Compare commits

...
7 Commits
Author SHA1 Message Date
Qiufeng 340d9b5245 feat: add lightweight application updates
TallyNote release / linux-x64 (push) Failing after 8m43s
2026-09-03 23:32:16 +08:00
Qiufeng 5d02fa5769 fix: simplify update metrics
TallyNote release / linux-x64 (push) Successful in 7m2s
2026-09-03 21:58:37 +08:00
Qiufeng 526b2df8ea feat: refine update center and release notes
TallyNote release / linux-x64 (push) Successful in 6m55s
2026-09-03 21:31:39 +08:00
Qiufeng 4f9629b089 fix: allow reverse proxy login
TallyNote release / linux-x64 (push) Successful in 6m56s
2026-09-03 15:27:10 +08:00
Qiufeng 36c2ed1361 fix: show completed download progress
TallyNote release / linux-x64 (push) Successful in 7m0s
2026-09-03 15:02:44 +08:00
Qiufeng 755b82d2e5 chore: align package version with v1.1.21
TallyNote release / linux-x64 (push) Successful in 7m27s
2026-09-03 14:55:38 +08:00
Qiufeng 0bdc812935 fix: support proxied origins and update progress
TallyNote release / linux-x64 (push) Failing after 11s
2026-09-03 14:54:30 +08:00
20 changed files with 1961 additions and 97 deletions
+1 -1
View File
@@ -140,7 +140,7 @@ curl --proto '=https' --tlsv1.2 -fsSL https://git.awaioi.com/awaioi/TallyNote/ra
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
公网反代必须使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。
公网反代推荐使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。反代只需把域名转发到 TallyNote 端口并保留 `Host`、`X-Forwarded-Proto`;应用不会因为代理缺少或改写浏览器 `Origin` 而拦截登录。已认证写请求仍使用会话 Cookie 与 CSRF 令牌保护。
### 构建发布包
+2 -2
View File
@@ -28,7 +28,7 @@ GITEA_TOKEN=... \
./scripts/publish-gitea-release.sh v1.1.2 ./release
```
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。构建脚本会同时生成完整安装包和轻量更新包:`tallynote-1.1.2-linux-x64-glibc.tar.gz` 用于首次安装,`tallynote-1.1.2-linux-x64-glibc.update-<锁文件 SHA256>.tar.gz` 仅用于复用现有运行时的后台更新。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
## curl 安装
@@ -104,7 +104,7 @@ sudo /usr/local/sbin/tallynote-uninstall
将环境文件中的 `TALLYNOTE_UPDATE_STRATEGY=systemd`、`TALLYNOTE_UPDATE_METADATA_URL` 和 `TALLYNOTE_UPDATE_ALLOWED_HOSTS` 配好后,后台“系统更新”会读取 Gitea 的 `/api/v1/repos/<owner>/<repo>/releases/latest`。检查结果只显示当前平台匹配且通过 SHA-256 校验的资产;如果配置了 `TALLYNOTE_UPDATE_PUBLIC_KEY_FILE` 并启用签名要求,再额外验证 Ed25519 签名。
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;当前安装如果存在匹配的锁文件指纹,更新器会自动选择轻量 `update-<锁文件 SHA256>` 资产,仅下载 `dist`、迁移和版本元数据,并复用当前版本的 Node 与生产依赖;如果运行时指纹不匹配或轻量包不可用,则自动选择完整安装包。root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
Web 进程把受保护的任务文件交给 root 的 `tallynote-update.path`/`tallynote-update.service`,root runner 会重新读取配置源并验证 metadata、清单和暂存目录,不信任队列文件中的 URL 或摘要。切换失败或健康检查失败会恢复旧版本;手动回滚:
+1 -1
View File
@@ -1077,7 +1077,7 @@ validate_existing_env() {
mode_bits=$(stat_mode_bits "$file")
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
local key key_count
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOWED_ORIGINS TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
key_count=$(env_key_count "$file" "$key")
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
done
+3
View File
@@ -0,0 +1,3 @@
ALTER TABLE update_jobs ADD COLUMN downloaded_bytes INTEGER;
ALTER TABLE update_jobs ADD COLUMN download_started_at INTEGER;
ALTER TABLE update_jobs ADD COLUMN download_speed_bps INTEGER;
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "tallynote",
"version": "1.1.20",
"version": "1.1.25",
"private": true,
"type": "module",
"packageManager": "pnpm@9.0.6",
+25 -1
View File
@@ -27,7 +27,11 @@ pnpm build
stage=$(mktemp -d)
trap 'rm -rf "$stage"' EXIT
mkdir -p "$stage/dist" "$stage/migrations" "$stage/bin" "$stage/scripts" "$stage/systemd" "$stage/runtime/bin"
cp -a dist/. "$stage/dist/"
# Copy only the production build outputs. In particular, do not carry a
# stale dist/web-next directory from a previous local preview build.
cp -a dist/server "$stage/dist/"
cp -a dist/shared "$stage/dist/"
cp -a dist/web "$stage/dist/"
cp -a migrations/. "$stage/migrations/"
cp package.json pnpm-lock.yaml "$stage/"
cp -a bin/. "$stage/bin/"
@@ -46,6 +50,26 @@ find "$stage" -type l -delete
mkdir -p "$OUT_DIR"
archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.tar.gz"
tar -C "$stage" -czf "$archive" --owner=0 --group=0 --numeric-owner .
