Expand description
Signing in from a window: how the page the application wants opened reaches QCode, and the window of last resort it can be shown in inside the container.
An application in a container asks the desktop to open a web address the way every Linux
program does, by running xdg-open. Inside a container that is nobody: there is no browser,
and until this was measured there was not even an xdg-open, so the call returned success and
did nothing at all — the person pressed “sign in” and the machine stayed silent.
So the image carries xdg-utils and a program of QCode’s own, and the container is told
through BROWSER to use it. That program writes the address into a folder the window’s
container shares with QCode, and nothing else: the folder is the workspace’s own, and the only
thing that travels through it is a line of text.
QCode opens the page in the person’s own browser, and carries the sign-in’s way back to the
application’s localhost inside the container: that is super::callback.
It showed the page inside the container first, in a small browser window of its own, so that
the localhost the sign-in returns to was the application’s without anything carried. Google
refuses that window: “Couldn’t sign you in — This browser or app may not be secure.” It stays
in the image as the window of last resort, which the person can ask for from the tab, for a
sign-in that is not Google’s or for the day Google lets it through.
That window costs the image next to nothing: it is the application’s own Electron — a whole
Chromium — started with a twenty-line program of QCode’s instead of the application’s. Electron
finds the program to run beside the executable it was started as, and resolves a symbolic link
to the real file first, which opened the editor itself when that was tried; a hard link is a
file of its own name and keeps BROWSER_DIR as the place Electron looks. The links are made
in the same build step that unpacks the archive, which is what keeps them free: made in a step
of their own, the layer copies the 200 MB executable.
The address is written to a temporary name and moved into place, so QCode never reads half a
line; and every address QCode takes is removed as it is read, so a folder left behind cannot
open yesterday’s page tomorrow. Only an http or https address is shown at all; everything
else is said on the tab instead.
Constants§
- BROWSER_
DIR - Where the sign-in window’s browser lives in the image: hard links to the application’s own Electron and its files, beside a program of QCode’s own.
- BROWSER_
MAIN - The browser itself: one window, showing the address it was started with.
- BROWSER_
PACKAGE - What Electron reads first: the program’s name, which is also the folder its cookies are kept
in under
~/.config, and the file it starts. - BROWSER_
PROGRAM - The browser’s executable, a hard link to the application’s.
- NO_
BROWSER - What an exec into the window’s container answers when its image has no sign-in window.
- OPEN_
DIR - The folder the window’s container writes addresses into, seen from inside that container.
- OPEN_
PROGRAM - The program the container runs to open an address, seen from inside the container.
- SCRIPT
- The program the image installs at
OPEN_PROGRAM.
Functions§
- browser_
install - The commands that put the sign-in window’s browser into an image, given the folder the application was unpacked into and its executable’s name there. They belong in the very build step that unpacks it, after the unpacking, so that every link costs nothing.
- is_web
- Whether an address is one QCode will hand a browser.
- opener_
step - The build step that puts
OPEN_PROGRAMinto an image, with the folder it writes into made in the image so that a container given nothing there still has it. It runs as root. - page_
command - The command, run inside the window’s container, that shows
addressin the sign-in window, started with the application’s ownflagsso that it reaches the same compositor the same way. - script
- The script with its folder filled in, ready to be written into an image.
- taken
- Takes every address waiting in
folder, oldest first, and removes each one as it is taken. - written
- The shell line that writes
contentstopath, for a build step.