An APK built in this VM pins this VM's CA, so it can never reach the host's ai-server -- which is exactly the iris Android client's situation (cross-compiled here, run against the host). So ai-server now puts the CA in every enrollment link it mints, base64url of its DER under the 'ca' parameter wg-app-link just learned to add, and client_core parses it back out as PEM. Nothing has to be built on the machine it talks to. Refused rather than ignored where 'ca' does not decode: a link that named a certificate and then pinned nothing is the one outcome nothing downstream could notice. EnrollmentStore moves out of desktop-app into client_core::config, since the Android client needs the same file for the same reason and only the directory differs by platform (AGENTS.md's sharing rule). desktop-app's --ca becomes the override for a link that carried none. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
53 lines
2.6 KiB
TOML
53 lines
2.6 KiB
TOML
[package]
|
|
name = "client-core"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
|
|
# The app's pure logic, held once instead of twice: the event model (shared
|
|
# with `server/` via `event-model`), the REST + SSE clients for its HTTP
|
|
# surface (see `server/src/routes.rs`'s module doc for the table), the
|
|
# transcript fold and cache, the markdown block model, the syntax
|
|
# highlighter and the ANSI parser. See `docs/CLIENT_CORE.md` for
|
|
# what this holds today, what it does not yet, and how it corresponds to
|
|
# the Kotlin it replaces.
|
|
#
|
|
# No UI framework dependency of any kind -- this crate is meant to outlive
|
|
# whichever one the app ends up drawing with (see RUST.md).
|
|
|
|
[dependencies]
|
|
event-model = { path = "../event-model" }
|
|
serde = { version = "1", features = ["derive"] }
|
|
# "raw_value" is `fetch_transcript_lines`'s reason -- it needs the exact
|
|
# bytes the server sent, not this crate's own re-serialization of a parsed
|
|
# `Value`, so a cached line and a live SSE frame for the same event agree
|
|
# byte-for-byte (see that method's doc). "float_roundtrip" is why they
|
|
# agree on a `ts` at all -- see server/Cargo.toml's identical comment.
|
|
serde_json = { version = "1", features = ["float_roundtrip", "raw_value"] }
|
|
# The blocking HTTP client for the REST calls and the long-lived SSE GETs.
|
|
# `server/` already depends on ureq for its own outbound HTTPS (the usage
|
|
# poll in usage.rs) and it is rustls-backed like the rest of this project's
|
|
# TLS, so this reuses that choice rather than pulling in reqwest's async
|
|
# stack -- a client that runs one blocking request at a time, the way
|
|
# Api.kt's `HttpURLConnection` calls and Sse.kt's blocking read loop do, has
|
|
# no need of an async runtime, and RUST.md's brief for this port is
|
|
# "lightweight" throughout.
|
|
ureq = { version = "3", features = ["json"] }
|
|
# The markdown block split (`markdown_blocks`), which has to agree with the
|
|
# renderer in `iris/transcript-ui` about where a block begins -- so it is
|
|
# the same parser at the same version, rather than a hand-written splitter
|
|
# that would drift from it.
|
|
pulldown-cmark = "0.13.4"
|
|
# The enrollment link's `ca` parameter is base64url of the CA's DER
|
|
# (`config::parse_link`). Same version `wg-app-link` already pins for the
|
|
# minting half, so a workspace that has both resolves one copy.
|
|
base64 = "0.23"
|
|
# The logging facade only -- `log_ring` implements a `log::Log` backend and
|
|
# wraps whichever real one the platform installed (`android_logger` on the
|
|
# phone, `env_logger` on the desktop), which is why neither of those is a
|
|
# dependency here. See `log_ring`'s module doc.
|
|
log = { version = "0.4.28", features = ["std"] }
|
|
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|