# The application-only asset is used by the online updater. It deliberately
# excludes the stable runtime (Node and production dependencies), systemd
# helpers and installer files; the updater overlays it on the currently
# installed, already-validated runtime before atomically switching releases.
app_stage=$(mktemp -d)
trap 'rm -rf "$stage" "$app_stage"' EXIT
mkdir -p "$app_stage/dist" "$app_stage/migrations" "$app_stage/bin" "$app_stage/scripts" "$app_stage/systemd"
cp -a "$stage/dist/server" "$app_stage/dist/"
cp -a "$stage/dist/shared" "$app_stage/dist/"
cp -a "$stage/dist/web" "$app_stage/dist/"
cp -a "$stage/migrations/." "$app_stage/migrations/"
cp -a "$stage/bin/." "$app_stage/bin/"
cp -a "$stage/scripts/." "$app_stage/scripts/"
cp -a "$stage/systemd/." "$app_stage/systemd/"
cp "$stage/package.json" "$app_stage/package.json"
cp "$stage/uninstall.sh" "$app_stage/uninstall.sh"
runtime_hash=$(sha256sum pnpm-lock.yaml | awk '{print $1}')
app_archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.update-${runtime_hash}.tar.gz"
tar -C "$app_stage" -czf "$app_archive" --owner=0 --group=0 --numeric-owner .
# Keep the sidecar useful when a caller builds more than one architecture into
# the same directory. The publishing script recomputes this list immediately
# before signing, so stale or hand-edited entries can never reach a Release.
+10 -2
View File
@@ -128,7 +128,8 @@ fi
[[ "$CURL_BIN" != *[[:space:]]* && "$CURL_BIN" != *[[:cntrl:]]* ]] || die 'curl executable path is invalid'
command -v "$CURL_BIN" >/dev/null 2>&1 || die 'curl is required'
assets=()
full_assets=()
update_assets=()
for file in "$ASSET_DIR"/*.tar.gz; do
[[ -f "$file" && ! -L "$file" ]] || continue
name=$(basename -- "$file")
@@ -136,9 +137,16 @@ for file in "$ASSET_DIR"/*.tar.gz; do
asset_version=${name#tallynote-}
asset_version=${asset_version%%-linux-*}
[[ "$asset_version" == "${TAG#v}" ]] || die "release asset version does not match tag: $name"
assets+=("$file")
if [[ "$name" =~ \.update-[a-f0-9]{64}\.tar\.gz$ ]]; then
update_assets+=("$file")
else
full_assets+=("$file")
fi
done
assets=("${full_assets[@]}")
if ((${#update_assets[@]})); then assets+=("${update_assets[@]}"); fi
(( ${#assets[@]} > 0 )) || die 'no .tar.gz release asset found'
(( ${#full_assets[@]} > 0 )) || die 'no full release asset found'
SUMS_FILE="$ASSET_DIR/SHA256SUMS"
SIG_FILE="$ASSET_DIR/SHA256SUMS.sig"
+4 -13
View File
@@ -648,19 +648,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
return payload;
});
app.addHook("onRequest", async (request) => {
if (!unsafeMethods.has(request.method) || !request.url.startsWith("/api/")) return;
const origin = request.headers.origin;
const allowed = new Set([config.publicOrigin]);
if (!config.isProduction) {
allowed.add("http://127.0.0.1:5173");
allowed.add("http://localhost:5173");
}
if (typeof origin !== "string" || !allowed.has(origin)) {
throw new AppError(403, "ORIGIN_FORBIDDEN", "请求来源不受信任");
}
});
app.setErrorHandler((error, request, reply) => {
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
if (error instanceof ZodError) {
@@ -947,6 +934,8 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
SELECT id, operation, status, version, platform, asset_name AS assetName,
size_bytes AS sizeBytes, error_message AS errorMessage,
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
download_speed_bps AS downloadSpeedBps,
requested_at AS applyQueuedAt
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
@@ -1193,6 +1182,8 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
SELECT id, operation, status, version, platform, asset_name AS assetName,
size_bytes AS sizeBytes, error_message AS errorMessage,
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
download_speed_bps AS downloadSpeedBps,
requested_at AS applyQueuedAt
FROM update_jobs WHERE id=? AND admin_id=?
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
+40 -3
View File
@@ -1,5 +1,5 @@
import { randomUUID } from "node:crypto";
import { lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
import { cp, lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
import path from "node:path";
import { pathToFileURL } from "node:url";
import type Database from "better-sqlite3";
@@ -10,6 +10,7 @@ import { writeAudit } from "../audit.js";
import {
atomicSwitchDirectory,
atomicSwitchRelease,
applicationUpdateRuntimeHash,
compareSemver,
createSafeArchive,
detectPlatform,
@@ -19,6 +20,7 @@ import {
isNewerVersion,
normalizeReleasePermissions,
parseSemver,
runtimeHashFromLockfile,
selectReleaseAsset,
sanitizeAssetName,
validateHttpsUrl,
@@ -212,9 +214,16 @@ async function resolveRelease(options: UpdateRunOptions, platform: ReturnType<ty
if (options.metadataUrl) {
const metadataUrl = validateHttpsUrl(options.metadataUrl, options);
const release = await fetchReleaseMetadata(metadataUrl, options);
let runtimeHash: string | undefined;
try {
runtimeHash = runtimeHashFromLockfile(await readFile(path.join(options.currentDir, "pnpm-lock.yaml")));
} catch {
// Fall back to the full archive when the current installation predates
// runtime fingerprints or is missing deployment provenance.
