diff --git a/.claude/NOTES-apk-search.md b/.claude/NOTES-apk-search.md index ec4b0dd..aa57ce3 100644 --- a/.claude/NOTES-apk-search.md +++ b/.claude/NOTES-apk-search.md @@ -30,3 +30,35 @@ - `app/package.json` currently copies ui with only `*.py` / `*.html`; parent must include `apk_sources/**/*.py` in packaged resources when integrating source workers. Kept package config outside this worker's scope. - No cross-provider reviewer launched: task explicitly forbids delegation and assigns integration/review to the parent. - Source metadata unknowns do not imply compatibility or verification. Unknown-package entries only group with other unknown-package entries with the same normalized name. + +## Store redesign (follow-up) + +- Read `/tmp/vrapk/p5-redesign.md` and common ground rules in full. Consulted Human Interface Craft, especially purpose/information, hierarchy, progressive disclosure and familiar navigation. +- Discover now owns the Android tab's full width; device controls/reports remain under On your Frame. Artwork cards, a featured app, browse rows, debounced search, friendly filters/count/empty state and skeletons replace the technical listing. +- Details use a native dialog with banner/icon, creator, description, screenshots with keyboard/arrow controls, badges, primary installation action and friendly source choices. Technical identifiers and compatibility facts are collapsed. +- Sources use a separate native settings dialog with aligned switches, source initials, descriptions, trust labels and repository form. A failed source produces a quiet human-readable notice. +- `_images.py` registers only source-entry artwork, returns opaque handles, permits HTTP(S) raster images only, rejects private/link-local/reserved IPs (including redirected targets), connects to the validated IP with TLS hostname checking, limits images to 8 MiB and bounds its memory cache to 64 MiB / registry to 4096 handles. Browser requests are same-origin `/source-image/`; arbitrary URLs are never accepted by the HTTP endpoint. +- New GET `/api/sources/details?source=&id=` supplies richer details. Search decorates offers with `artwork` and a plain-language `verdict`. +- Optional source metadata is documented in search.py: `images: {icon, banner, screenshots}`, developer, description, popularity, open_source, requires_meta_services, frame_tested. Only explicit `frame_tested=True` earns Works on the Frame. Installability alone says Ready to try. No fabricated popularity labels when a source provides no ranking data. +- Background jobs accept an optional progress reporter; source installs report Downloading and Installing. The UI displays a percentage only if supplied by a job. Current shared download() interface provides no byte progress, so real sources show truthful indeterminate stages, not fabricated percentages. +- Demo listings include real recorded public artwork plus clearly documented illustrative listing metadata. Preview installer alone simulates percentages and completion; it never calls frame_android.install or SSH. Repo toggles in preview use an isolated temporary settings file. + +### Visual review and evidence + +- Iteration 1: inspected browse and detail screenshots; found too much vertical space above the app rows and description. Reduced hero/banner heights and header spacing. +- Iteration 2: inspected wide and narrow layouts; moved desktop search beside the heading, placed a full popular row before the short VR row, compacted the disconnected-headset notice for browsing, aligned settings switches, preserved radio focus after detail refresh and improved progress text contrast. +- Final visual inspection: 1440x1050 desktop and 390x844 narrow viewport, two narrow columns (172px each), document width 380px inside a 390px viewport (no horizontal overflow). +- Final PNGs in `/tmp/apk-search-evidence/v2/`: browse-home.png, search-results.png, app-details.png, install-progress.png, sources-sheet.png, empty-state.png, narrow-window.png. Iteration screenshots retained there too. +- Browser checks via T3 preview at http://127.0.0.1:8795/#android: six grouped apps; no package/API/ABI/engine/demo jargon in browse; typing `world` yields three apps after debounce; app details contain three screenshots and two source choices; source selection updates installation target and keeps keyboard focus; disabling itch.io removes its notice and persists for subsequent searches; simulated install displays Downloading 43%, then completion and Open in Steam; empty search renders illustrated recovery; narrow two-column layout has no horizontal overflow. +- `FRAME_APK_SEARCH_DEMO=1 python3 tests/search_preview.py` started the local server used above. Real device endpoints rejected. +- `python3 -m unittest discover -s tests`: 188 tests passed on Python 3.9.6, exit 0. Final log `/tmp/apk-search-evidence/v2/unittest.log`. +- `node --check /tmp/apk-search-evidence/v2/ui.js`: exit 0 (inline script extracted from final index.html). +- Python 3.9 grammar parse: seven changed/new Python files passed. `git diff --check`: exit 0. + +### Still unverified / parent integration + +- Real source modules, real repository add/remove writes, real downloads and physical headset launch/install are not tested. No SSH or device installation performed. +- Image fetch transport tested with mocks; preview serves recorded images through the actual HTTP image endpoint/cache. Live asset files were fetched separately to create fixtures; live proxy TLS/redirect behavior across provider CDNs remains unverified. +- Percentages in install-progress.png are explicitly simulated by the preview harness. Real provider byte-progress integration needs an extension to the shared download interface; stage reporting works now. +- Source workers must provide `images` and creator/description metadata for rich listings; fallback gradients/initials work without them. Frame-tested/popularity signals must be backed by source evidence, not inferred from installability. +- The earlier packaging (`apk_sources/**/*.py`) and install_obb signature integration notes still apply. No Electron build or cross-provider review run; parent owns integration/review and this brief prohibits delegation. diff --git a/tests/fixtures/apk-search/artwork/README.md b/tests/fixtures/apk-search/artwork/README.md new file mode 100644 index 0000000..6c67814 --- /dev/null +++ b/tests/fixtures/apk-search/artwork/README.md @@ -0,0 +1,19 @@ +# Store preview artwork + +Recorded public artwork for offline UI verification, fetched 2026-09-28. +`urls.json` records each original URL. No unit test downloads these files. + +- Open Brush banner, icon and screenshots: Icosa Foundation's public + `icosa-foundation/openbrush.app` website