Updates from Gitea, step 1: the model (host-tested)

A streaming JSON scanner (a 33 KB list of releases costs a few hundred
bytes), the release reader built on it, HTTP response heads and chunked
bodies, URLs, and the decisions: which release is an update, whether to
announce it, and which download URLs the device takes. Tested against the
real answers of git.twis.la.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 15:11:58 +02:00
co-authored by Claude Sonnet 5.5
parent 6b7e90765f
commit b0e8226943
13 changed files with 1058 additions and 0 deletions
+15
View File
@@ -0,0 +1,15 @@
#include "update_check.h"
#include "http_head.h"
namespace roro::release {
bool trustedAssetUrl(const std::string& url, const std::string& host, const std::string& repo) {
Url u = parseUrl(url);
if (!u.ok || !u.https || u.port != 443 || u.host != host) return false;
std::string prefix = "/" + repo + "/releases/download/";
return u.path.compare(0, prefix.size(), prefix) == 0 && u.path.find("..") == std::string::npos &&
u.path.find('?') == std::string::npos && u.path.find('#') == std::string::npos;
}
} // namespace roro::release