51 lines
2.6 KiB
Markdown
51 lines
2.6 KiB
Markdown
# CLAUDE.md
|
|
|
|
## Project
|
|
|
|
Alta Proxy Tool (APT) is a Windows-only Electron app. Its source of record and releases are on GitPeji:
|
|
|
|
- Repository: `https://git.pejicorp.com/peji/Alta-Proxy-Tool`
|
|
- Releases: `https://git.pejicorp.com/peji/Alta-Proxy-Tool/releases`
|
|
|
|
The app imports an Alta Video session through a stable-ID paired Chrome extension, discovers cameras, and directly launches the fixed `aware-cam-proxy.exe` helper.
|
|
|
|
## Commands
|
|
|
|
```bash
|
|
npm start
|
|
npm run dev
|
|
npm test
|
|
npm run check
|
|
npm run build-test
|
|
npm run build
|
|
```
|
|
|
|
## Required security architecture
|
|
|
|
- Main owns `SessionStore`, `AltaClient`, `ProxyProcessManager`, bridge authentication, and safe update checking.
|
|
- Renderer/preload contracts must never carry the Alta deployment credential or cookie.
|
|
- IPC methods are narrow and sender-validated against the main local file frame.
|
|
- Bridge is exactly `127.0.0.1:18247`, exact committed extension origin, and `X-APT-Pairing` authenticated.
|
|
- Persist only the pairing hash envelope under Electron `userData`; plaintext is shown once after first run/rotation.
|
|
- Proxy helper launches directly with `shell: false`; passwordless launch uses the main-owned paired session only through the helper's required `-k` argument. Never expose that cookie to renderer IPC, UI, logs, files, shell commands, or tracked process metadata; stop only app-owned child processes.
|
|
- Update behavior is check-only against the exact GitPeji API. The only follow-up action opens the fixed GitPeji releases page externally.
|
|
- Never add download/install/replace logic, arbitrary URLs, redirect following, shell scripts, broad process killing, hardcoded bridge secrets, or credential-bearing renderer state.
|
|
- Synthetic tests only: never use a real tenant or Alta session.
|
|
|
|
## File map
|
|
|
|
- `main.js`: Electron adapter, lifecycle, trusted IPC registration, fixed bridge listener
|
|
- `src/electron-runtime.js`: runtime orchestration, pairing persistence, bridge request contract
|
|
- `src/session-store.js`: in-memory credential boundary
|
|
- `src/alta-client.js`: bounded same-origin Alta API client
|
|
- `src/proxy-launch.js`: Windows direct-spawn owned-child manager
|
|
- `src/update-policy.js`: GitPeji check-only policy
|
|
- `src/bridge-auth.js`: stable extension origin, scrypt pairing, limits/deadlines
|
|
- `preload.js`: narrow methods and event payload stripping
|
|
- `renderer.js`: non-secret connection/device/proxy/pairing/update UI
|
|
- `test/runtime-contract.test.js`: integration and forbidden-source policy
|
|
|
|
## Scope
|
|
|
|
Windows is the current supported runtime because `aware-cam-proxy.exe` is Windows-specific. Do not upgrade dependencies or change production/Tool Hub as part of runtime hardening unless explicitly requested.
|