 @@
/target/
/gen/schemas

4512
desktop/src-tauri/Cargo.lock generated Normal file

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,14 @@
[package]
name = "gtd"
version = "1.0.0"
description = "GTD desktop app — Tauri shell around the Expo web export"
edition = "2021"
authors = ["Marcus"]
[build-dependencies]
tauri-build = { version = "2", features = [] }
[dependencies]
tauri = { version = "2", features = [] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"

View File

@@ -0,0 +1,3 @@
fn main() {
tauri_build::build()
}

View File

@@ -0,0 +1,7 @@
{
"$schema": "../gen/schemas/desktop-schema.json",
"identifier": "main-capability",
"description": "Capabilities for the GTD main window. The Expo web frontend needs no Tauri plugin APIs — it only talks to the remote API over fetch — so this grants the read-only core defaults (window/event/app metadata) and nothing privileged.",
"windows": ["main"],
"permissions": ["core:default"]
}

Binary file not shown.

After

Width:  |  Height:  |  Size: 15 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 47 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

Binary file not shown.

After

Width:  |  Height:  |  Size: 59 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 182 KiB

View File

@@ -0,0 +1,22 @@
#!/bin/sh
# Start the Expo web dev server for `tauri dev`.
#
# Runs from src-tauri/ as Tauri's beforeDevCommand, or from desktop/ by hand.
# Serves the GTD web UI on :8081 (devUrl in tauri.conf.json) with hot reload;
# the Tauri window loads it and talks to https://gtd.rehbock.xyz/api.
set -eu
if [ -x "$HOME/.hermes/node/bin/node" ]; then
export PATH="$HOME/.hermes/node/bin:$PATH"
fi
HERE="$(cd "$(dirname "$0")" && pwd)"
case "$HERE" in
*/desktop/src-tauri/scripts) REPO="$(cd "$HERE/../../.." && pwd)" ;;
*/desktop/scripts) REPO="$(cd "$HERE/../.." && pwd)" ;;
*) REPO="$(cd "$HERE/../.." && pwd)" ;;
esac
APP_DIR="$REPO/app"
cd "$APP_DIR"
exec npx expo start --web --port 8081

View File

@@ -0,0 +1,37 @@
#!/bin/sh
# Re-export the Expo web frontend for the Tauri desktop shell.
#
# Runs from src-tauri/ as Tauri's beforeBuildCommand, or from desktop/ by hand.
# `frontendDist` points at ../app/dist in the repo root, so a plain release
# build of an unchanged tree simply re-bundles the last committed export —
# exactly like the web deploy copies app/dist to the VPS.
#
# Node 22 only (matches app/.nvmrc and CI): newer npm writes lockfiles that
# CI's npm 10 refuses, so force the hermes node 22 toolchain if present.
set -eu
HERE="$(cd "$(dirname "$0")" && pwd)"
case "$HERE" in
*/desktop/src-tauri/scripts)
# invoked as src-tauri/scripts/export-web.sh (Tauri hook cwd): repo is two up
ROOT="$(cd "$HERE/../../.." && pwd)" ;;
*/desktop/scripts)
# invoked as desktop/scripts/export-web.sh: repo is two up
ROOT="$(cd "$HERE/../.." && pwd)" ;;
*)
ROOT="$(cd "$HERE/../.." && pwd)" ;;
esac
if [ -x "$HOME/.hermes/node/bin/node" ]; then
export PATH="$HOME/.hermes/node/bin:$PATH"
fi
NODE_MAJOR="$(node -p 'process.versions.node.split(".")[0]')"
if [ "$NODE_MAJOR" != "22" ]; then
echo "export-web.sh: need node 22 (have $(node -v)); refusing to run" >&2
exit 1
fi
cd "$ROOT/app"
npx expo export --platform web
echo "export-web.sh: exported to $ROOT/app/dist"

View File

@@ -0,0 +1,22 @@
// GTD desktop shell — Tauri 2 backend.
//
// The UI is the Expo web export (rebuilt from `app/` by
// `scripts/export-web.sh` into `app/dist`, which this crate bundles via
// `frontendDist`). All app logic, offline queueing, and API sync live in
// that frontend; Rust only hosts the window. Native hooks (global
// quick-add, menu-bar toggle) can attach to the builder below later
// without touching the web code.
//
// CSP note (tauri.conf.json > app.security): `dangerousDisableAssetCspModification`
// lists "style-src" because Tauri otherwise injects nonces into that directive,
// which makes WebKit ignore 'unsafe-inline' and block every react-native-web
// inline `style=""` attribute plus Reanimated's runtime <style> tags. The
// result is a collapsed, unstyled page — a black screen in dark mode.
// script-src still receives Tauri's hashes/nonces.
#![cfg_attr(not(debug_assertions), windows_subsystem = "windows")]
fn main() {
tauri::Builder::default()
.run(tauri::generate_context!())
.expect("failed to run GTD");
}

View File

@@ -0,0 +1,48 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "GTD",
"version": "1.0.0",
"identifier": "xyz.rehbock.gtd",
"build": {
"devUrl": "http://localhost:8081",
"beforeDevCommand": "scripts/dev-web.sh",
"beforeBuildCommand": "scripts/export-web.sh",
"frontendDist": "../../app/dist"
},
"app": {
"windows": [
{
"label": "main",
"title": "GTD",
"url": "index.html",
"width": 1100,
"height": 750,
"minWidth": 800,
"minHeight": 600,
"center": true
}
],
"security": {
"dangerousDisableAssetCspModification": ["style-src"],
"csp": {
"default-src": "'self' tauri: asset: http://asset.localhost",
"script-src": "'self' 'unsafe-inline' 'unsafe-eval' tauri: asset: http://asset.localhost blob: data:",
"style-src": "'self' 'unsafe-inline' tauri: asset: http://asset.localhost blob: data:",
"img-src": "'self' tauri: asset: http://asset.localhost blob: data:",
"font-src": "'self' tauri: asset: http://asset.localhost blob: data:",
"connect-src": "'self' ipc: http://ipc.localhost tauri: asset: http://asset.localhost https://gtd.rehbock.xyz",
"media-src": "'self' tauri: asset: http://asset.localhost blob: data:"
}
}
},
"bundle": {
"active": true,
"targets": ["app", "dmg"],
"icon": ["icons/icon.icns", "icons/icon.ico", "icons/32x32.png", "icons/128x128.png", "icons/128x128@2x.png"],
"category": "Productivity",
"macOS": {
"minimumSystemVersion": "11.0",
"hardenedRuntime": true
}
}
}