assets. Artwork remains credited to + its creators; used here to preview the Open Brush listing. +- Mindustry, AntennaPod and NewPipe icons/screenshots: their public F-Droid + listings. Corresponding projects use GPL licences; these images represent + those same apps in the store preview. +- Luanti, SuperTuxKart and other social previews: public GitHub-generated + repository preview images. Project names/logos belong to their owners. + +`../store.json` contains illustrative listing metadata, including mock package +names, popularity, dates, version/size and compatibility fields. It is not a +catalogue or evidence that a particular release works on the Frame. `_demo.py` +is opt-in and cannot download APKs. `tests/search_preview.py` preloads these +recordings into the image cache and simulates installation without a headset. diff --git a/tests/fixtures/apk-search/artwork/brush-banner.jpg b/tests/fixtures/apk-search/artwork/brush-banner.jpg new file mode 100644 index 0000000..b7bd790 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/brush-banner.jpg differ diff --git a/tests/fixtures/apk-search/artwork/brush-icon.png b/tests/fixtures/apk-search/artwork/brush-icon.png new file mode 100644 index 0000000..32cfb0a Binary files /dev/null and b/tests/fixtures/apk-search/artwork/brush-icon.png differ diff --git a/tests/fixtures/apk-search/artwork/brush-shot1.png b/tests/fixtures/apk-search/artwork/brush-shot1.png new file mode 100644 index 0000000..3cd6b99 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/brush-shot1.png differ diff --git a/tests/fixtures/apk-search/artwork/brush-shot2.webp b/tests/fixtures/apk-search/artwork/brush-shot2.webp new file mode 100644 index 0000000..c22ad8c Binary files /dev/null and b/tests/fixtures/apk-search/artwork/brush-shot2.webp differ diff --git a/tests/fixtures/apk-search/artwork/brush-shot3.webp b/tests/fixtures/apk-search/artwork/brush-shot3.webp new file mode 100644 index 0000000..13b255e Binary files /dev/null and b/tests/fixtures/apk-search/artwork/brush-shot3.webp differ diff --git a/tests/fixtures/apk-search/artwork/kart.png b/tests/fixtures/apk-search/artwork/kart.png new file mode 100644 index 0000000..6d90ef5 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/kart.png differ diff --git a/tests/fixtures/apk-search/artwork/luanti-icon.png b/tests/fixtures/apk-search/artwork/luanti-icon.png new file mode 100644 index 0000000..47d7345 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/luanti-icon.png differ diff --git a/tests/fixtures/apk-search/artwork/luanti.png b/tests/fixtures/apk-search/artwork/luanti.png new file mode 100644 index 0000000..c8fa35d Binary files /dev/null and b/tests/fixtures/apk-search/artwork/luanti.png differ diff --git a/tests/fixtures/apk-search/artwork/mindustry-icon.png b/tests/fixtures/apk-search/artwork/mindustry-icon.png new file mode 100644 index 0000000..db8b4f2 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/mindustry-icon.png differ diff --git a/tests/fixtures/apk-search/artwork/mindustry-shot.png b/tests/fixtures/apk-search/artwork/mindustry-shot.png new file mode 100644 index 0000000..b9c5874 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/mindustry-shot.png differ diff --git a/tests/fixtures/apk-search/artwork/newpipe-icon.png b/tests/fixtures/apk-search/artwork/newpipe-icon.png new file mode 100644 index 0000000..561ea34 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/newpipe-icon.png differ diff --git a/tests/fixtures/apk-search/artwork/newpipe-shot.png b/tests/fixtures/apk-search/artwork/newpipe-shot.png new file mode 100644 index 0000000..3ecd0de Binary files /dev/null and b/tests/fixtures/apk-search/artwork/newpipe-shot.png differ diff --git a/tests/fixtures/apk-search/artwork/pod-icon.png b/tests/fixtures/apk-search/artwork/pod-icon.png new file mode 100644 index 0000000..9b54286 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/pod-icon.png differ diff --git a/tests/fixtures/apk-search/artwork/pod-shot.png b/tests/fixtures/apk-search/artwork/pod-shot.png new file mode 100644 index 0000000..a189a10 Binary files /dev/null and b/tests/fixtures/apk-search/artwork/pod-shot.png differ diff --git a/tests/fixtures/apk-search/artwork/urls.json b/tests/fixtures/apk-search/artwork/urls.json new file mode 100644 index 0000000..7574e46 --- /dev/null +++ b/tests/fixtures/apk-search/artwork/urls.json @@ -0,0 +1,16 @@ +{ + "brush-banner.jpg": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/bg.jpg", + "brush-icon.png": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/icon.png", + "brush-shot1.png": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/1.png", + "brush-shot2.webp": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/2.webp", + "brush-shot3.webp": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/3.webp", + "luanti.png": "https://opengraph.githubassets.com/1/luanti-org/luanti", + "kart.png": "https://opengraph.githubassets.com/1/supertuxkart/stk-code", + "luanti-icon.png": "https://raw.githubusercontent.com/luanti-org/luanti/master/textures/base/pack/logo.png", + "pod-icon.png": "https://f-droid.org/repo/de.danoeh.antennapod/en-US/icon_w44b41PyuNt3pI7Gh8zYHJrWgu__3HT7YSWZtttfenk=.png", + "mindustry-icon.png": "https://f-droid.org/repo/io.anuke.mindustry/en-US/icon_Eno3XvqCZUcHRm3eMjiUleAxgzLopPe6-hkI7BHx1lU=.png", + "mindustry-shot.png": "https://f-droid.org/repo/io.anuke.mindustry/en-US/phoneScreenshots/1.png", + "pod-shot.png": "https://f-droid.org/repo/de.danoeh.antennapod/en-US/phoneScreenshots/00.png", + "newpipe-icon.png": "https://f-droid.org/repo/org.schabi.newpipe/en-US/icon_OHy4y1W-fJCNhHHOBCM9V_cxZNJJgbcNkB-x7UDTY9Q=.png", + "newpipe-shot.png": "https://f-droid.org/repo/org.schabi.newpipe/en-US/phoneScreenshots/00.png" +} diff --git a/tests/fixtures/apk-search/store.json b/tests/fixtures/apk-search/store.json new file mode 100644 index 0000000..26bf886 --- /dev/null +++ b/tests/fixtures/apk-search/store.json @@ -0,0 +1,182 @@ +[ + { + "id": "brush", + "package": "org.preview.brush", + "name": "Open Brush", + "summary": "Make the world your canvas. Paint, sculpt and create in a space without limits.", + "description": "Your imagination deserves more room. Open Brush turns the space around you into a canvas, with expressive brushes, vivid colors and light you can paint with.