Serve src/ directly from the web server with no Node process involved. The
Caddyfile is the shortest path to TLS, which every non-localhost deployment
needs: on a plain-HTTP LAN address Chromium drops WebCodecs and blocks
IndexedDB, so export slows to real-time capture and projects stop saving.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
electron/main.js starts the same static server the bare-metal target uses on
127.0.0.1 with a random port and points the window at it, rather than calling
loadFile(). Chromium exposes WebCodecs and IndexedDB only in a secure context:
over file:// the exporter would fall back to real-time MediaRecorder capture
and projects would stop saving, both silently.
The renderer runs sandboxed with no node integration, denies every permission
request, and hands http(s) navigations to the real browser.
PACKAGING.md documents all three distribution targets, including the NSIS
"Access denied" failure caused by an endpoint protection agent locking the
freshly written unsigned exe.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dockerfile builds a static-web-server image serving src/ with the third-party
assets vendored in a first stage, so the runtime layer carries no Node and no
shell tooling. WITH_FFMPEG=0 drops the 18.5 MB asm.js encoder for a smaller
image, at the cost of fetching it at export time.
.gitignore covers dist/, which the release scripts write on every run: without
it a fresh clone reports the build output as untracked and publish.ps1 warns
that the worktree is dirty on every build.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
scripts/build-release.ps1 packages the desktop installers; scripts/publish.ps1
pushes the container image to git.azuze.fr and attaches the installers to the
Gitea release for the same tag. The split keeps a local build free of any
credential, and lets a failed upload be retried with -BinariesOnly
-NoBinaryBuild without paying for the build again.
Two details the plain `npm run dist:*` path gets wrong for a release:
- package.json's global artifactName resolves NSIS and portable to the same
file name, so one silently overwrites the other. The build script passes
distinct -c.nsis.artifactName / -c.portable.artifactName.
- Artifact names now carry the tag, so publish.ps1 can glob exactly one tag's
files and never ship a stale one. electron-builder's update metadata
(.blockmap, latest*.yml, the NSIS .7z payload) is swept out of dist/ so it
cannot match that glob and end up attached to the release.
The tag defaults to v<package.json version> rather than git describe, because
electron-builder stamps package.json into the app: a SHA-based tag would name
an installer whose About box disagrees with it.
Also brings scripts/server.cjs, vendor.mjs and make-icon.cjs under version
control, which the release scripts and the Docker build both call.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Fix download filename handling in converter and export functions
- Make updateRecordCanvas return Promise to handle async loadFromJSON correctly
- Add setCoords() call in setObjectValue to fix object selection after updates
- Update recorder initialization and animation frame handling
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>