Commit Graph
17 Commits
Author SHA1 Message Date
pj 958931f5ef announce updates rather than install them when a package manager owns the binary 2026-09-03 13:24:20 +05:30
pj ae5a7b4c0e let cargo.lock catch up with the 0.0.4 bump 2026-09-03 13:24:20 +05:30
pj 31a4aef5d2 keep the checkout owned by the runner when generating .SRCINFO 2026-09-03 11:30:50 +05:30
pj 17c3873723 re-read the clock when the window comes back 2026-09-03 11:22:44 +05:30
pj 9462b7920f hold the hour it is now open through every strip, folds included 2026-09-03 11:22:44 +05:30
pj 1c709967f8 fix few bugs 2026-09-02 19:12:19 +05:30
pj c1c6db1406 fix diff escape bug 2026-09-02 14:33:57 +05:30
pj af8e66e84d fix bug on hour fold update 2026-09-02 13:08:02 +05:30
pj 3754e4a652 Sync the lock file to the version the crate declares
Cargo.toml went to 0.0.1 with the release, and the lock kept the 0.1.0 it was
written with. Every cargo command has been quietly rewriting it since, so
anyone running the Rust suite gets a dirty tree before they have changed
anything.
2026-08-13 22:17:01 +05:30
pj 67879fd6c3 Keep the hour it is now on the axis
The visible range is drawn from the events in view, and in the evening the
events are behind you: the bounds end at six, everything after that is in the
trailing strip, and the now line has nowhere to land. The app stops saying
where in the day you are, which is most of what it is open for. Same at seven
in the morning, from the other end.

So when today is one of the columns, the axis takes that one hour in, and
everything the widening reached over folds behind it. At half eleven at night
the fixture week reads 7am to 8pm as usual, then an "8pm to 11pm" strip, then
one 11pm row with the line in it. A row and a strip, not four rows of empty
evening. Only the hour itself is opened, so how far the clock has drifted past
the last event costs nothing.

The pin sits on top of the hysteresis rather than inside it. previous.current
still holds what the events and the user asked for, so an hour pinned open
tonight cannot accumulate into the bounds the grid remembers tomorrow.

One consequence, and it is the only place the axis is allowed to move under
you: page to a week that does not contain today and the row goes again, along
with the strip it was sitting under.

The tick that drives it is an hour long, not a minute, because that is how
often the answer changes. It lives in a new useClock alongside the minute tick
the now line already had, which moves there out of GridNowLine. Both schedule
off the clock rather than off an interval, so a machine that was asleep
catches up on the next tick instead of drifting further out every hour.

The browser suite has to say what time it is now. The shape of the axis
depends on the hour a run happens at, so anything measuring a row height or
counting strips pins the clock to the middle of the working day, the same way
it already pins the theme and the week start. The three tests that are about
the clock ask for half eleven at night, which the fixture leaves empty.
2026-08-13 22:15:08 +05:30
pj 3323496a34 License under MIT
No licence file meant nobody had permission to redistribute this, which is a
strange position for a public repo with an AUR package pointing at it. The
PKGBUILD said license=('custom') because there was nothing truthful to put
there.

MIT is not one of the licences Arch keeps in /usr/share/licenses/common, so
the package now fetches the licence from its own tag and installs a copy. The
release workflow checksums that copy from the tag it checked out, rather than
trusting whatever main has drifted to.

Declared in package.json and Cargo.toml too, so the manifests and the package
agree on the answer.
2026-08-12 21:30:13 +05:30
pj fef1ad7ff5 Publish an Arch package to the AUR from the release
The AppImage runs on Arch but not as a Wayland client. It carries Ubuntu's
GTK stack including libwayland-client, which cannot talk to a current
compositor, so on Hyprland it fails to initialise GTK and only starts once it
falls back to Xwayland. Verified both ways on a real session: the AppImage
comes up with xwayland 1, the packaged build with xwayland 0.

margin-calendar-bin repackages the published .deb rather than building from
source, which is forced rather than lazy. The Google OAuth client is embedded
at compile time from a file that is not in the repo, so a source package
would build cleanly on a stranger's machine and then tell them Google
Calendar is not set up.

The job runs after the manifest check, so the AUR can only ever point at a
release that survived it, and it checksums the artifact it just downloaded
rather than one it assumed was there. Without AUR_SSH_PRIVATE_KEY it renders
the package, warns, and leaves the release alone.

license=('custom') is honest rather than chosen: this repo has no licence
file. That is worth fixing before anyone else packages it.
2026-08-12 20:59:21 +05:30
pj 8a525110c5 Cover the token round trip, not just the cipher
Every existing test handed seal and open a constant key, so the derivation
they are used with had no coverage at all: a key that disagreed with itself
between two calls would have passed the whole suite and broken every sign-in.

This drives store, load and delete through the real salt file and the real
machine id, and loads twice on purpose, because the second load derives the
key afresh from what the first one left on disk.
2026-08-12 20:20:51 +05:30
pj 99bbe1113a Bind a stored token to the Mac it was stored on
The machine identifier mixed into the key was read from /etc/machine-id,
which does not exist on macOS, so it was the empty string there. The salt
sits next to the ciphertext and the key context is a constant in a public
binary, which makes that identifier the only thing standing between a copied
home directory and a readable refresh token. Empty is not a neutral
contribution of no entropy, it is the absence of the binding: until now a
home directory lifted off a Mac decrypted anywhere. The file has claimed
otherwise since it was written.

macOS now reads IOPlatformUUID from ioreg, a stock binary called by absolute
path because an app launched from Finder inherits a minimal environment. The
result is cached, since a process spawn is real money when key() runs on
every load and every store. A failure yields an empty id and a working key
rather than an error, because refusing here would lock a user out of a token
that is perfectly good.

iOS and Android stay empty deliberately. The sandbox is the real boundary
there, and every identifier those platforms offer is reset by a reinstall,
which would strand a token that was never in any danger.