\n\nCreate something small, build something extraordinary, or just enjoy making your first mark in VR. This community-led painting app is free and open source.", + "developer": "Icosa Foundation", + "license": "Apache-2.0", + "free": true, + "downloadable": true, + "version": "2.32.29", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": true, + "updated": "2026-09-27", + "size": 85000000, + "popularity": 100, + "images": { + "banner": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/bg.jpg", + "icon": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/icon.png", + "screenshots": [ + "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/1.png", + "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/2.webp", + "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/carousel/3.webp" + ] + }, + "engine": "Unity OpenXR", + "frame_tested": true, + "icon": "https://raw.githubusercontent.com/icosa-foundation/openbrush.app/main/assets/icon.png", + "page": "https://openbrush.app" + }, + { + "id": "mindustry", + "package": "org.preview.mindustry", + "name": "Mindustry", + "summary": "Build a factory. Defend your world.", + "description": "Build a factory. Defend your world.", + "developer": "Anuken", + "license": "GPL-3.0", + "free": true, + "downloadable": true, + "version": "1.2", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": false, + "updated": "2026-09-26", + "size": 85000000, + "popularity": 92, + "images": { + "banner": "https://f-droid.org/repo/io.anuke.mindustry/en-US/phoneScreenshots/1.png", + "icon": "https://f-droid.org/repo/io.anuke.mindustry/en-US/icon_Eno3XvqCZUcHRm3eMjiUleAxgzLopPe6-hkI7BHx1lU=.png", + "screenshots": [ + "https://f-droid.org/repo/io.anuke.mindustry/en-US/phoneScreenshots/1.png" + ] + }, + "icon": "https://f-droid.org/repo/io.anuke.mindustry/en-US/icon_Eno3XvqCZUcHRm3eMjiUleAxgzLopPe6-hkI7BHx1lU=.png" + }, + { + "id": "luanti", + "package": "org.preview.luanti", + "name": "Luanti", + "summary": "A world of blocks. Endless possibilities.", + "description": "A world of blocks. Endless possibilities.", + "developer": "Luanti contributors", + "license": "LGPL-2.1", + "free": true, + "downloadable": true, + "version": "1.3", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": false, + "updated": "2026-09-25", + "size": 85000000, + "popularity": 84, + "images": { + "banner": "https://opengraph.githubassets.com/1/luanti-org/luanti", + "icon": "https://raw.githubusercontent.com/luanti-org/luanti/master/textures/base/pack/logo.png", + "screenshots": [ + "https://opengraph.githubassets.com/1/luanti-org/luanti" + ] + }, + "icon": "https://raw.githubusercontent.com/luanti-org/luanti/master/textures/base/pack/logo.png" + }, + { + "id": "pod", + "package": "org.preview.pod", + "name": "AntennaPod", + "summary": "Your favorite stories, wherever you listen.", + "description": "Your favorite stories, wherever you listen.", + "developer": "AntennaPod contributors", + "license": "GPL-3.0", + "free": true, + "downloadable": true, + "version": "1.4", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": false, + "updated": "2026-09-24", + "size": 85000000, + "popularity": 76, + "images": { + "banner": "https://f-droid.org/repo/de.danoeh.antennapod/en-US/phoneScreenshots/00.png", + "icon": "https://f-droid.org/repo/de.danoeh.antennapod/en-US/icon_w44b41PyuNt3pI7Gh8zYHJrWgu__3HT7YSWZtttfenk=.png", + "screenshots": [ + "https://f-droid.org/repo/de.danoeh.antennapod/en-US/phoneScreenshots/00.png" + ] + }, + "icon": "https://f-droid.org/repo/de.danoeh.antennapod/en-US/icon_w44b41PyuNt3pI7Gh8zYHJrWgu__3HT7YSWZtttfenk=.png" + }, + { + "id": "newpipe", + "package": "org.preview.newpipe", + "name": "NewPipe", + "summary": "Your videos and music, without the distractions.", + "description": "Your videos and music, without the distractions.", + "developer": "Team NewPipe", + "license": "GPL-3.0", + "free": true, + "downloadable": true, + "version": "1.5", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": false, + "updated": "2026-09-23", + "size": 85000000, + "popularity": 68, + "images": { + "banner": "https://f-droid.org/repo/org.schabi.newpipe/en-US/phoneScreenshots/00.png", + "icon": "https://f-droid.org/repo/org.schabi.newpipe/en-US/icon_OHy4y1W-fJCNhHHOBCM9V_cxZNJJgbcNkB-x7UDTY9Q=.png", + "screenshots": [ + "https://f-droid.org/repo/org.schabi.newpipe/en-US/phoneScreenshots/00.png" + ] + }, + "icon": "https://f-droid.org/repo/org.schabi.newpipe/en-US/icon_OHy4y1W-fJCNhHHOBCM9V_cxZNJJgbcNkB-x7UDTY9Q=.png" + }, + { + "id": "kart", + "package": "org.preview.kart", + "name": "SuperTuxKart", + "summary": "A little friendly competition. A lot of colorful chaos.", + "description": "A little friendly competition. A lot of colorful chaos.", + "developer": "SuperTuxKart Team", + "license": "GPL-3.0", + "free": true, + "downloadable": false, + "version": "1.6", + "version_code": 1, + "min_sdk": 26, + "abis": [ + "arm64-v8a" + ], + "vr": false, + "updated": "2026-09-22", + "size": 85000000, + "popularity": 60, + "images": { + "banner": "https://opengraph.githubassets.com/1/supertuxkart/stk-code", + "icon": null, + "screenshots": [ + "https://opengraph.githubassets.com/1/supertuxkart/stk-code" + ] + }, + "icon": null, + "page": "https://supertuxkart.net" + } +] diff --git a/tests/search_preview.py b/tests/search_preview.py index 3e0bf5a..cdd6bec 100644 --- a/tests/search_preview.py +++ b/tests/search_preview.py @@ -1,27 +1,58 @@ -"""Local demo server for UI checks; rejects every device endpoint. +"""Local store preview. No device access; installation progress is simulated. FRAME_APK_SEARCH_DEMO=1 python3 tests/search_preview.py """ +import json import os from pathlib import Path import sys +import tempfile +import time from urllib.parse import urlparse sys.path.insert(0, str(Path(__file__).resolve().parents[1] / 'ui')) import server +from apk_sources import _demo, _images, search class Preview(server.Handler): def do_GET(self): - if urlparse(self.path).path not in ('/', '/index.html', '/api/search', '/api/sources', '/api/job', '/api/host'): - self.send_json({'error': 'Device access disabled in search preview'}, 503) + path = urlparse(self.path).path + if path == '/api/android': + self.send_json({'apps': []}) + return + if path == '/api/android/reports': + self.send_json({'reports': [], 'shared': False}) + return + if path not in ('/', '/index.html', '/api/search', '/api/sources', '/api/sources/details', '/api/job', '/api/host') and not path.startswith('/source-image/'): + self.send_json({'error': 'Headset disconnected', 'offline': True}, 503) return super().do_GET() def do_POST(self): - self.send_json({'error': 'Writes disabled in search preview'}, 403) + if not self.local_request(): + return + if urlparse(self.path).path == '/api/sources/install': + body = json.loads(self.rfile.read(int(self.headers.get('Content-Length', 0)))) + def work(report): + for percent in (12, 28, 43, 67, 89): + report('Downloading', percent) + time.sleep(2) + report('Installing', None) + time.sleep(3) + return {'package': 'org.preview.' + body['id'], 'message': 'Preview installation