Public Access
A streaming JSON scanner (a 33 KB list of releases costs a few hundred bytes), the release reader built on it, HTTP response heads and chunked bodies, URLs, and the decisions: which release is an update, whether to announce it, and which download URLs the device takes. Tested against the real answers of git.twis.la. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
16 lines
565 B
C++
16 lines
565 B
C++
#include "update_check.h"
|
|
|
|
#include "http_head.h"
|
|
|
|
namespace roro::release {
|
|
|
|
bool trustedAssetUrl(const std::string& url, const std::string& host, const std::string& repo) {
|
|
Url u = parseUrl(url);
|
|
if (!u.ok || !u.https || u.port != 443 || u.host != host) return false;
|
|
std::string prefix = "/" + repo + "/releases/download/";
|
|
return u.path.compare(0, prefix.size(), prefix) == 0 && u.path.find("..") == std::string::npos &&
|
|
u.path.find('?') == std::string::npos && u.path.find('#') == std::string::npos;
|
|
}
|
|
|
|
} // namespace roro::release
|