}
let asset = options.assetUrl && !options.requireSignature
? { name: sanitizeAssetName(options.assetName ?? path.basename(new URL(options.assetUrl).pathname)), url: validateHttpsUrl(options.assetUrl, { ...options, baseUrl: metadataUrl }).toString(), ...(options.expectedSha256 ? { sha256: options.expectedSha256 } : {}) }
: selectReleaseAsset(release, platform);
: selectReleaseAsset(release, platform, runtimeHash);
if (!asset) throw new Error("没有匹配当前平台的更新文件");
const integrity = await attachSidecarHash(release, asset, {
allowedHosts: options.allowedHosts ?? [],
@@ -291,12 +300,40 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
try {
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, options);
const progressStartedAt = Date.now();
let lastProgressWrite = 0;
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, {
...options,
onProgress: (downloadedBytes, totalBytes) => {
const now = Date.now();
if (!options.sqlite || now - lastProgressWrite < 250) return;
lastProgressWrite = now;
const elapsed = Math.max(1, now - progressStartedAt);
const speedBps = Math.round(downloadedBytes * 1000 / elapsed);
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=COALESCE(?, size_bytes), download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloadedBytes, totalBytes, progressStartedAt, speedBps, now, jobId);
},
});
if (options.sqlite) {
const finishedAt = Date.now();
const elapsed = Math.max(1, finishedAt - progressStartedAt);
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=?, download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloaded.size, downloaded.size, progressStartedAt, Math.round(downloaded.size * 1000 / elapsed), finishedAt, jobId);
}
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
const stagedDir = path.join(workspace, "payload");
await extractSafeArchive(archivePath, stagedDir, options.maxBytes === undefined ? {} : { maxBytes: options.maxBytes });
if (applicationUpdateRuntimeHash(resolved.asset.name)) {
const currentRelease = await realpath(options.currentDir).catch(() => { throw new Error("当前安装目录无效"); });
const currentInfo = await lstat(currentRelease).catch(() => null);
if (!currentInfo?.isDirectory() || currentInfo.isSymbolicLink()) throw new Error("当前安装目录无效");
for (const entry of ["node_modules", "runtime", "pnpm-lock.yaml"] as const) {
const source = path.join(currentRelease, entry);
const sourceInfo = await lstat(source).catch(() => null);
if (!sourceInfo || sourceInfo.isSymbolicLink()) throw new Error("当前运行时不完整,无法应用轻量更新");
await cp(source, path.join(stagedDir, entry), { recursive: sourceInfo.isDirectory(), errorOnExist: true, force: false });
}
}
await normalizeReleasePermissions(stagedDir);
const payloadInfo = await lstat(path.join(stagedDir, "dist")).catch(() => null);
if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) throw new Error("发布包缺少 dist 目录");
+3
View File
@@ -148,6 +148,9 @@ export const updateJobs = sqliteTable("update_jobs", {
downloadPath: text("download_path"),
backupPath: text("backup_path"),
sizeBytes: integer("size_bytes"),
downloadedBytes: integer("downloaded_bytes"),
downloadStartedAt: integer("download_started_at"),
downloadSpeedBps: integer("download_speed_bps"),
errorMessage: text("error_message"),
createdAt: integer("created_at").notNull(),
requestedAt: integer("requested_at"),
+12 -1
View File
@@ -13,6 +13,7 @@ import {
fetchReleaseText,
isNewerVersion,
parseSemver,
runtimeHashFromLockfile,
sanitizeAssetName,
selectReleaseAsset,
validateHttpsUrl,
@@ -204,7 +205,14 @@ export async function checkForUpdate(database: Database.Database, config: AppCon
} catch {
throw new AppError(502, "UPDATE_CHECK_FAILED", "暂时无法获取最新版本,请稍后重试");
}
let asset = selectReleaseAsset(metadata, platform);
let runtimeHash: string | undefined;
try {
runtimeHash = runtimeHashFromLockfile(readFileSync(path.join(config.projectRoot, "pnpm-lock.yaml")));
} catch {
// Legacy or source installations may not contain the lockfile. They stay
// on the full release asset instead of risking an incompatible runtime.
}
let asset = selectReleaseAsset(metadata, platform, runtimeHash);
let signatureVerified = false;
if (asset) {
const integrity = await attachSidecarHash(metadata, asset, {
@@ -351,6 +359,9 @@ export function publicUpdateJob(row: Record<string, unknown> | undefined): Recor
platform: row.platform,
assetName: row.assetName ?? null,
sizeBytes: row.sizeBytes ?? null,
downloadedBytes: row.downloadedBytes ?? null,
downloadStartedAt: row.downloadStartedAt ?? null,
downloadSpeedBps: row.downloadSpeedBps ?? null,
// Do not expose filesystem paths, command output, or upstream response
// text through the authenticated status endpoint. Detailed diagnostics
// remain in the server journal for operators.
