Re-gate auto-update to Base+Premium now that paid activation works end-to-end (absorbs #271), and align the Rust entitlement layer with the TS matrix shipped in #297: - FEATURE_TIERS: auto-update -> [base, premium]; the 'temporarily open' carve-out and its test are gone (free_allows_auto_update_temporarily -> free_denied_auto_update). Dead rows web-sync, cloud-backup and advanced-reports are purged (no call-site anywhere; advanced-reports -> Premium contradicted the TS reports-advanced -> Base+ matrix). Only auto-update remains on the Rust side. - features[] override, fail-closed in Free (CWE-863): new current_entitlements() resolves the edition AND the signed features[] through the same machine-binding path — every downgrade path returns ('free', []) so a copied license.key can never keep its signed features. check_entitlement combines them via the new pure is_entitled(): is_feature_allowed(feature, edition) || features.contains(feature), with a defense-in-depth free short-circuit mirroring the TS isEntitled. current_edition() now delegates to current_entitlements() — single resolution path, no drift possible. - dev-override: new Cargo feature (off by default, never in a release feature set — CWE-489: debug_assertions could be flipped on a custom release build and become a Premium backdoor). Only when compiled in, SR_DEV_EDITION forces the edition (free|base|premium) to test tiers locally. A feature-off test proves the env var has zero effect in normal builds; feature-on companions (env access serialized by a mutex) cover cargo test --features dev-override. No Tauri command signature changes: check_entitlement keeps its (feature: String) -> Result<bool, String> contract for useUpdater.ts and ErrorPage.tsx. Validation: cargo check + cargo test (106 passed, feature off) + cargo test --features dev-override + npm test (871) + npm run build. Resolves #301 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
78 lines
3.1 KiB
TOML
78 lines
3.1 KiB
TOML
[package]
|
|
name = "simpl-result"
|
|
version = "0.14.0"
|
|
description = "Personal finance management app"
|
|
license = "GPL-3.0-only"
|
|
authors = ["you"]
|
|
edition = "2021"
|
|
|
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
|
|
|
[lib]
|
|
# The `_lib` suffix may seem redundant but it is necessary
|
|
# to make the lib name unique and wouldn't conflict with the bin name.
|
|
# This seems to be only an issue on Windows, see https://github.com/rust-lang/cargo/issues/8519
|
|
name = "simpl_result_lib"
|
|
crate-type = ["staticlib", "cdylib", "rlib"]
|
|
|
|
[build-dependencies]
|
|
tauri-build = { version = "2", features = [] }
|
|
|
|
[dependencies]
|
|
tauri = { version = "2", features = [] }
|
|
tauri-plugin-opener = "2"
|
|
tauri-plugin-sql = { version = "2", features = ["sqlite"] }
|
|
tauri-plugin-dialog = "2"
|
|
tauri-plugin-updater = "2"
|
|
tauri-plugin-process = "2"
|
|
tauri-plugin-deep-link = "2"
|
|
tauri-plugin-single-instance = { version = "2", features = ["deep-link"] }
|
|
libsqlite3-sys = { version = "0.30", features = ["bundled"] }
|
|
rusqlite = { version = "0.32", features = ["bundled"] }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
sha2 = "0.10"
|
|
encoding_rs = "0.8"
|
|
walkdir = "2"
|
|
aes-gcm = "0.10"
|
|
argon2 = "0.5"
|
|
subtle = "2"
|
|
rand = "0.8"
|
|
jsonwebtoken = "9"
|
|
machine-uid = "0.5"
|
|
reqwest = { version = "0.12", features = ["json"] }
|
|
# Date arithmetic for the Modified Dietz return calculator (Issue #142):
|
|
# we need day-precision diffs to weight cash flows W_i = (T - t_i) / T.
|
|
# `serde` feature lets `NaiveDate` cross the Tauri command boundary in JSON.
|
|
chrono = { version = "0.4", default-features = false, features = ["serde", "std"] }
|
|
tokio = { version = "1", features = ["macros"] }
|
|
hostname = "0.4"
|
|
urlencoding = "2"
|
|
base64 = "0.22"
|
|
# OAuth token storage in OS keychain (Credential Manager on Windows,
|
|
# Secret Service on Linux). We use sync-secret-service to get sync
|
|
# methods that are safe to call from async Tauri commands without
|
|
# tokio runtime entanglement. Requires libdbus-1-dev at build time
|
|
# on Linux (libdbus-1-3 is present on every desktop Linux at runtime).
|
|
keyring = { version = "3.6", default-features = false, features = ["sync-secret-service", "crypto-rust", "windows-native"] }
|
|
zeroize = "1"
|
|
hmac = "0.12"
|
|
|
|
[dev-dependencies]
|
|
# Used in license_commands.rs tests to sign test JWTs. We avoid the `pem`
|
|
# feature because the `LineEnding` re-export path varies between versions
|
|
# of pkcs8/spki; building the PKCS#8 DER manually is stable and trivial
|
|
# for Ed25519.
|
|
ed25519-dalek = { version = "2", features = ["pkcs8", "rand_core"] }
|
|
# HTTP mock server for balance_commands fetch_price tests (Issue #155).
|
|
mockito = "1.6"
|
|
|
|
[features]
|
|
# Dev-only escape hatch: when enabled, the SR_DEV_EDITION env var forces the
|
|
# resolved edition (free|base|premium) so the three license tiers can be tested
|
|
# without real license files. MUST stay out of `default` and of any release
|
|
# feature set — gating this on debug_assertions instead would let a custom
|
|
# release build honor the env var and become a Premium backdoor (CWE-489).
|
|
# Usage: cargo test --features dev-override, or `tauri dev` with
|
|
# `-- --features dev-override`.
|
|
dev-override = []
|