complete'} + self.send_json(server.start_job('Preview installation', work, progress=True)) + return + if urlparse(self.path).path == '/api/sources': + super().do_POST() + return + self.send_json({'error': 'Device access disabled in store preview'}, 403) if __name__ == '__main__': if os.environ.get('FRAME_APK_SEARCH_DEMO') != '1': sys.exit('Set FRAME_APK_SEARCH_DEMO=1') - server.ThreadingHTTPServer(('127.0.0.1', 8795), Preview).serve_forever() + for name, url in json.loads((_demo.FIXTURES / 'artwork' / 'urls.json').read_text()).items(): + _images.remember(url, (_demo.FIXTURES / 'artwork' / name).read_bytes()) + with tempfile.TemporaryDirectory(prefix='frame-store-preview-') as tmp: + search.settings_path = lambda: Path(tmp) / 'enabled.json' + server.ThreadingHTTPServer(('127.0.0.1', 8795), Preview).serve_forever() diff --git a/tests/test_apk_artwork.py b/tests/test_apk_artwork.py new file mode 100644 index 0000000..b036f90 --- /dev/null +++ b/tests/test_apk_artwork.py @@ -0,0 +1,101 @@ +import http.client +import json +from pathlib import Path +import socket +import sys +import threading +import unittest +from unittest.mock import patch, Mock + +sys.path.insert(0, str(Path(__file__).resolve().parents[1] / 'ui')) +from apk_sources import _images, search, SourceError +import server + +PNG = (Path(__file__).parent / 'fixtures/apk-search/artwork/brush-icon.png').read_bytes() + + +class ArtworkTests(unittest.TestCase): + def setUp(self): + with _images._lock: + _images._urls.clear() + _images._cache.clear() + + def test_only_registered_source_images_are_fetchable(self): + with patch.object(_images, 'fetch') as fetch: + with self.assertRaisesRegex(SourceError, 'Unknown artwork'): + _images.image('https://example.com/arbitrary.png') + fetch.assert_not_called() + entry = {'images': {'icon': 'https://example.com/icon.png', 'banner': 'file:///tmp/private', + 'screenshots': ['https://example.com/shot.png', 'javascript:alert(1)']}} + art = _images.artwork(entry) + self.assertTrue(art['icon'].startswith('/source-image/')) + self.assertIsNone(art['banner']) + self.assertEqual(len(art['screenshots']), 1) + with patch.object(_images, 'fetch', return_value=(PNG, 'image/png')) as fetch: + self.assertEqual(_images.image(art['icon'].split('/')[-1]), (PNG, 'image/png')) + _images.image(art['icon'].split('/')[-1]) + fetch.assert_called_once_with('https://example.com/icon.png') + + def test_rejects_credentials_ports_and_non_http(self): + for url in ['file:///tmp/a.png', 'data:image/png;base64,AAAA', 'http://user:pass@example.com/a.png', + 'http://example.com:22/a.png', 'https://example.com:bad/a.png', '//example.com/a.png']: + self.assertIsNone(_images.register(url), url) + + def test_blocks_private_loopback_and_mixed_dns_answers(self): + for ip in ['127.0.0.1', '10.0.0.1', '169.254.169.254', '::1', '192.168.1.1']: + with patch.object(socket, 'getaddrinfo', return_value=[(2,1,6,'',(ip,443))]), \ + patch.object(socket, 'create_connection') as connect: + with self.assertRaisesRegex(SourceError, 'Private network'): + _images.fetch('https://example.com/private.png') + connect.assert_not_called() + + def test_redirect_to_private_network_is_rejected(self): + response = Mock(status=302) + response.getheader.return_value = 'http://127.0.0.1/secret' + conn = Mock() + conn.getresponse.return_value = response + public = [(2,1,6,'',('93.184.216.34',80))] + private = [(2,1,6,'',('127.0.0.1',80))] + with patch.object(socket, 'getaddrinfo', side_effect=[public,private]), \ + patch.object(socket, 'create_connection') as connect, \ + patch.object(http.client, 'HTTPConnection', return_value=conn): + with self.assertRaisesRegex(SourceError, 'Private network'): + _images.fetch('http://example.com/a.png') + connect.assert_called_once_with(('93.184.216.34',80),timeout=10) + + def test_non_images_and_oversized_images_are_rejected(self): + with self.assertRaises(SourceError): + _images.remember('https://example.com/a.svg', b'') + with self.assertRaisesRegex(SourceError, 'too large'): + _images.remember('https://example.com/a.png', PNG[:8] + b'x' * _images.MAX_IMAGE) + + def test_handles_are_bounded(self): + for i in range(4100): + _images.register('https://example.com/%d.png' % i) + self.assertEqual(len(_images._urls),4096) + + def test_plain_language_verdict_is_evidence_based(self): + self.assertEqual(search.verdict({})['label'], 'Not yet checked on the Frame') + self.assertEqual(search.verdict({'min_sdk':24,'abis':[]})['label'], 'Ready to try on the Frame') + self.assertEqual(search.verdict({'min_sdk':24,'abis':[],'frame_tested':True})['label'], 'Works on the Frame') + self.assertIn('newer Android', search.verdict({'min_sdk':31})['label']) + self.assertIn('Meta Quest services', search.verdict({'requires_meta_services':True})['label']) + self.assertEqual(search.verdict({'engine':'VrApi'})['tone'],'blocked') + self.assertNotEqual(search.verdict({'frame_tested':True,'min_sdk':31})['tone'],'works') + + def test_image_endpoint_does_not_allow_arbitrary_urls(self): + httpd = server.ThreadingHTTPServer(('127.0.0.1',0),server.Handler) + threading.Thread(target=httpd.serve_forever,daemon=True).start() + try: + path = _images.register('https://example.com/app.png') + _images.remember('https://example.com/app.png',PNG) + for url, expected in [(path,200),('/source-image/unknown',404)]: + c=http.client.HTTPConnection('127.0.0.1',httpd.server_port) + c.request('GET',url) + r=c.getresponse();data=r.read();c.close() + self.assertEqual(r.status,expected) + if expected==200: + self.assertEqual(data,PNG) + self.assertEqual(r.getheader('Content-Type'),'image/png') + finally: + httpd.shutdown();httpd.server_close() diff --git a/tests/test_apk_search.py b/tests/test_apk_search.py index 9775e07..d5c1389 100644 --- a/tests/test_apk_search.py +++ b/tests/test_apk_search.py @@ -181,6 +181,18 @@ class EndpointTests(SettingsTest): self.assertIsNone(job['error']) install.assert_called_once_with('/fake.apk', name='Open Brush', icon_png=None, source='one') + def test_details_endpoint_and_real_install_stages(self): + code, entry = self.request('GET', '/api/sources/details?source=one&id=brush') + self.assertEqual(code, 200) + self.assertEqual(entry['name'], 'Open Brush') + self.assertEqual(entry['verdict']['label'], 'Ready to try on the Frame') + self.assertIn('artwork', entry) + self.assertEqual(self.request('GET', '/api/sources/details?source=one')[0], 400) + stages = [] + with patch.object(server.frame_android, 'install', return_value={'package':'org.brush'}): + search.install('one', 'brush', progress=lambda stage, percent: stages.append((stage,percent))) + self.assertEqual(stages, [('Downloading',None),('Installing',None)]) + def test_http_repository_management(self): self.assertEqual(self.request('POST', '/api/sources', {'action': 