diff --git a/Makefile b/Makefile
index c8d6ba8..83f9ab7 100644
--- a/Makefile
+++ b/Makefile
@@ -36,7 +36,7 @@ BUILDER_ARGS := $(if $(STORES_API),-- --config.extraMetadata.warpEngine.registry
.DEFAULT_GOAL := help
-.PHONY: help setup node-check build typecheck lint lint-fix check start smoke uitest test \
+.PHONY: help setup node-check build typecheck lint lint-fix check start smoke uitest storetest test \
dist dist-mac dist-win dist-linux release publish clean distclean version
help: ## List available targets
@@ -72,7 +72,7 @@ lint-fix: ## Lint and fix what can be fixed automatically
# The order is deliberate: a type error explains a lint error, and both explain a
# failing test, so the cheapest check that can fail runs first.
-check: typecheck lint test ## Type-check, lint, and run both test suites
+check: typecheck lint test ## Type-check, lint, and run every test suite
start: ## Run the app against whatever store is installed
npm start
@@ -83,7 +83,10 @@ smoke: ## Drive the store bridge with no window at all
uitest: ## Load the window once and report what rendered
npm run uitest
-test: smoke uitest ## Both checks
+storetest: ## Add and remove a store in a sandbox (the only code that deletes a tree)
+ npm run storetest
+
+test: smoke storetest uitest ## All three checks
dist: node-check ## Package for this machine
npm run dist $(BUILDER_ARGS)
diff --git a/README.md b/README.md
index f47f469..2ba71e1 100644
--- a/README.md
+++ b/README.md
@@ -159,11 +159,16 @@ Everything that is not a title lives in the **side menu** on the left, and the
another switches to it: the grid, the categories and the folders all follow, and
the client reopens on that store next time. Two stores installed from the same
catalog into different folders show their folder instead of their id, because
- the id would not tell them apart. **Add a store…** brings up the registry
- picker, the same one the first run offers.
+ the id would not tell them apart. Hovering a row shows a **bin**, which takes that
+ store off the machine — see below.
+- **+**, beside Refresh, brings up the picker: the stores the registry offers, and a
+ field for **any catalog address of your own**. A bare host is enough (`https` is
+ assumed) and the name is taken from it. This is the same screen the first run shows,
+ so a machine with no store yet can also start from a typed address rather than only
+ from the list.
- **Account** appears only where the catalog offers a sign-in, and holds *Sign in…* or
*Sign out* — see above.
-- **Actions** holds **Refresh**, which re-reads the catalog. Titles are installed
+- **Actions** holds **Refresh**, which re-reads the catalog, and **+** to add one. Titles are installed
one at a time from their own cards; there is no install-everything button.
- **Categories** narrows the grid, one category at a time, with the count next to
each: *Everything*, *Installed*, *Updates*, *Not installed*, then a row per
@@ -202,6 +207,13 @@ While the store is working, only the things that would start a second call are
disabled: the menu, the log drawer and the category filters keep working, because
they change what is on screen and nothing on disk.
+**Removing a store uninstalls what it installed.** The bin on a store row asks first,
+and says how many titles will go with it. That is not a convenience — a store's
+`state.json` is the only record of which payloads, icons and menu entries belong to it,
+so leaving the games behind would leave orphans nothing could ever identify, least of
+all a later install of the same store into the same folder. The catalog cache, the
+settings and any sign-in token go too.
+
Anything installed from the window is a normal menu entry, so it also shows up in
your launcher, Dock or Start menu — the app does not have to be running to play.
@@ -216,9 +228,10 @@ names. `make` on its own lists everything.
| `make build` | compile TypeScript, bundle the preload and the renderer |
| `make typecheck` | type-check everything, emitting nothing |
| `make lint` | the strict rule set (`lint-fix` fixes what it can) |
-| `make check` | **typecheck, lint and both test suites** — the gate |
+| `make check` | **typecheck, lint and every test suite** — the gate |
| `make start` | run the app against whatever store is installed |
| `make smoke` | drive the store with no window and no Electron at all |
+| `make storetest` | add and remove a store in a sandbox — the only code that deletes a tree |
| `SMOKE_HOME=
SMOKE_TOKEN= npm run smoke` | the same, against a sandbox store and as a signed-in person |
| `make uitest` | load the window once and report what rendered |
| `SELFTEST_SHOT=shot.png npm run uitest` | the same, and the window photographs itself into that file |
@@ -340,14 +353,19 @@ own runtime.
single-instance lock. Otherwise a copy the user already has open swallows the test
process, which exits 0 and reads as a pass.