+23 -3
View File
@@ -43,6 +43,16 @@ export type ReleaseMetadata = {
assets: ReleaseAsset[];
};
const APPLICATION_UPDATE_ASSET = /\.update-([a-f0-9]{64})\.tar\.gz$/i;
export function applicationUpdateRuntimeHash(assetName: string): string | undefined {
return APPLICATION_UPDATE_ASSET.exec(assetName)?.[1]?.toLowerCase();
}
export function runtimeHashFromLockfile(lockfile: string | Buffer): string {
return createHash("sha256").update(lockfile).digest("hex");
}
export type UrlPolicy = {
/** Host names or HTTPS URLs which are allowed for requests. */
allowedHosts?: readonly string[] | undefined;
@@ -379,7 +389,7 @@ export async function fetchReleaseBytes(
}
}
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform()): ReleaseAsset | undefined {
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform(), runtimeHash?: string): ReleaseAsset | undefined {
const platformCandidates = release.assets.filter((asset) => {
const name = asset.name.toLowerCase();
return platform.aliases.filter((alias) => alias.toLowerCase().includes(platform.arch.toLowerCase())).some((alias) => name.includes(alias.toLowerCase()));
@@ -398,7 +408,15 @@ export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPl
const target = platform.target.toLowerCase();
return Number(b.name.toLowerCase().includes(target)) - Number(a.name.toLowerCase().includes(target));
});
return candidates[0];
const normalizedRuntimeHash = runtimeHash?.trim().toLowerCase();
if (normalizedRuntimeHash && /^[a-f0-9]{64}$/.test(normalizedRuntimeHash)) {
const applicationUpdate = candidates.find((asset) => applicationUpdateRuntimeHash(asset.name) === normalizedRuntimeHash);
if (applicationUpdate) return applicationUpdate;
}
// Older clients choose the first matching asset. Releases therefore keep
// the traditional full archive first, while current clients explicitly
// opt into a compatible application-only asset.
return candidates.find((asset) => !applicationUpdateRuntimeHash(asset.name));
}
export function sanitizeAssetName(value: string): string {
@@ -423,7 +441,7 @@ export async function verifySha256(filePath: string, expected: string): Promise<
export async function downloadReleaseAsset(
url: string | URL,
destination: string,
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined } = {},
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined; onProgress?: ((downloadedBytes: number, totalBytes: number | null) => void) | undefined } = {},
): Promise<{ size: number; sha256: string }> {
const fetchImpl = options.fetchImpl ?? fetch;
let current = validateHttpsUrl(url, options);
@@ -446,6 +464,7 @@ export async function downloadReleaseAsset(
}
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
const declared = Number(response.headers.get("content-length") ?? 0);
const totalBytes = Number.isSafeInteger(declared) && declared > 0 ? declared : null;
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
@@ -454,6 +473,7 @@ export async function downloadReleaseAsset(
const hash = createHash("sha256");
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
size += chunk.length;
options.onProgress?.(size, totalBytes);
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
hash.update(chunk);
callback(null, chunk);
+3 -3
View File
@@ -129,10 +129,10 @@ describe("TallyNote API", () => {
}
});
it("拒绝没有 Origin 的写请求", async () => {
it("反向代理缺少 Origin 时仍允许登录请求进入认证流程", async () => {
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
expect(response.statusCode).toBe(403);
expect(response.json().error.code).toBe("ORIGIN_FORBIDDEN");
expect(response.statusCode).toBe(401);
expect(response.json().error.code).toBe("INVALID_CREDENTIALS");
});
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
+2 -1
View File
@@ -42,9 +42,10 @@ describe("数据库迁移", () => {
{ name: "0002_update_jobs.sql" },
{ name: "0003_update_job_ownership.sql" },
{ name: "0004_update_download_apply.sql" },
{ name: "0005_update_progress.sql" },
]);
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation"]));
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation", "downloaded_bytes", "download_started_at", "download_speed_bps"]));
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
migrated.sqlite.close();
migrated = openDatabase(config);
+1
View File
@@ -48,6 +48,7 @@ describe("部署安全配置", () => {
expect(loadConfig().trustProxy).toBe(1);
});
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
+13
View File
@@ -6,6 +6,7 @@ import path from "node:path";
import { createHash, generateKeyPairSync, randomUUID, sign } from "node:crypto";
import {
atomicSwitchRelease,
applicationUpdateRuntimeHash,
createSafeArchive,
detectPlatform,
downloadReleaseAsset,
@@ -16,6 +17,7 @@ import {
normalizeReleasePermissions,
sanitizeAssetName,
selectReleaseAsset,
runtimeHashFromLockfile,
validateHttpsUrl,
} from "../server/update.js";
import { finalizeUpdateJob, runUpdate } from "../server/cli/update.js";
@@ -50,6 +52,17 @@ describe("更新安全工具", () => {