'enable', 'source': 'one', 'enabled': False})[0], 200) code, reply = self.request('POST', '/api/sources', {'action': 'add', 'url': 'https://repo.example/repo'}) diff --git a/ui/apk_sources/_demo.py b/ui/apk_sources/_demo.py index 1080368..b83760a 100644 --- a/ui/apk_sources/_demo.py +++ b/ui/apk_sources/_demo.py @@ -1,29 +1,29 @@ -"""Opt-in local UI fixtures: FRAME_APK_SEARCH_DEMO=1. Never downloads.""" +"""Opt-in local store fixtures: FRAME_APK_SEARCH_DEMO=1. Never downloads.""" +import json +from pathlib import Path from apk_sources import SourceError KIND = 'demo' +FIXTURES = Path(__file__).resolve().parents[2] / 'tests' / 'fixtures' / 'apk-search' def sources(): - return [{'id': 'demo-' + key, 'kind': KIND, 'name': name + ' (demo)', 'enabled': True, + return [{'id': 'demo-' + key, 'kind': KIND, 'name': name, 'enabled': True, 'builtin': True, 'trust': trust, 'url': 'https://example.invalid'} - for key, name, trust in [('fdroid', 'F-Droid', 'community'), + for key, name, trust in [('github', 'GitHub', 'official'), ('fdroid', 'F-Droid', 'community'), ('sidequest', 'SideQuest', 'official'), ('itch', 'itch.io', 'community')]] def search(source, query, limit=50): if source['id'] == 'demo-itch': - raise SourceError('Demo: source temporarily unavailable') - entries = [{'id': 'brush', 'package': 'org.demo.brush', 'name': 'Open Brush', - 'summary': 'Paint in VR — demonstration listing only', 'version': '2.32', - 'version_code': 232, 'min_sdk': 29, 'abis': ['arm64-v8a'], 'vr': True, - 'engine': 'Unity OpenXR', 'size': 125000000, 'updated': '2026-09-25', - 'verified': source['id'] == 'demo-fdroid', 'free': True, 'downloadable': True}, - {'id': 'radio', 'package': 'org.demo.radio', 'name': 'Pocket Radio', - 'summary': 'Listen in a flat Android panel', 'version': '1.0', 'version_code': 1, - 'min_sdk': 24, 'abis': [], 'vr': False, 'size': 3000000, 'free': True, - 'downloadable': False, 'page': 'https://example.invalid/radio'}] - return [e for e in entries if query.lower() in e['name'].lower()][:limit] + raise SourceError('Source temporarily unavailable') + entries = json.loads((FIXTURES / 'store.json').read_text()) + if source['id'] == 'demo-sidequest': + entries = [e for e in entries if e['vr']] + if source['id'] == 'demo-fdroid': + entries = [e for e in entries if not e['vr']] + return [dict(e, verified=source['id'] in ('demo-github', 'demo-fdroid')) for e in entries + if query.lower() in (e['name'] + ' ' + e['summary']).lower()][:limit] def details(source, entry_id): @@ -31,4 +31,4 @@ def details(source, entry_id): def download(source, entry_id, version_code=None): - raise SourceError('Demo sources cannot download or install apps') + raise SourceError('Preview sources cannot download or install apps') diff --git a/ui/apk_sources/_images.py b/ui/apk_sources/_images.py new file mode 100644 index 0000000..df71483 --- /dev/null +++ b/ui/apk_sources/_images.py @@ -0,0 +1,122 @@ +"""Bounded artwork cache. Only source-provided URLs get opaque image handles.""" +from collections import OrderedDict +import http.client +import ipaddress +import secrets +import socket +import ssl +import threading +from urllib.parse import urljoin, urlsplit + +from apk_sources import SourceError + +_lock = threading.Lock() +_urls = OrderedDict() +_cache = OrderedDict() +MAX_IMAGE = 8 * 1024 * 1024 +MAX_CACHE = 64 * 1024 * 1024 + + +def valid_url(url): + try: + p = urlsplit(url) + return (p.scheme in ('https', 'http') and bool(p.hostname) and not p.username and not p.password + and p.port in (None, 80, 443) and len(url) <= 4096) + except (ValueError, TypeError): + return False + + +def register(url): + if not isinstance(url, str) or not valid_url(url): + return None + with _lock: + for token, known in _urls.items(): + if known == url: + _urls.move_to_end(token) + return '/source-image/' + token + token = secrets.token_urlsafe(24) + _urls[token] = url + while len(_urls) > 4096: + _urls.popitem(last=False) + return '/source-image/' + token + + +def artwork(entry): + images = entry.get('images') or {} + if not isinstance(images, dict): + images = {} + return {'icon': register(images.get('icon') or entry.get('icon')), + 'banner': register(images.get('banner')), + 'screenshots': [path for path in (register(u) for u in (images.get('screenshots') or [])[:12]) if path]} + + +def image_type(data): + if data.startswith(b'\x89PNG\r\n\x1a\n'): + return 'image/png' + if data.startswith(b'\xff\xd8\xff'): + return 'image/jpeg' + if data.startswith((b'GIF87a', b'GIF89a')): + return 'image/gif' + if data[:4] == b'RIFF' and data[8:12] == b'WEBP': + return 'image/webp' + raise SourceError('Artwork is not a supported image') + + +def fetch(url, redirects=3): + if not valid_url(url): + raise SourceError('Artwork URL is not allowed') + p = urlsplit(url) + port = p.port or (443 if p.scheme == 'https' else 80) + addresses = socket.getaddrinfo(p.hostname, port, type=socket.SOCK_STREAM) + if not addresses or any(not ipaddress.ip_address(a[4][0]).is_global for a in addresses): + raise SourceError('Private network artwork is not allowed') + # Connect to the checked IP, never resolve again between validation and use. + sock = socket.create_connection((addresses[0][4][0], port), timeout=10) + conn = http.client.HTTPConnection(p.hostname, port, timeout=10) + try: + if p.scheme == 'https': + sock = ssl.create_default_context().wrap_socket(sock, server_hostname=p.hostname) + conn.sock = sock + path = p.path or '/' + if p.query: + path += '?' + p.query + conn.request('GET', path, headers={'User-Agent': 'FrameControl/0.3.1', 'Accept': 'image/png,image/jpeg,image/webp,image/gif'}) + response = conn.getresponse() + if response.status in (301, 302, 303, 307, 308) and redirects: + target = urljoin(url, response.getheader('Location', '')) + conn.close() + return fetch(target, redirects - 1) + if response.status != 200: + raise SourceError('Artwork is unavailable') + data = response.read(MAX_IMAGE + 1) + if len(data) > MAX_IMAGE: + raise SourceError('Artwork is too large') + return data, image_type(data) + finally: + conn.close() + sock.close() + + +def remember(url, data): + value = (data, image_type(data)) + if len(data) > MAX_IMAGE: + raise SourceError('Artwork is too large') + with _lock: + _cache[url] = value + _cache.move_to_end(url) + while sum(len(v[0]) for v in _cache.values()) > MAX_CACHE: + _cache.popitem(last=False) + return value + + +def image(token): + with _lock: + url = _urls.get(token) + if not url: + raise SourceError('Unknown artwork') + cached = _cache.get(url) + if cached: + _cache.move_to_end(url) + return cached + data, _ = fetch(url) + return remember(url, data) diff --git a/ui/apk_sources/search.py b/ui/apk_sources/search.py