-Both test scripts accept a sandbox store instead of the real one, which is how
-this repository is tested without touching a working installation:
+The test scripts accept a sandbox store instead of the real one, which is how this
+repository is tested without touching a working installation:
```sh
STORE_ROOT=/tmp/sandbox-root npm start
SMOKE_HOME=/tmp/sandbox-root/ttg-desktop npm run smoke
```
+**`STORE_ROOT` replaces the search path rather than being added to the front of it.**
+It used to prepend, so a "sandboxed" run still listed the real stores and could switch
+to one; now that a store can also be *removed*, a sandbox that can reach a working
+installation is not a sandbox. `make storetest` relies on this.
+
### How it is put together
TypeScript, in layers, with the dependency rule pointing inward. **[STRUCTURE.md](STRUCTURE.md)
diff --git a/RELEASE_NOTES.md b/RELEASE_NOTES.md
index bff65b5..81e433d 100644
--- a/RELEASE_NOTES.md
+++ b/RELEASE_NOTES.md
@@ -1,34 +1,30 @@
-# WarpEngine Client 2.4.0
+# WarpEngine Client 2.5.0
-**The catalog can now say a title is not yours, and the client can do something about
-it.** Where a store sells things, a card shows the **price** and a **Buy** button that
-opens the store's own page; where you own it, an **Install** as before. Two new
-categories go with it — **Owned** and **To buy** — because owning something is not the
-same as having installed it.
+**A store can be taken off the machine again.** Hovering a store in the side menu shows
+a bin. It asks first, and says how many titles will go with it — because removing a
+store *uninstalls what it installed*. That is not a convenience: a store's `state.json`
+is the only record of which payloads, icons and menu entries belong to it, so leaving
+the games behind would leave orphans nothing could ever identify, least of all a later
+install of the same store into the same folder. The catalog cache, the settings and any
+sign-in token go too.
-**Signing in, without a password ever reaching this window.** The side menu grows an
-**Account** block, and signing in shows a short code: your browser opens on the store's
-own page and you type it there. That detour is the point — a desktop application asking
-for a password is a desktop application people should not be giving one to. The token
-lives in the OS keychain (Keychain, libsecret, DPAPI), one per store, and *Sign out*
-revokes it at the server as well as forgetting it here.
+**Adding one moved to a + beside Refresh**, and it now takes a catalog address of your
+own as well as the ones the registry lists. A bare host is enough — `https` is assumed —
+and the name is taken from the address. Both are actions on the whole store rather than
+on one of them, which is why they sit together; the full-width "Add a store…" button
+under the list read as a third store.
-**None of this is knowledge about any particular store.** It all arrives from the
-catalog's own server: WarpEngine 0.5 answers `GET /api/service` with what it offers, and
-puts an `access` block on every entry. A client that carried those facts would work for
-exactly one shop — this one asks, which is why the same build serves any of them.
+**The picker has a way out.** Opening it with a store already installed used to be a
+trap: the grid was replaced and nothing short of installing something brought it back.
-**A store with no sign-in shows none.** Every WarpEngine before 0.5 has no descriptor at
-all, and a 0.5 store that sells nothing reports none either. Both read as "a plain
-catalog", which is what this client assumed for its whole life until now, and the window
-behaves accordingly: no Account block, no prices, no new categories.
+**Two things found by the new test.** `make storetest` adds and removes a store in a
+sandbox, because removal is the only code here that deletes a directory tree and the
+path it deletes is named by the window. It immediately caught that `http://` was
+accepted and became a store called *http* — the trailing slashes were being stripped
+before the scheme was checked — and that `STORE_ROOT` only *prepended* to the search
+path, so a "sandboxed" run still listed the real stores. With a delete button in the
+window, a sandbox that can reach a working installation is not a sandbox; it replaces
+the search path now.
