Public Access
Updates from Gitea, step 1: the model (host-tested)
A streaming JSON scanner (a 33 KB list of releases costs a few hundred bytes), the release reader built on it, HTTP response heads and chunked bodies, URLs, and the decisions: which release is an update, whether to announce it, and which download URLs the device takes. Tested against the real answers of git.twis.la. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
#include "update_check.h"
|
||||
|
||||
#include "http_head.h"
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
bool trustedAssetUrl(const std::string& url, const std::string& host, const std::string& repo) {
|
||||
Url u = parseUrl(url);
|
||||
if (!u.ok || !u.https || u.port != 443 || u.host != host) return false;
|
||||
std::string prefix = "/" + repo + "/releases/download/";
|
||||
return u.path.compare(0, prefix.size(), prefix) == 0 && u.path.find("..") == std::string::npos &&
|
||||
u.path.find('?') == std::string::npos && u.path.find('#') == std::string::npos;
|
||||
}
|
||||
|
||||
} // namespace roro::release
|
||||
Reference in New Issue
Block a user