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
});
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
const full = { name: "tallynote-1.2.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
const app = { name: `tallynote-1.2.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
const release = { version: "1.2.0", assets: [full, app] };
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
expect(applicationUpdateRuntimeHash(full.name)).toBeUndefined();
});
it("验证 SHA256SUMS 的 Ed25519 detached signature", () => {
const { publicKey, privateKey } = generateKeyPairSync("ed25519");
const payload = "a".repeat(64) + " tallynote.tar.gz\n";
@@ -66,7 +66,7 @@ export default function ExpenseDetail({ expense, timezone = "Asia/Shanghai", onC
</Drawer>
<Dialog visible={action === "status"} header={detail.status === "reimbursed" ? "改回未报销?" : "标记为已报销?"} confirmBtn={{ content: "确认变更", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void updateStatus()} onCancel={() => { if (!busy) setAction(null); }}>{detail.status === "reimbursed" ? "这笔账目会重新出现在未报销列表。" : "确认这笔账目已完成报销,并从未报销列表移出?"}</Dialog>
<Dialog visible={action === "trash"} header="移入回收站?" confirmBtn={{ content: "移入回收站", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void trash()} onCancel={() => { if (!busy) setAction(null); }}>账目会从普通列表和导出结果中隐藏,附件会保留,可在回收站恢复。</Dialog>
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert"><AlertCircle size={16} />{removeError}</div>}</>}</Dialog>
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert">{removeError}</div>}</>}</Dialog>
<Dialog visible={Boolean(preview)} header={preview?.originalName} onClose={() => setPreview(null)} cancelBtn="关闭" footer={null}>{preview && <div className="tn-preview">{preview.mimeType.startsWith("image/") ? <img src={`/api/attachments/${preview.id}/content`} alt={preview.originalName} /> : <iframe src={`/api/attachments/${preview.id}/content`} title={preview.originalName} />}</div>}</Dialog>
</>;
}
File diff suppressed because it is too large Load Diff
+283
View File
@@ -0,0 +1,283 @@
export type MockScenario =
| "latest" // 已是最新
| "available" // 发现新版本(待下载)
| "downloading_30" // 下载中 30%
| "downloading_85" // 下载中 85% + 高速
| "staged" // 下载完成已校验,待立即更新
| "backing_up" // 正在备份数据
| "applying" // 正在原子切换并重启中(倒计时)
| "completed" // 更新完成
| "failed_verify" // 完整性校验失败
| "disabled"; // 手动模式未配置源
export interface MockUpdateState {
info: any;
title: string;
description: string;
}
export const MOCK_SCENARIOS: Record<MockScenario, MockUpdateState> = {
latest: {
title: "版本健康(已是最新)",
description: "展示当前运行版本已是最新,各项指标正常,无待处理任务",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 600_000,
latest: {
version: "1.1.22",
tagName: "v1.1.22",
releaseName: "v1.1.22 稳定版",
publishedAt: new Date(Date.now() - 3600_000 * 24).toISOString(),
compatible: true,
integrityReady: true,
signatureReady: true,
isNewer: false,
assetName: "tallynote-1.1.22-linux-x64-glibc.tar.gz",
assetSize: 120540160,
notes: "### TallyNote 1.1.22\n\n- 优化反向代理下登录兼容性\n- 增强安全审计与防重放机制\n- 前端组件性能深度优化",
},
job: null,
},
},
available: {
title: "发现新版本(待下载)",
description: "检查到官方发布了更高版本,显示更新日志与文件校验信息,可点击下载",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 60_000,
latest: {
version: "1.1.23",
tagName: "v1.1.23",
releaseName: "v1.1.23 重大更新",
publishedAt: new Date(Date.now() - 1800_000).toISOString(),
compatible: true,
integrityReady: true,
signatureReady: true,
isNewer: true,
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
assetSize: 121000000,
notes: "### TallyNote 1.1.23\n\n- 【新功能】系统更新中心全面重构,支持动态速率流光进度条与平滑重启倒计时\n- 【交互】优化抽屉展开动效与手机端自适应导航\n- 【安全】发布包支持双重 Ed25519 签名与 SHA-256 清单交叉校验",
},
job: null,
},
},
downloading_30: {
title: "下载更新中(进度 38%)",
description: "展示真实下载速率、已下载字节数与动态流光进度条",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: {
version: "1.1.23",
tagName: "v1.1.23",
compatible: true,
integrityReady: true,
signatureReady: true,
isNewer: true,
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
assetSize: 121000000,
},
job: {
id: "mock-job-001",
operation: "download",
status: "downloading",
version: "1.1.23",
platform: "x64/glibc",
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
sizeBytes: 121000000,
downloadedBytes: 46200000,
downloadStartedAt: Date.now() - 10000,
downloadSpeedBps: 8800000, // 8.4 MB/s
createdAt: Date.now() - 10000,
updatedAt: Date.now(),
},
},
},
downloading_85: {
title: "下载冲刺中(进度 88%)",
description: "高速冲刺状态,即将触发 SHA-256 校验",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: {
version: "1.1.23",
tagName: "v1.1.23",
compatible: true,
integrityReady: true,
signatureReady: true,
isNewer: true,
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
assetSize: 121000000,
},
job: {
id: "mock-job-002",
operation: "download",
status: "downloading",
version: "1.1.23",
platform: "x64/glibc",
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
sizeBytes: 121000000,
downloadedBytes: 106480000,
downloadStartedAt: Date.now() - 15000,