-**A title nobody has bought is not dimmed.** The dimming and the dashed badge belong to
-what this *machine* cannot do — an unsupported platform, no build for this architecture
-— and there is nothing wrong with the machine when a title simply costs money.
-
-**A bearer token is never sent to a host that did not issue it.** A gated download
-answers with a redirect to signed storage, often somebody else's server, and some object
-stores refuse a request outright when an `Authorization` header rides along with the
-signature. The credential stops at the origin it belongs to; a redirect back to the
-catalog keeps it.
+**`btn-secondary` had no styling at all.** It was introduced in 2.4.0 on the card's
+sign-in button and on the sign-in panel, and rendered as a plain button in both places.
diff --git a/package.json b/package.json
index 759e6f7..10fc032 100644
--- a/package.json
+++ b/package.json
@@ -1,7 +1,7 @@
{
"name": "warp-engine-client",
"productName": "WarpEngine Client",
- "version": "2.4.0",
+ "version": "2.5.0",
"description": "Graphical client for WarpEngine stores: install a catalog into your own application menu.",
"license": "MIT",
"author": "Teletype Games ",
@@ -21,7 +21,9 @@
"dist": "npm run build && electron-builder",
"dist:mac": "npm run build && electron-builder --mac",
"dist:win": "npm run build && electron-builder --win",
- "dist:linux": "npm run build && electron-builder --linux"
+ "dist:linux": "npm run build && electron-builder --linux",
+ "storetest": "npm run build && node build/scripts/StoreLifecycleTest.js",
+ "test": "npm run smoke && npm run storetest && npm run uitest"
},
"devDependencies": {
"@types/node": "^26.2.0",
diff --git a/src/application/services/PreferencesService.ts b/src/application/services/PreferencesService.ts
index 0c6e496..d3654fc 100644
--- a/src/application/services/PreferencesService.ts
+++ b/src/application/services/PreferencesService.ts
@@ -45,6 +45,18 @@ export class PreferencesService {
this.merge({ storeHome: home })
}
+ /**
+ * Stop remembering a store, for when it is no longer on the machine.
+ *
+ * The key is removed rather than blanked: an empty string would be a remembered home
+ * that matches nothing, and every reader would have to know to treat it as absent.
+ */
+ public forgetStoreHome (): void {
+ const { storeHome, ...rest } = this.repository.read()
+ void storeHome
+ this.repository.write(rest)
+ }
+
private merge (changes: Preferences): void {
this.repository.write({ ...this.repository.read(), ...changes })
}
diff --git a/src/application/services/StoreProvisioningService.ts b/src/application/services/StoreProvisioningService.ts
index 26d8675..d4d2eec 100644
--- a/src/application/services/StoreProvisioningService.ts
+++ b/src/application/services/StoreProvisioningService.ts
@@ -4,6 +4,7 @@ import type { RegistryStore } from '../../domain/models/RegistryStore'
import { deriveStoreId } from '../../domain/models/StoreIdentity'
import type { InstalledStoreRepository } from '../../domain/ports/InstalledStoreRepository'
import type { StoreEngineInstaller } from '../../domain/ports/StoreEngineInstaller'
+import type { StoreCatalogGateway } from '../../domain/ports/StoreCatalogGateway'
import type { StoreRegistryRepository } from '../../domain/ports/StoreRegistryRepository'
import type { StoreSelectionService } from './StoreSelectionService'
@@ -19,7 +20,8 @@ export class StoreProvisioningService {
private readonly registry: StoreRegistryRepository,
private readonly installer: StoreEngineInstaller,
private readonly stores: InstalledStoreRepository,
- private readonly selection: StoreSelectionService
+ private readonly selection: StoreSelectionService,
+ private readonly catalogGateway: StoreCatalogGateway
) {}
public get registryUrl (): string {
@@ -47,4 +49,79 @@ export class StoreProvisioningService {
return this.selection.adoptStore(installed)
}
+ /**
+ * A catalog the registry does not offer.
