diff --git a/.changes/third-party-notices.json b/.changes/third-party-notices.json new file mode 100644 index 00000000..40b5c58c --- /dev/null +++ b/.changes/third-party-notices.json @@ -0,0 +1 @@ +{ "type": "internal", "reason": "Every build now carries the third-party notices (THIRD_PARTY_NOTICES.txt in the web and PWA builds, precached by the PWA; inside the HTML of the portable file), generated offline from the bundle and checked against a committed manifest; a change in what ships fails the build until the manifest is updated and reviewed. Nothing in the app's interface changes; the screen that shows the notices comes in a later change." } diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ba269de4..3aa4b5bc 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -91,8 +91,12 @@ jobs: run: npm run build:pwa - name: PWA precache closure (mode=pwa) run: npm run check:pwa-closure - - name: PWA precache closure (Cloudflare Production path) - run: CF_PAGES_BRANCH=main npm run build && node scripts/check-pwa-closure.mjs dist + # issue #301 — the notices ship in each build, match the manifest, and the + # PWA precaches them; the build itself already failed on a manifest mismatch + - name: Third-party notices in the web, portable and PWA builds + run: npm run check:third-party-notices + - name: PWA precache closure and notices (Cloudflare Production path) + run: CF_PAGES_BRANCH=main npm run build && node scripts/check-pwa-closure.mjs dist && node scripts/check-third-party-notices.mjs dist pwa # ── E2E, parallelised ────────────────────────────────────────────────── # The dev-server + portable suite (`npm run e2e`) is split into N shards that diff --git a/e2e/portable-file.spec.ts b/e2e/portable-file.spec.ts index 7233baad..d1f8b978 100644 --- a/e2e/portable-file.spec.ts +++ b/e2e/portable-file.spec.ts @@ -7,6 +7,7 @@ import { capturedExports, installProbe, pathProbe, portableUrl } from './support import { expectOneVersionStory, readAboutVersion, readNewestShown, seedWhatsNewSeen } from './support/whatsNew' import { RELEASE_NOTES } from '../src/releaseNotes/releaseNotes' import { LEGACY_SHARE_VECTORS } from '../src/model/shareLegacy.fixture' +import { PORTABLE_TEMPLATE_ID, portableTemplate, sha256 } from '../scripts/third-party-notices/core.mjs' // SLICE-2 §5–§6: the portable single-file build opened from file://. No dev // server, no window.__loop bridge (production build) — driven entirely through @@ -167,6 +168,53 @@ test.describe('portable file://', () => { } }) + // issue #301 - the notices ride in the single file as TEXT in a