Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: tarwin/tinyjsapp
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.44.1
Choose a base ref
...
head repository: tarwin/tinyjsapp
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.45.0
Choose a head ref
  • 11 commits
  • 10 files changed
  • 2 contributors

Commits on Oct 2, 2026

  1. fix(setup): one mktemp dir instead of guessable /tmp/*-$$ paths (#30)

    setup.sh downloaded and built txiki under /tmp/tjs-$$.gz,
    /tmp/txiki-src-$$ and /tmp/txiki-$$.zip. PID-based names are
    predictable, so another local user could pre-plant a symlink or a
    source tree there. Everything now goes in one mktemp -d dir removed by
    an EXIT trap; the macOS launcher build's BUILD_TMP lives inside it
    (a second trap would replace the first).
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    a4f23ea View commit details
    Browse the repository at this point in the history
  2. fix(build): pin txiki.js binary hashes, re-check the build cache (#26)

    runtime/txiki.sha256 holds the sha256 of the tjs binary inside each
    saghul/txiki.js release zip we fetch (v26.6.0 macOS arm64/x86_64,
    Windows x86_64). cli.js checks it after download AND on every reuse of
    ~/Library/Caches/tinyjs (user-writable, and its exe gets bundled and
    codesigned into cross-arch/universal builds); setup.sh, setup.ps1 and
    release.yml check their downloads against it too. Verify notes in
    TODO-verify.md.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    24970b1 View commit details
    Browse the repository at this point in the history
  3. fix(bridge): built Windows/Linux apps ignore inherited TINYJS_*/WEBVI…

    …EW2_* env (#29)
    
    A built app copied its whole environment into the launcher and honored
    TINYJS_HTML/TINYJS_LAUNCHER/TINYJS_SOCKET itself, so whatever started it
    could swap its page or launcher, inject script, widen media/read access,
    or (WEBVIEW2_ADDITIONAL_BROWSER_ARGUMENTS, which we appended to) open a
    remote-debugging port. When bundlePath() says we're built, those are
    ignored and every inherited TINYJS_*/WEBVIEW2_* var is dropped before the
    bridge sets its own from the manifest; TINYJS_LAUNCHER_DEBUG stays.
    Dev and macOS are unchanged. Verify steps in TODO-verify.md.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    1f912ef View commit details
    Browse the repository at this point in the history
  4. fix(bridge): key tiny.fetch streams by calling window (#30)

    Every page numbers its streams f1, f2… from scratch, so two windows
    streaming at once collided on f1: the later stream replaced the earlier
    one in the bridge's map (the first window's body was cut off after one
    chunk), and any window could pull or cancel another's by id. Streams
    are now keyed by the calling window plus the id, and a reloaded page's
    leftover stream under a reused id is cancelled first.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    284bcce View commit details
    Browse the repository at this point in the history
  5. fix(bridge): flatten \r and \t in window titles too (#30)

    Both setTitle paths only replaced \n; use one(), which every other
    single-line wire field already goes through.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    6441c20 View commit details
    Browse the repository at this point in the history
  6. fix(bridge): store is a null-prototype object (#30)

    On a plain {}, set('__proto__', v) swapped the store's prototype
    instead of storing anything (get('x') then answered v.x, nothing was
    saved) and get('constructor') returned Object's own function. A
    store.json holding non-object JSON now loads as empty instead of
    throwing on every call. Verify notes for #30.7 in TODO-verify.md.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    9919a05 View commit details
    Browse the repository at this point in the history
  7. fix(windows): one WebView2 profile per app, not per launcher.exe (#29)

    Stock webview keys the WebView2 user-data folder on the exe name, and
    every tinyjs app's window belongs to launcher.exe, so all tinyjs apps on
    a machine shared cookies, IndexedDB, permissions and localStorage (file://
    is one origin under --allow-file-access-from-files). The bridge now sets
    TINYJS_WEBVIEW2_DATA=%APPDATA%\<app-id>\WebView2 and the win32_edge.hh
    patch uses it. No migration: apps start with a fresh profile. tinyjs dev
    also rebuilds launcher-win.exe when win32_edge.hh changes.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 2, 2026
    Configuration menu
    Copy the full SHA
    5f1dcf4 View commit details
    Browse the repository at this point in the history

Commits on Oct 3, 2026

  1. docs(verify): Windows checks for #26, #29.4, #30.7, per-app WebView2 …

    …profile
    
    All run on Windows 11 2026-10-02: setup.ps1 pin check (clean + tampered),
    built-app env stripping against a dev control, dev regression incl. F12,
    two-window streams + store, and the per-app profile (build, folder,
    isolation, persistence, survives self-update). Windows CI #26 and Linux
    #30.7 still open.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 3, 2026
    Configuration menu
    Copy the full SHA
    44eb4ca View commit details
    Browse the repository at this point in the history
  2. docs(verify): Linux checks for #30.4, #29.4, #30.7

    setup.sh prebuilt + source build leave no temp dir; built app ignores
    inherited TINYJS_* knobs (dev control bites, built doesn't); two-window
    fetch streams and null-prototype store reproduced on the old bridge and
    fixed on this one, dev and built.
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 3, 2026
    Configuration menu
    Copy the full SHA
    fa22374 View commit details
    Browse the repository at this point in the history
  3. Merge branch 'fix/hardening-1' — #26, #29, #30 hardening

    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 3, 2026
    Configuration menu
    Copy the full SHA
    af2dc72 View commit details
    Browse the repository at this point in the history
  4. release: v0.45.0 — per-app WebView2 profile, built-app env, txiki pin…

    …s, bridge fixes (#26, #29, #30)
    
    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
    tarwin and claude committed Oct 3, 2026
    Configuration menu
    Copy the full SHA
    ea26741 View commit details
    Browse the repository at this point in the history
Loading