+ *
+ * Nothing about installing changes — a record is still a name and a catalog, and the
+ * configuration still comes from the engine's defaults. What differs is only where
+ * the two fields came from, which is why this hands the same record to the same
+ * method rather than growing a second path.
+ *
+ * The name is derived from the host when none is given: it is a label for the picker,
+ * and asking somebody to invent one before they can try a URL is a question with no
+ * useful answer.
+ */
+ public async installCatalog (
+ catalogUrl: string,
+ name: string | null = null,
+ progress?: EngineProgressListener
+ ): Promise {
+ const url = normaliseCatalogUrl(catalogUrl)
+ const chosen: RegistryStore = { name: name?.trim() ?? '', catalogUrl: url }
+ return await this.installStore(
+ chosen.name.length > 0 ? chosen : { ...chosen, name: readHostName(url) },
+ progress
+ )
+ }
+
+ /**
+ * Remove a store: everything it installed, then the store itself.
+ *
+ * Whichever store is open afterwards is decided by re-reading the disk rather than
+ * guessed at here — removing the open one has to leave the window pointing at
+ * something that exists, and that answer lives in one place.
+ */
+ public async removeStore (store: InstalledStore, progress?: EngineProgressListener): Promise {
+ await this.catalogGateway.removeStore(store, progress)
+ this.selection.forgetStore(store)
+ }
+}
+
+/**
+ * What somebody typed, as a URL this can be used as.
+ *
+ * Two liberties taken on purpose, because both are what a person means: a bare host
+ * gets https, and a trailing slash goes. Anything still unparseable is refused here
+ * rather than at the first fetch — a store home written for a bad URL is a directory
+ * somebody has to find and delete.
+ */
+function normaliseCatalogUrl (value: string): string {
+ const trimmed = value.trim()
+ if (trimmed.length === 0) throw new Error('a catalog address is needed')
+
+ const withScheme = /^https?:\/\//i.test(trimmed) ? trimmed : `https://${trimmed}`
+ let parsed: URL
+ try {
+ parsed = new URL(withScheme)
+ } catch {
+ throw new Error(`not a usable address: ${value}`)
+ }
+ // A URL can parse and still have no host — `http://` does. That one used to slip
+ // through and become a store called "http", because the trailing slashes were being
+ // stripped *before* the scheme was checked, turning `http://` into `http:` and then
+ // into `https://http:`.
+ if (parsed.hostname.length === 0) throw new Error(`not a usable address: ${value}`)
+
+ // Rebuilt from the parsed URL rather than from the string: it drops the query and
+ // the fragment — a catalog is a base address, not a request — and settles the
+ // trailing slash in one place instead of at every call site that appends a path.
+ return `${parsed.origin}${parsed.pathname}`.replace(/\/+$/, '')
+}
+
+function readHostName (catalogUrl: string): string {
+ try {
+ return new URL(catalogUrl).hostname.replace(/^www\./, '')
+ } catch {
+ return catalogUrl
+ }
}
diff --git a/src/application/services/StoreSelectionService.ts b/src/application/services/StoreSelectionService.ts
index f5464af..5f128ba 100644
--- a/src/application/services/StoreSelectionService.ts
+++ b/src/application/services/StoreSelectionService.ts
@@ -40,6 +40,13 @@ export class StoreSelectionService {
return store
}
+ /** The store at this home, or an error naming it. Does not change what is open. */
+ public requireStoreAt (home: string): InstalledStore {
+ const store = this.stores.findByHome(home)
+ if (store === null) throw new StoreMissingError(home)
+ return store
+ }
+
public selectStore (home: string): InstalledStore {
const store = this.stores.findByHome(home)
if (store === null) throw new StoreMissingError(home)
@@ -55,6 +62,20 @@ export class StoreSelectionService {
return store
}
+ /**
+ * Forget a store that is no longer on the machine.
+ *
+ * The next store is not chosen here: `findCurrentStore` re-reads the disk and applies
+ * the same rule it always does, so "which store is open" has exactly one answer in
+ * one place. Clearing the remembered home first is what stops it choosing the one
+ * that has just been deleted.