downloadSpeedBps: 12500000, // 11.9 MB/s
createdAt: Date.now() - 15000,
updatedAt: Date.now(),
},
},
},
staged: {
title: "下载完成(待立即应用)",
description: "更新包与签名均已校验就绪,随时可以安全点击【立即更新】",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: {
version: "1.1.23",
tagName: "v1.1.23",
compatible: true,
integrityReady: true,
signatureReady: true,
isNewer: true,
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
assetSize: 121000000,
notes: "### TallyNote 1.1.23\n\n- 更新包已完整解压检验通过,具备升级条件。",
},
job: {
id: "mock-job-003",
operation: "download",
status: "staged",
version: "1.1.23",
platform: "x64/glibc",
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
sizeBytes: 121000000,
downloadedBytes: 121000000,
createdAt: Date.now() - 60000,
updatedAt: Date.now() - 5000,
},
},
},
backing_up: {
title: "数据备份中(更新保护)",
description: "正在为 /var/lib/tallynote 生成自动还原快照",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
job: {
id: "mock-job-004",
operation: "apply",
status: "backing_up",
version: "1.1.23",
platform: "x64/glibc",
createdAt: Date.now() - 20000,
updatedAt: Date.now() - 2000,
},
},
},
applying: {
title: "服务平滑重启中(倒计时中)",
description: "已原子切换版本,systemd 正在热重启,前端实时探活",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
job: {
id: "mock-job-005",
operation: "apply",
status: "applying",
version: "1.1.23",
platform: "x64/glibc",
applyQueuedAt: Date.now() - 12000,
restartWindowSeconds: 30,
restartDeadline: Date.now() + 18000,
createdAt: Date.now() - 25000,
updatedAt: Date.now() - 2000,
},
},
},
completed: {
title: "更新成功完成",
description: "新版本健康检查通过,已平滑无感升级至最新",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.23",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 30_000,
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: false },
job: {
id: "mock-job-006",
operation: "apply",
status: "completed",
version: "1.1.23",
platform: "x64/glibc",
completedAt: Date.now() - 10000,
createdAt: Date.now() - 45000,
updatedAt: Date.now() - 10000,
},
},
},
failed_verify: {
title: "更新失败状态(安全拦截)",
description: "模拟签名不匹配或发布包篡改时的安全拦截展示与错误提示",
info: {
configured: true,
strategy: "systemd",
currentVersion: "1.1.22",
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
checkedAt: Date.now() - 120_000,
latest: {
version: "1.1.23",
tagName: "v1.1.23",
compatible: true,
integrityReady: false,
signatureReady: false,
isNewer: true,
},
job: {
id: "mock-job-007",
operation: "download",
status: "failed",
version: "1.1.23",
platform: "x64/glibc",
errorMessage: "发布包 SHA-256 校验与清单不一致,系统已自动阻断并保护原有数据。",
createdAt: Date.now() - 30000,
updatedAt: Date.now() - 5000,
},
},
},
disabled: {
title: "手动源码模式",
description: "未接入 systemd 时的只读说明与命令引导展示",
info: {
configured: false,
strategy: "disabled",
currentVersion: "1.1.22",
platform: { target: "macOS/darwin", os: "darwin", arch: "arm64" },
checkedAt: Date.now() - 3600_000,
latest: null,
job: null,
},
},
};
+552
View File
@@ -410,6 +410,34 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
@keyframes tn-app-enter { from { opacity: 0; } to { opacity: 1; } }
@keyframes tn-auth-page-in { from { opacity: 0; transform: translateY(4px); } to { opacity: 1; transform: translateY(0); } }
.t-dialog { border: 1px solid var(--tn-border); border-radius: 4px; box-shadow: 0 18px 42px rgba(8, 47, 118, .18); }
/* TDesign Dialog global no-icon & pure baseline typography normalization */
.t-dialog__header .t-icon:not(.t-icon-close),
.t-dialog__body .t-icon,
.t-dialog .t-icon.t-is-info,
.t-dialog .t-icon.t-is-success,
.t-dialog .t-icon.t-is-warning,
.t-dialog .t-icon.t-is-error {
display: none !important;
}
.t-dialog__header {
font-size: 16px;
font-weight: 600;
color: var(--tn-navy-900);
line-height: 1.4;
margin-bottom: 8px;
gap: 0 !important;
}
.t-dialog__header-content {
display: block !important;
width: 100%;
}
.t-dialog__body {
font-size: 13.5px;
line-height: 1.65;
color: var(--tn-text);
padding: 8px 0 20px 0;
}
.t-dialog__mask { background: var(--td-mask-active) !important; }
.t-dialog__footer .t-button { min-width: 76px; }
@media (max-width: 900px) {
@@ -537,3 +565,527 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
@media (prefers-reduced-motion: reduce) {
*, *::before, *::after { animation-duration: .01ms !important; animation-iteration-count: 1 !important; transition-duration: .01ms !important; scroll-behavior: auto !important; }
}
/* ==========================================================================
TallyNote Update Center (Redesigned UI & Interactive Styles)
========================================================================== */
/* Mock Console Controller */
.tn-mock-console {
margin-bottom: 16px;
padding: 14px 18px;
background: #f8fbff;
border: 1px dashed var(--td-brand-color-3);
border-radius: 4px;
}
.tn-mock-console-header {
display: flex;
align-items: center;
justify-content: space-between;
flex-wrap: wrap;
gap: 8px;
margin-bottom: 12px;
}
.tn-mock-console-title {
display: flex;
align-items: center;
gap: 8px;
font-size: 13px;