index c4aeb93..d1f3d18 100644 --- a/ui/apk_sources/search.py +++ b/ui/apk_sources/search.py @@ -1,4 +1,9 @@ -"""Parallel APK search and source selection. No device access during searches.""" +"""Parallel APK search and source selection. No device access during searches. + +Optional store metadata: images {icon, banner, screenshots}, developer, +description, popularity, open_source, requires_meta_services, frame_tested. +Only an explicit frame_tested=True produces a working-on-Frame verdict. +""" import importlib import inspect import json @@ -127,6 +132,35 @@ def fit(entry): 'reasons': reasons} +def verdict(entry): + compatibility = fit(entry) + hints = ' '.join(str(entry.get(k) or '') for k in ('engine', 'vr_engine', 'vr_hints', 'vr_issues')).lower() + if entry.get('requires_meta_services') is True: + return {'label': "Needs Meta Quest services; won't run", 'tone': 'blocked'} + if entry.get('min_sdk') is not None and entry['min_sdk'] > 30: + return {'label': 'Might not work: needs a newer Android than the Frame has', 'tone': 'blocked'} + if compatibility['installable'] is False: + return {'label': "This version isn't made for the Frame", 'tone': 'blocked'} + if 'vrapi' in hints: + return {'label': "Made for older Quest headsets; won't run on the Frame", 'tone': 'blocked'} + if entry.get('frame_tested') is True: + return {'label': 'Works on the Frame', 'tone': 'works'} + if compatibility['installable'] is True: + return {'label': 'Ready to try on the Frame', 'tone': 'ready'} + return {'label': 'Not yet checked on the Frame', 'tone': 'unknown'} + + +def decorate(entry): + from apk_sources import _images + return dict(entry, fit=fit(entry), verdict=verdict(entry), artwork=_images.artwork(entry)) + + +def details(source_id, entry_id): + module, source = resolve(source_id) + return decorate(dict(module.details(source, entry_id), source=source_id, + source_name=source['name'], trust=source.get('trust'))) + + def offer_rank(entry): compatible = entry['fit']['installable'] is True return (entry.get('downloadable') is True and entry['fit']['installable'] is not False, @@ -139,7 +173,7 @@ def offer_rank(entry): def group(entries, query='', vr=None, installable=False): groups = {} for entry in entries: - entry = dict(entry, fit=fit(entry)) + entry = decorate(entry) if vr is not None and entry.get('vr') is not vr: continue if installable and entry['fit']['installable'] is not True: @@ -204,7 +238,7 @@ def search(query='', vr=None, source=None, installable=False, timeout=TIMEOUT, l return {'apps': group(entries, query, vr, installable), 'sources': statuses} -def install(source_id, entry_id, version_code=None): +def install(source_id, entry_id, version_code=None, progress=None): import frame_android module, source = resolve(source_id) if not source['enabled']: @@ -212,6 +246,8 @@ def install(source_id, entry_id, version_code=None): entry = module.details(source, entry_id) if entry.get('free') is not True or entry.get('downloadable') is not True: raise SourceError('This app must be obtained from its developer page') + if progress: + progress('Downloading', None) downloaded = module.download(source, entry_id, version_code=version_code) obb = downloaded.get('obb') or entry.get('obb') or [] if obb and not hasattr(frame_android, 'install_obb'): @@ -220,6 +256,8 @@ def install(source_id, entry_id, version_code=None): 'source': source['name']} if 'artwork' in inspect.signature(frame_android.install).parameters: kwargs['artwork'] = downloaded.get('artwork') or entry.get('artwork') + if progress: + progress('Installing', None) result = frame_android.install(downloaded['apk'], **kwargs) if obb: frame_android.install_obb(result['package'], obb) diff --git a/ui/index.html b/ui/index.html index 97b68e5..60796f6 100644 --- a/ui/index.html +++ b/ui/index.html @@ -70,15 +70,6 @@ body.mobile .desk-only { display: none; } - .source-repo-form { display:grid; gap:10px; margin-top:14px; } - .source-repo-form input { display:block; width:100%; margin-top:5px; } - .source-offer { border-top:1px solid var(--line); padding-top:10px; margin-top:10px; } - #searchGrid .source-offer select { display:block; max-width:100%; width:100%; margin-top:5px; } - #searchFilters [aria-pressed=true], #sourceFilters [aria-pressed=true] { box-shadow:inset 0 0 0 1px var(--link); color:var(--link); } - #searchGrid h3, #searchGrid p { margin:4px 0; } - #searchGrid .row { margin-top:0; } - #searchGrid .source-offer { margin-top:auto; } - #sourceStatus { margin-bottom:10px; } /* ---- pages: one per tab; the header nav switches between them ---- */ .page { display: flex; flex-direction: column; gap: 26px; } .page:not(.on) { display: none; } @@ -370,6 +361,155 @@ /* The on-screen keyboard covers the bottom of the screen; the tab bar would ride on top of it. */ body.typing nav { display: none; } } + /* ---- Discover: artwork first, details when you need them ---- */ + .sr-only { position:absolute; width:1px; height:1px; padding:0; overflow:hidden; clip:rect(0,0,0,0); white-space:nowrap; } + #androidLibrary { grid-template-columns:1fr; } + #androidLibrary .and-col { display:grid; grid-template-columns:repeat(auto-fit,minmax(min(100%,320px),1fr)); align-items:start; } + .store-tabs { display:flex; align-items:center; gap:8px; margin-bottom:20px; border-bottom:1px solid #ffffff12; padding-bottom:14px; } + .store-tabs > button { background:transparent; color:var(--muted); border-radius:6px; } + .store-tabs > button.on { color:var(--bright); background:#ffffff0e; } + .store-heading h1 { font-size:clamp(28px,3.2vw,38px); letter-spacing:-1.2px; line-height:1.15; margin:8px 0 10px; font-weight:700; color:var(--bright); } + .store-heading p, .sources-intro p { color:#a8b5c2; margin:0 0 24px; font-size:15px; } + .store-eyebrow { color:var(--link); font-size:11px; text-transform:uppercase; font-weight:700; letter-spacing:1.8px; } + .store-toolbar { display:grid; grid-template-columns:minmax(0,1fr) minmax(300px,400px); align-items:center; gap:32px; } + .store-toolbar .store-heading p { margin-bottom:0; } + @media(max-width:900px) { .store-toolbar { display:block; } .store-toolbar .store-heading p { margin-bottom:20px; } } + .store-search { display:flex; align-items:center; gap:12px; border:1px solid #ffffff12; background:#0e1723a6; border-radius:8px; padding:6px 8px 6px 16px; } + .store-search svg { width:21px; height:21px; color:var(--muted); flex:none; } + .store-search input[type=search] { background:transparent; padding:9px 0; font-size:15px; border:0; box-shadow:none; min-width:0; } + .store-search:focus-within { border-color:var(--link); } + .store-search button { border-radius:5px; } + .store-filters { display:flex; justify-content:space-between; align-items:center; gap:16px; margin:16px 