No migration, and that is a decision rather than an oversight. Nothing has
been released, so the only install this can orphan is a development machine,
and doing it now costs one reconnect instead of costing every Mac user one
later.

For the same reason the keychain-fallback.* paths are gone. They migrated
nobody, and they were subtly wrong anyway: they carried the old salt across
under the new name while deriving with the new key context, which silently
produced a token that could not be opened. A migration that looks like it
works and does not is worse than no migration.

key() also no longer treats every failure to read the salt as absence. A
missing file and a file too short to be a salt both take a fresh one, since
neither has anything left to lose, but a salt that exists and will not read
is now an error. Writing over it turned one transient read failure into the
permanent loss of every stored token.
2026-08-12 20:16:29 +05:30
pj 590506eb92 Build and sign releases in CI, and install locally with one command
Ported from margin's pipeline, with the platform list this app actually
claims. Release is manual: it bumps tauri.conf.json, package.json and
Cargo.toml together, tags, and then builds the tag rather than whatever main
has drifted to by the time the runners pick it up.

Nothing publishes until every platform lands. The last job downloads
latest.json and refuses to take the release out of draft unless
darwin-aarch64, darwin-x86_64 and linux-x86_64 are all present, because a
half-populated manifest is worse than no release at all: the updater would
offer an update to the platforms that made it and error on the ones that did
not.

Linux builds on Ubuntu 22.04 rather than latest. The bundle will not run on
anything older than the glibc it was linked against, and 22.04 is the
baseline docs/setup.md commits to. Windows is not built, matching the bundle
targets and the README; adding it is a matrix entry, msi and nsis in the
targets, and windows-x86_64 in the publish gate.

The updater had a plugin, a capability and a menu item but no keypair and no
endpoint, so releases would have produced artifacts nothing could verify.
The public half is now in tauri.release.conf.json and the private half is a
repository secret, alongside the Google OAuth client that build.rs embeds.
Without that secret the build falls back to the example credentials and warns
rather than failing, which yields an app that runs and then says Google
Calendar is not set up.

CI enforces the gate setup.md already names, the two test suites, and nothing
more. cargo fmt --check and cargo clippy -D warnings both fail on the tree as
it stands, and adopting either is a cleanup pass to decide on rather than
something to bolt onto a new pipeline.

justfile is the local equivalent of all this. `just install` builds for the
machine it is run on and installs it, and is the same command whether or not
the app is already there, so it doubles as the update. On macOS it asks a
running copy to quit first, because replacing a bundle under a live process
leaves it half old and half new.
2026-08-12 20:16:29 +05:30
pj d4c3a304b5 Sign in on a phone with no console work, in the browser's own session
Mobile OAuth reused the desktop client all along; what stopped it was the
browser. Sending the user out to Safari or Chrome backgrounds the app, iOS
suspends it, and the redirect carrying the code arrives at a socket nobody
is accepting on. The consent page now opens in front of the app instead, in
SFSafariViewController or a Chrome Custom Tab, so the loopback listener
stays live and the existing `installed` client is enough. Verified against
Google's real consent screen on a simulator and an emulator.

A per-platform client is still supported and is now an upgrade rather than a
prerequisite. On iOS it buys ASWebAuthenticationSession, which shares
Safari's session so nobody is asked to sign in to Google twice. Android
needs nothing: Custom Tabs share Chrome's cookies, measured rather than
assumed. iOS session sharing could not be confirmed on the simulator and
wants a real device.

Never an app-owned WebView: Google blocks it, and rightly, since a webview
the app controls can read the password typed into it.

Cancelling is no longer reported as a failure. AuthEvent carries a
`cancelled` flag, set by comparing against the constant every back-out path
returns, and Google's `access_denied` on desktop counts too.

Five frontend bugs found by driving the real UI, not by reading it: the
details card slid under the tab bar leaving its buttons unhittable; the
ghost click after a touch pressed a button in the card that tap had just
opened, opening the editor by itself; the swipe that pages the day was dead
over every read-only block; 84px of macOS traffic-light lane was reserved on
platforms with no traffic lights; and the desktop header ignored the top
safe area on an iPad. A first launch now says what to do next rather than
showing an empty grid, and accounts are named as Google accounts throughout.
2026-08-12 18:32:45 +05:30
pj 661100dfdc Margin Calendar: a Google Calendar client for desktop and phone
Tauri 2, React 19 and zustand on the front, Rust behind. Rust owns auth,
all HTTP to Google, the SQLite store, the sync loop, recurrence expansion
and timezone maths. TypeScript owns rendering and never talks to Google,
which keeps the content security policy locked to ipc:.

Week, day and agenda views, and no month view: it would be a second layout
engine, and the fit and fold logic that makes a day fit the window without
scrolling is the whole point of the app.

Runs on macOS, Linux, Android and iOS. Desktop catches Google's OAuth
redirect on a loopback port. A phone cannot, and Google rejects loopback
for mobile client types anyway, so it redirects to a custom URI scheme and
needs its own public OAuth clients, which docs/mobile.md covers. Refresh
tokens are sealed with XChaCha20-Poly1305 in the app data directory on
every platform, with no OS credential store in the picture.

On a phone the chrome becomes a top bar and a bottom tab bar, overlays
become sheets, hover affordances become taps, and dragging out an event
waits for a long press. Navigation moves one day at a time everywhere,
a swipe included.
2026-08-12 17:09:21 +05:30