color: var(--tn-navy-900);
}
.tn-mock-console-tip {
font-size: 12px;
color: var(--tn-text-secondary);
}
.tn-mock-scenario-chips {
display: flex;
flex-wrap: wrap;
gap: 8px;
}
.tn-scenario-chip {
padding: 5px 11px;
font-size: 12px;
border: 1px solid var(--tn-border);
border-radius: 3px;
background: #ffffff;
color: var(--tn-text-secondary);
cursor: pointer;
transition: all 0.16s ease;
}
.tn-scenario-chip:hover {
border-color: var(--td-brand-color-4);
color: var(--td-brand-color);
background: var(--td-brand-color-1);
}
.tn-scenario-chip.active {
background: var(--td-brand-color);
border-color: var(--td-brand-color);
color: #ffffff;
font-weight: 600;
box-shadow: 0 2px 6px rgba(23, 92, 211, 0.2);
}
/* Update Page Actions */
.tn-update-page-actions {
display: flex;
align-items: center;
gap: 10px;
}
/* 4 Metrics Grid */
.tn-update-metrics-grid {
display: grid;
grid-template-columns: repeat(4, minmax(0, 1fr));
gap: 14px;
margin-bottom: 16px;
}
.tn-metric-card .t-card__body {
display: flex;
flex-direction: column;
justify-content: space-between;
padding: 16px 18px;
min-height: 104px;
}
.tn-metric-content {
width: 100%;
}
.tn-metric-label {
display: block;
font-size: 12px;
color: var(--tn-text-secondary);
margin-bottom: 4px;
}
.tn-metric-value {
font-size: 20px;
font-weight: 700;
color: var(--tn-navy-900);
font-family: "Plus Jakarta Sans Variable", sans-serif;
font-variant-numeric: tabular-nums;
line-height: 1.2;
}
.tn-metric-foot {
margin-top: 6px;
font-size: 12px;
color: var(--tn-text-muted);
}
/* Stepper Surface */
.tn-stepper-surface {
margin-bottom: 16px;
padding: 20px;
}
.tn-stepper-head {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 16px;
margin-bottom: 20px;
}
.tn-section-heading {
margin: 0 0 4px;
font-size: 15px;
font-weight: 700;
color: var(--tn-text);
}
.tn-section-subheading {
font-size: 12px;
color: var(--tn-text-secondary);
}
.tn-stepper-wrap {
padding: 10px 0 20px;
}
.tn-stepper-wrap .t-steps {
max-width: 860px;
margin: 0 auto;
}
.tn-stepper-wrap {
min-width: 0;
overflow-x: auto;
scrollbar-width: thin;
scrollbar-color: var(--td-brand-color-3) transparent;
}
.tn-stepper-wrap .t-steps {
min-width: 680px;
}
/* Job Runtime Panel (Active download & progress) */
.tn-job-runtime-panel {
margin-top: 14px;
padding: 16px;
background: #f8fbff;
border: 1px solid var(--td-brand-color-2);
border-radius: 4px;
}
.tn-job-runtime-header {
display: flex;
align-items: center;
justify-content: space-between;
flex-wrap: wrap;
gap: 10px;
margin-bottom: 12px;
}
.tn-job-status-badge {
display: flex;
align-items: center;
gap: 8px;
font-size: 13px;
color: var(--tn-navy-900);
min-width: 0;
overflow-wrap: anywhere;
}
.tn-pulse-dot {
width: 8px;
height: 8px;
border-radius: 50%;
background: var(--td-brand-color);
box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7);
animation: tn-pulse 1.8s infinite;
}
@keyframes tn-pulse {
0% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7); }
70% { transform: scale(1); box-shadow: 0 0 0 6px rgba(23, 92, 211, 0); }
100% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0); }
}
.tn-job-subtext {
color: var(--tn-text-secondary);
font-size: 12px;
font-family: "Plus Jakarta Sans Variable", sans-serif;
font-variant-numeric: tabular-nums;
}
.tn-speed-indicator {
display: flex;
align-items: center;
gap: 8px;
min-width: 0;
flex-wrap: wrap;
}
.tn-speed-badge {
display: inline-flex;
align-items: center;
gap: 4px;
padding: 2px 8px;
border-radius: 3px;
background: #ffffff;
border: 1px solid var(--td-brand-color-3);
color: var(--td-brand-color);
font-size: 12px;
font-weight: 600;
font-family: "Plus Jakarta Sans Variable", sans-serif;
font-variant-numeric: tabular-nums;
}
.tn-eta-badge {
display: inline-block;
padding: 2px 8px;
border-radius: 3px;
background: #f2f5f9;
color: var(--tn-text-secondary);
font-size: 12px;
font-variant-numeric: tabular-nums;
}
/* Progress Bar with modern stream light effect */
.tn-progress-stream {
position: relative;
height: 8px;
background: #e1e9f4;
border-radius: 999px;
overflow: hidden;
margin-bottom: 12px;
}
.tn-progress-stream-bar {
height: 100%;
background: linear-gradient(90deg, #175cd3 0%, #3d7be5 100%);
border-radius: inherit;
transition: width 0.35s ease;
position: relative;
}
.tn-progress-stream-bar::after {
content: "";
position: absolute;
top: 0; left: 0; bottom: 0; right: 0;
background-image: linear-gradient(
-45deg,
rgba(255, 255, 255, 0.25) 25%,
transparent 25%,
transparent 50%,
rgba(255, 255, 255, 0.25) 50%,
rgba(255, 255, 255, 0.25) 75%,
transparent 75%,
transparent
);
background-size: 30px 30px;
animation: tn-stream-flow 1.5s linear infinite;
}
@keyframes tn-stream-flow {
0% { background-position: 0 0; }
100% { background-position: 30px 30px; }
}
.tn-job-runtime-desc {
font-size: 12px;
color: var(--tn-text-secondary);
line-height: 1.6;
}
/* Restarting State Banner */
.tn-restarting-banner {
display: flex;
align-items: center;
gap: 12px;
padding: 8px 12px;
background: #fff8e6;
