mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 06:00:33 +02:00
Store: add repositories in a background job and show the TOFU fingerprint
Adding a repository downloads and verifies its whole index, so it now runs as a job (runJob in the UI) and reports 'Trusted on first use: <fingerprint>' when no pin was given. fdroidrepos:// links pass the server check, as documented. Jobs report SourceError messages without a 'SourceError:' prefix. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
ddcf3b2ad2
commit
a9d78679ec
5 files changed
+62
-13
No files matched your search
+4
-2
@@ -53,8 +53,10 @@ Adding fetches and validates the complete index **before saving** the source.
|
||||
Without a fingerprint, Frame Control verifies the JAR signature and remembers
|
||||
its signer: trust on first use (TOFU). This establishes continuity with the
|
||||
first server response, not independent publisher identity. Obtain the published
|
||||
fingerprint through a trusted channel when possible. Re-adding an existing URL
|
||||
preserves its pin; changing it requires deliberately removing and re-adding it.
|
||||
fingerprint through a trusted channel when possible; the store's Add a source
|
||||
form shows the pinned one ("Trusted on first use: …") so you can compare it.
|
||||
Re-adding an existing URL preserves its pin; changing it requires deliberately
|
||||
removing and re-adding it.
|
||||
|
||||
The API for the search/server integration is in `ui/apk_sources/fdroid.py`:
|
||||
`add_repo(url, fingerprint=None, name=None)`, `remove_repo(source_id)`,
|
||||
|
||||
Reference in new issue
Block a user