0 24px; } + .store-chips { display:flex; flex-wrap:wrap; gap:7px; } + .store-chips button { border-radius:20px; font-size:12px; height:34px; padding:0 14px; background:#ffffff07; color:#b5c0cb; border:1px solid #ffffff0c; } + .store-chips button[aria-pressed=true] { background:#235779; border-color:#5287a5; color:white; } + .store-source-select select { max-width:180px; padding:8px 26px 8px 10px; font:inherit; font-size:12px; border:0; border-radius:5px; color:var(--text); background:#1d2b3b; } + .store-notice { color:#a8b5c2; font-size:12px; margin:12px 0; } + body:has(.page.on #appStore:not([hidden])) #offline { padding:10px 16px; background:#ffffff06; box-shadow:inset 3px 0 0 var(--dim); } + body:has(.page.on #appStore:not([hidden])) #offline .s { display:none; } + .store-result-count { font-size:13px; color:var(--muted); margin-bottom:14px; } + .store-result-count:empty { display:none; } + .store-hero { position:relative; display:block; width:100%; height:270px; border:0; padding:0; border-radius:12px; overflow:hidden; text-align:left; margin:0 0 32px; isolation:isolate; } + .store-art { position:relative; display:block; overflow:hidden; background:radial-gradient(ellipse at 75% 10%, hsl(var(--hue) 50% 40%),transparent 70%),linear-gradient(140deg,hsl(var(--hue) 35% 18%),#101827); } + .store-art > img { position:absolute; inset:0; width:100%; height:100%; object-fit:cover; z-index:1; } + .art-initial { position:absolute; inset:0; display:flex; align-items:center; justify-content:center; font-size:70px; font-weight:700; color:#ffffff45; letter-spacing:-4px; } + .store-hero > .store-art { position:absolute; inset:0; } + .store-hero::after { content:""; position:absolute; inset:0; background:linear-gradient(90deg,#081421ec 0%,#08142175 48%,#08142108 80%),linear-gradient(0deg,#08142170,transparent); z-index:2; } + .hero-copy { position:relative; z-index:3; padding:30px; max-width:550px; display:flex; align-items:flex-start; flex-direction:column; gap:12px; } + .hero-copy .store-eyebrow { color:#c2e7ff; } + .hero-copy strong { color:white; font-size:38px; letter-spacing:-.8px; line-height:1.1; } + .hero-copy > span:not(.store-eyebrow):not(.hero-cta) { color:#e0e8ef; font-size:16px; font-weight:400; max-width:380px; line-height:1.6; } + .hero-cta { color:white; display:inline-flex; align-items:center; background:#ffffff20; border:1px solid #ffffff40; border-radius:6px; padding:10px 18px; font-size:13px; margin-top:6px; } + .store-row { margin-bottom:34px; } + .store-row-head { display:flex; align-items:baseline; gap:12px; margin-bottom:14px; } + .store-row-head h2 { text-transform:none; letter-spacing:-.3px; font-size:21px; font-weight:600; color:var(--bright); margin:0; } + .store-row-head p { color:var(--muted); font-size:12px; margin:0; } + .store-grid { display:grid; grid-template-columns:repeat(auto-fill,minmax(225px,1fr)); gap:18px; } + .store-card { display:block; width:100%; height:auto; min-width:0; padding:0; border:1px solid #ffffff0b; border-radius:9px; overflow:hidden; text-align:left; background:#1b2938; color:var(--text); transition:transform .18s,box-shadow .18s; font-weight:400; } + .store-card:hover { transform:translateY(-4px); background:#223448; box-shadow:0 12px 28px #0004; } + .store-card .store-art { aspect-ratio:16/9; width:100%; } + .store-card-content { padding:15px 14px; display:block; } + .store-card-title { display:flex; align-items:center; gap:9px; margin-bottom:9px; min-width:0; } + .store-icon { display:inline-flex; align-items:center; justify-content:center; width:34px; height:34px; border-radius:8px; overflow:hidden; flex:none; background:hsl(var(--hue) 35% 28%); color:#fff; font-size:17px; position:relative; } + .store-icon img { position:absolute; inset:0; width:100%; height:100%; object-fit:cover; } + .store-card-title strong { font-size:15px; color:var(--bright); text-overflow:ellipsis; overflow:hidden; white-space:nowrap; } + .store-summary { display:block; color:#a8b5c2; font-size:12px; white-space:nowrap; overflow:hidden; text-overflow:ellipsis; } + .store-card-foot { display:flex; justify-content:space-between; align-items:center; gap:6px; margin-top:16px; font-size:11px; color:#a8b5c2; } + .store-card-foot b { color:#dbeecf; font-weight:500; } + .store-badges { display:flex; flex-wrap:wrap; gap:7px; } + .store-badge { font-size:11px; color:#b7d8ec; background:#6ec9ff14; padding:4px 9px; border-radius:5px; } + .store-badge.works { color:#b8e2ab; background:#70bb5418; } + .store-empty { display:flex; flex-direction:column; align-items:center; text-align:center; padding:58px 20px 70px; } + .store-empty svg { width:110px; height:90px; color:var(--link); margin-bottom:14px; } + .store-empty h2 { font-size:23px; color:var(--bright); margin:8px 0; text-transform:none; letter-spacing:0; } + .store-empty p { max-width:390px; color:var(--muted); margin:0 0 22px; } + .store-skeleton { aspect-ratio:1.2; background:linear-gradient(110deg,#233446 30%,#30455b 45%,#233446 60%); background-size:250% 100%; border-radius:9px; animation:store-shimmer 1.8s ease infinite; } + @keyframes store-shimmer { to { background-position:-150% 0; } } + .store-dialog { padding:0; border:1px solid #ffffff1a; border-radius:14px; background:#172331; color:var(--text); width:min(980px,calc(100vw - 40px)); max-width:none; max-height:calc(100dvh - 48px); overflow:auto; box-shadow:0 30px 100px #0009; } + .store-dialog::backdrop { background:#030a13c9; backdrop-filter:blur(7px); } + .store-close { position:sticky; float:right; top:14px; margin:14px 14px -54px 0; z-index:6; height:36px; width:36px; padding:0; border-radius:50%; background:#09131dcc; color:white; font-size:25px; line-height:1; border:1px solid #ffffff30; } + .detail-banner { height:195px; } + .detail-banner::after { content:""; position:absolute; inset:0; z-index:2; background:linear-gradient(0deg,#172331,transparent 70%); } + .detail-content { padding:0 30px 30px; position:relative; } + .detail-heading { display:flex; gap:16px; align-items:center; margin-top:-24px; position:relative; z-index:3; } + .detail-heading .store-icon { width:70px; height:70px; border-radius:15px; box-shadow:0 3px 18px #0004; font-size:32px; } + .detail-heading h1 { font-size:30px; color:white; letter-spacing:-.7px; margin:0 0 4px; } + .detail-heading p { margin:0; color:#a8b5c2; font-size:13px; } + .detail-content > .store-badges { margin:20px 0; } + .detail-layout { display:grid; grid-template-columns:minmax(0,1fr) 290px; gap:30px; margin-top:22px; } + .detail-layout h2 { text-transform:none; letter-spacing:0; font-size:17px; color:white; margin:0 0 14px; } + .detail-description { color:#b5c2ce; font-size:14px; line-height:1.75; white-space:pre-line; } + .detail-gallery { display:flex; gap:10px; overflow-x:auto; scroll-snap-type:x mandatory; margin:0 0 10px; } + .detail-gallery .store-art { flex:0 0 86%; aspect-ratio:16/9; border-radius:7px; scroll-snap-align:start; } + .detail-gallery .store-art img { object-fit:contain; background:#0b1420; } + .gallery-controls { display:flex; justify-content:space-between; align-items:center; margin-bottom:24px; font-size:11px; color:var(--muted); } + .gallery-controls button { height:30px; width:34px; padding:0; border-radius:5px; } + .detail-buy { align-self:start; background:#0e1926; padding:18px; border:1px solid #ffffff0a; border-radius:10px; } + .detail-buy .store-primary { width:100%; min-height:46px; border-radius:7px; margin:8px 0; font-size:15px; } + .detail-verdict { color:#b6d6a8; font-size:12px; line-height:1.55; margin:0 0 15px; } + .detail-verdict.blocked { color:#e3b77a; } + .detail-verdict.unknown { color:#adbac7; } + .detail-price { font-size:23px; color:white; font-weight:600; } + .detail-small { font-size:11px; color:var(--muted); margin:4px 0 18px; } + .offer-choice { display:flex; align-items:flex-start; gap:9px; padding:11px 9px; margin-top:8px; border:1px solid #ffffff12; border-radius:7px; cursor:pointer; } + .offer-choice:has(input:checked) { background:#1e3c52; border-color:#5386a6; } + .offer-choice input { margin:4px 0 0; accent-color:var(--blue); } + .offer-choice strong { font-size:12px; display:block; color:var(--bright); } + .offer-choice small { display:block; font-size:10px; color:#a8bbc9; margin-top:4px; } + .offer-mark { display:inline-flex; justify-content:center; align-items:center; height:26px; width:26px; flex:none; border-radius:6px; background:hsl(var(--hue) 30% 30%); color:white; font-size:11px; } + .detail-technical { border-top:1px solid #ffffff14; margin-top:25px; padding-top:16px; font-size:12px; color:var(--muted); } + .detail-technical summary { cursor:pointer; } + .detail-technical dl { display:grid; grid-template-columns:110px minmax(0,1fr); gap:6px; } + .detail-technical dd { margin:0; overflow-wrap:anywhere; } + .detail-buy .store-primary:disabled { opacity:1; color:#d6e8f7; background:#274f71; cursor:default; } + #detailProgress::-webkit-progress-bar { background:#283b4d; border-radius:3px; } + #detailProgress::-webkit-progress-value { background:var(--blue); border-radius:3px; } + #detailProgress { height:4px; width:100%; accent-color:var(--blue); display:block; margin-bottom:10px; } + .sources-dialog { width:min(560px,calc(100vw - 32px)); padding:30px; } + .sources-dialog .store-close { margin:-16px -16px -20px 0; top:0; } + .sources-intro h1 { font-size:28px; color:white; letter-spacing:-.7px; margin:9px 0; } + .source-setting { display:flex; align-items:center; gap:13px; padding:17px 0; border-top:1px solid #ffffff0c; } + .source-setting .offer-mark { width:42px; height:42px; font-size:16px; border-radius:10px; } + .source-setting .grow { flex:1; min-width:0; } + .store-dialog a { color:var(--link); } + .source-setting strong { display:block; font-size:14px; color:white; } + .source-setting p { color:#a3b4c3; font-size:12px; margin:3px 0; } + .source-setting small { color:var(--muted); font-size:10px; } + .source-toggle { appearance:none; width:38px; height:23px; flex:none; border-radius:15px; background:#465463; position:relative; cursor:pointer; margin:0; } + .source-toggle::after { content:""; position:absolute; top:3px; left:3px; width:17px; height:17px; background:#fff; border-radius:50%; transition:transform .15s; } + .source-toggle:checked { background:#208dca; } + .source-toggle:checked::after { transform:translateX(15px); } + .source-repo-form { display:grid; gap:12px; border-top:1px solid #ffffff14; margin-top:10px; padding-top:24px; } + .source-repo-form h2 { font-size:19px; letter-spacing:0; text-transform:none; color:white; margin:0; } + .source-repo-form p { color:var(--muted); font-size:12px; margin:0; } + .source-repo-form label { font-size:12px; } + .source-repo-form input { margin-top:7px; display:block; border-radius:6px; } + .source-repo-form details { font-size:11px; color:var(--muted); } + .source-repo-form button { justify-self:start; border-radius:6px; } + #appStore :focus-visible, .store-dialog :focus-visible, .store-tabs :focus-visible { outline:2px solid var(--link); outline-offset:4px; } + .store-search input:focus-visible { outline:0!important; } + @media(min-width:1400px) { .store-grid { grid-template-columns:repeat(5,minmax(0,1fr)); } } + @media(max-width:1000px) { .store-grid { grid-template-columns:repeat(3,minmax(0,1fr)); } .detail-layout { grid-template-columns:minmax(0,1fr) 260px; gap:20px; } } + @media(max-width:680px) { + .store-grid { grid-template-columns:repeat(2,minmax(0,1fr)); gap:12px; } + .store-tabs { margin-bottom:24px; gap:2px; } .store-tabs button { padding:0 10px; font-size:12px; } + .store-heading p { font-size:13px; max-width:320px; } + .store-filters { align-items:flex-start; flex-direction:column; gap:10px; margin-bottom:18px; } + .store-chips { gap:5px; } .store-chips button { font-size:11px; padding:0 10px; } + .store-hero { height:285px; border-radius:9px; margin-bottom:26px; } + .hero-copy { padding:26px 22px; } .hero-copy strong { font-size:29px; } + .hero-copy > span:not(.store-eyebrow):not(.hero-cta) { font-size:13px; max-width:260px; } + .store-row-head { display:block; } .store-row-head h2 { font-size:18px; } .store-row-head p { margin-top:3px; } + .store-card-content { padding:10px; } .store-card-title { gap:6px; } .store-card-title strong { font-size:13px; } + .store-card-title .store-icon { width:25px; height:25px; font-size:12px; border-radius:6px; } + .store-card-foot { font-size:10px; margin-top:12px; } .store-summary { font-size:11px; } + .store-dialog { width:calc(100vw - 16px); max-height:calc(100dvh - 20px); border-radius:10px; } + .detail-banner { height:190px; } .detail-content { padding:0 18px 24px; } .detail-heading h1 { font-size:24px; } + .detail-layout { display:flex; flex-direction:column; gap:24px; } .detail-buy { order:-1; width:100%; } + .sources-dialog { padding:24px; } .sources-dialog .store-close { margin:-12px -12px -20px 0; } + } + @media(prefers-reduced-motion:reduce) { html { scroll-behavior:auto; } .store-card, .source-toggle::after { transition:none; } .store-skeleton { animation:none; } } + @@ -530,9 +670,16 @@
-

Android apps

-
-
+
+
+
A little more possibility

Find your next favorite.

Great games and useful apps. All in one place, all free to explore.

+
+
+ +
+
+
+ -
-

Find apps

-
-
-
-
-
-
Sources -
-
- - - -
-
-
Installable means Android 11 and arm64 requirements match. It does not guarantee the app runs. Unknown facts stay unknown.
+