border: 1px solid #ffd666;
border-radius: 3px;
color: #8c5b00;
}
.tn-restarting-spinner {
color: #faad14;
}
/* Release Surface */
.tn-release-surface {
margin-bottom: 16px;
padding: 20px;
}
.tn-release-header {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 16px;
}
.tn-release-tag-row {
display: flex;
align-items: center;
gap: 8px;
margin-bottom: 6px;
}
.tn-release-title {
margin: 0 0 6px;
font-size: 22px;
font-weight: 700;
color: var(--tn-navy-900);
}
.tn-release-time {
font-size: 12px;
color: var(--tn-text-secondary);
}
.tn-release-notes-box {
margin: 16px 0;
padding: 12px 16px;
background: #f8fafc;
border: 1px solid var(--tn-border);
border-left: 3px solid var(--td-brand-color);
border-radius: 3px;
}
.tn-release-notes-heading {
display: flex;
align-items: center;
gap: 6px;
font-size: 12px;
font-weight: 600;
color: var(--tn-navy-900);
margin-bottom: 6px;
}
.tn-release-notes-content {
font-size: 13px;
color: var(--tn-text-secondary);
line-height: 1.6;
max-height: 140px;
overflow-y: auto;
}
.tn-markdown-notes {
color: inherit;
line-height: 1.7;
overflow-wrap: anywhere;
}
.tn-markdown-notes p,
.tn-markdown-notes h3,
.tn-markdown-notes h4,
.tn-markdown-notes h5 {
margin: 0 0 8px;
}
.tn-markdown-notes p:last-child,
.tn-markdown-notes ul:last-child,
.tn-markdown-notes pre:last-child,
.tn-markdown-notes h3:last-child,
.tn-markdown-notes h4:last-child,
.tn-markdown-notes h5:last-child {
margin-bottom: 0;
}
.tn-markdown-notes h3,
.tn-markdown-notes h4,
.tn-markdown-notes h5 {
color: var(--tn-navy-900);
font-weight: 700;
}
.tn-markdown-notes h3 { font-size: 15px; }
.tn-markdown-notes h4 { font-size: 14px; }
.tn-markdown-notes h5 { font-size: 13px; }
.tn-markdown-notes ul {
margin: 0 0 8px;
padding-left: 20px;
}
.tn-markdown-notes li { margin: 3px 0; }
.tn-markdown-notes strong { color: var(--tn-navy-900); font-weight: 700; }
.tn-markdown-notes code {
padding: 1px 4px;
border: 1px solid var(--tn-border-subtle);
border-radius: 3px;
background: #f2f5f9;
color: var(--tn-navy-900);
font-family: "Plus Jakarta Sans Variable", ui-monospace, monospace;
font-size: .92em;
}
.tn-markdown-notes pre {
margin: 0 0 8px;
padding: 10px 12px;
overflow-x: auto;
border: 1px solid var(--tn-border-subtle);
border-radius: 3px;
background: #f8fafc;
white-space: pre-wrap;
}
.tn-markdown-notes pre code { padding: 0; border: 0; background: transparent; }
.tn-markdown-notes a { color: var(--td-brand-color); text-decoration: underline; text-underline-offset: 2px; }
.tn-markdown-notes-compact { font-size: 13px; }
/* Facts Grid */
.tn-facts-grid {
display: grid;
grid-template-columns: repeat(3, minmax(0, 1fr));
gap: 14px;
margin: 18px 0;
padding: 14px 0;
border-top: 1px solid var(--tn-border-subtle);
border-bottom: 1px solid var(--tn-border-subtle);
}
.tn-fact-item {
display: flex;
flex-direction: column;
gap: 4px;
}
.tn-fact-label {
font-size: 12px;
color: var(--tn-text-secondary);
}
.tn-fact-value {
font-size: 14px;
color: var(--tn-text);
font-weight: 600;
overflow-wrap: anywhere;
}
.tn-fact-hint {
font-size: 11px;
color: var(--tn-text-muted);
}
.tn-release-card-actions {
display: flex;
align-items: center;
gap: 12px;
margin-top: 16px;
}
/* Dialog content styles */
.tn-confirm-dialog-content {
font-size: 13px;
line-height: 1.6;
color: var(--tn-text);
}
.tn-update-safety-tips {
margin-top: 10px;
padding: 10px 14px;
background: #f6f8fb;
border-radius: 3px;
border: 1px solid var(--tn-border-subtle);
font-size: 12px;
color: var(--tn-text-secondary);
display: flex;
flex-direction: column;
gap: 4px;
}
.tn-full-notes-modal {
margin: 0;
padding: 12px;
background: #f8fafc;
border-radius: 3px;
font-size: 13px;
line-height: 1.6;
color: var(--tn-text);
max-height: 50vh;
overflow-y: auto;
}
.tn-empty-surface {
padding: 36px 20px;
text-align: center;
}
.tn-empty-content {
display: flex;
flex-direction: column;
align-items: center;
gap: 8px;
color: var(--tn-text-secondary);
font-size: 13px;
}
.tn-inline-warning {
display: flex;
align-items: center;
gap: 8px;
padding: 10px 14px;
margin-bottom: 14px;
background: #fffbe6;
border: 1px solid #ffe58f;
border-radius: 3px;
color: #d48806;
font-size: 13px;
}
/* Responsive adjustments */
@media (max-width: 992px) {
.tn-update-metrics-grid {
grid-template-columns: repeat(2, minmax(0, 1fr));
}
.tn-facts-grid {
grid-template-columns: 1fr;
}
}
@media (max-width: 640px) {
.tn-update-metrics-grid {
grid-template-columns: 1fr;
}
.tn-mock-console-header {
flex-direction: column;
align-items: flex-start;
}
.tn-release-header {
flex-direction: column;
}
.tn-release-card-actions {
flex-direction: column;
width: 100%;
}
.tn-release-card-actions .t-button {
width: 100%;
}
.tn-stepper-wrap {
margin-inline: -4px;
padding-inline: 4px;
}
.tn-stepper-wrap .t-steps {
min-width: 620px;
}
.tn-job-runtime-header {
align-items: stretch;
}
.tn-job-status-badge,
.tn-speed-indicator {
width: 100%;
}
.tn-speed-indicator {
justify-content: flex-start;
}
}