Skip to main content

Module signin

Module signin 

Source
Expand description

Signing in from a window: how the page the application wants opened reaches QCode, and the window of last resort it can be shown in inside the container.

An application in a container asks the desktop to open a web address the way every Linux program does, by running xdg-open. Inside a container that is nobody: there is no browser, and until this was measured there was not even an xdg-open, so the call returned success and did nothing at all — the person pressed “sign in” and the machine stayed silent.

So the image carries xdg-utils and a program of QCode’s own, and the container is told through BROWSER to use it. That program writes the address into a folder the window’s container shares with QCode, and nothing else: the folder is the workspace’s own, and the only thing that travels through it is a line of text.

QCode opens the page in the person’s own browser, and carries the sign-in’s way back to the application’s localhost inside the container: that is super::callback.

It showed the page inside the container first, in a small browser window of its own, so that the localhost the sign-in returns to was the application’s without anything carried. Google refuses that window: “Couldn’t sign you in — This browser or app may not be secure.” It stays in the image as the window of last resort, which the person can ask for from the tab, for a sign-in that is not Google’s or for the day Google lets it through.

That window costs the image next to nothing: it is the application’s own Electron — a whole Chromium — started with a twenty-line program of QCode’s instead of the application’s. Electron finds the program to run beside the executable it was started as, and resolves a symbolic link to the real file first, which opened the editor itself when that was tried; a hard link is a file of its own name and keeps BROWSER_DIR as the place Electron looks. The links are made in the same build step that unpacks the archive, which is what keeps them free: made in a step of their own, the layer copies the 200 MB executable.

The address is written to a temporary name and moved into place, so QCode never reads half a line; and every address QCode takes is removed as it is read, so a folder left behind cannot open yesterday’s page tomorrow. Only an http or https address is shown at all; everything else is said on the tab instead.

Constants§

BROWSER_DIR
Where the sign-in window’s browser lives in the image: hard links to the application’s own Electron and its files, beside a program of QCode’s own.
BROWSER_MAIN
The browser itself: one window, showing the address it was started with.
BROWSER_PACKAGE
What Electron reads first: the program’s name, which is also the folder its cookies are kept in under ~/.config, and the file it starts.
BROWSER_PROGRAM
The browser’s executable, a hard link to the application’s.
NO_BROWSER
What an exec into the window’s container answers when its image has no sign-in window.
OPEN_DIR
The folder the window’s container writes addresses into, seen from inside that container.
OPEN_PROGRAM
The program the container runs to open an address, seen from inside the container.
SCRIPT
The program the image installs at OPEN_PROGRAM.

Functions§

browser_install
The commands that put the sign-in window’s browser into an image, given the folder the application was unpacked into and its executable’s name there. They belong in the very build step that unpacks it, after the unpacking, so that every link costs nothing.
is_web
Whether an address is one QCode will hand a browser.
opener_step
The build step that puts OPEN_PROGRAM into an image, with the folder it writes into made in the image so that a container given nothing there still has it. It runs as root.
page_command
The command, run inside the window’s container, that shows address in the sign-in window, started with the application’s own flags so that it reaches the same compositor the same way.
script
The script with its folder filled in, ready to be written into an image.
taken
Takes every address waiting in folder, oldest first, and removes each one as it is taken.
written
The shell line that writes contents to path, for a build step.