+ */
+ public forgetStore (store: InstalledStore): void {
+ if (this.preferences.readStoreHome() === store.home) this.preferences.forgetStoreHome()
+ if (this.current?.home === store.home) this.current = null
+ this.findCurrentStore()
+ }
+
public readDefaultStoreRoot (): string {
return this.stores.readRoots()[0] ?? ''
}
diff --git a/src/domain/ports/InstalledStoreRepository.ts b/src/domain/ports/InstalledStoreRepository.ts
index b7566f5..61ba391 100644
--- a/src/domain/ports/InstalledStoreRepository.ts
+++ b/src/domain/ports/InstalledStoreRepository.ts
@@ -7,4 +7,9 @@ export interface InstalledStoreRepository {
/** The roots that are searched, in the order the shell installer would use them. */
readRoots: () => readonly string[]
resolveDefaultHome: (storeId: string) => string
+ /**
+ * Delete a store home. Only a directory this repository would have *found* is
+ * accepted, so a caller cannot name an arbitrary path and have it removed.
+ */
+ removeHome: (home: string) => void
}
diff --git a/src/domain/ports/StoreCatalogGateway.ts b/src/domain/ports/StoreCatalogGateway.ts
index dabcf6f..fa43fff 100644
--- a/src/domain/ports/StoreCatalogGateway.ts
+++ b/src/domain/ports/StoreCatalogGateway.ts
@@ -16,6 +16,15 @@ export interface StoreCatalogGateway {
readPaths: (store: InstalledStore, progress?: EngineProgressListener) => Promise
syncGames: (store: InstalledStore, names: readonly string[], progress?: EngineProgressListener) => Promise
removeGame: (store: InstalledStore, name: string, progress?: EngineProgressListener) => Promise
+ /**
+ * Take a whole store off this machine: everything it installed, then its own home.
+ *
+ * The games go first and deliberately so. A store's `state.json` is the only record
+ * of what it put where, so deleting the home first would strip the one thing that
+ * knows which payloads, icons and menu entries belong to it — leaving a library of
+ * orphans nothing can ever clean up.
+ */
+ removeStore: (store: InstalledStore, progress?: EngineProgressListener) => Promise
/** Whether this store offers a sign-in, and whether we are holding a token for it. */
readAccount: (store: InstalledStore) => Promise
diff --git a/src/infrastructure/engine/NativeStoreCatalogGateway.ts b/src/infrastructure/engine/NativeStoreCatalogGateway.ts
index a36dba7..20beab0 100644
--- a/src/infrastructure/engine/NativeStoreCatalogGateway.ts
+++ b/src/infrastructure/engine/NativeStoreCatalogGateway.ts
@@ -15,6 +15,7 @@ import type { SignInPrompt, StoreAccount } from '../../domain/models/StoreAccoun
import { APP_MODE, WEB_MODE, type StoreConfiguration } from '../../domain/models/StoreConfiguration'
import type { StorePaths } from '../../domain/models/StorePaths'
import type { CredentialRepository } from '../../domain/ports/CredentialRepository'
+import type { InstalledStoreRepository } from '../../domain/ports/InstalledStoreRepository'
import type { SignInPollResult, StoreCatalogGateway } from '../../domain/ports/StoreCatalogGateway'
import { StoreFileSystem } from '../files/StoreFileSystem'
import { CatalogClient, type FetchedCatalog } from './CatalogClient'
@@ -54,7 +55,10 @@ export class NativeStoreCatalogGateway implements StoreCatalogGateway {
* The credentials are injected because they are the host's to keep: on a desktop the
* OS keychain, in the smoke test a map in memory. Nothing here knows which.
*/
- public constructor (private readonly credentials: CredentialRepository = NO_CREDENTIALS) {}
+ public constructor (
+ private readonly credentials: CredentialRepository = NO_CREDENTIALS,
+ private readonly stores: InstalledStoreRepository = NO_STORES
+ ) {}
public async listGames (
store: InstalledStore,
@@ -151,6 +155,34 @@ export class NativeStoreCatalogGateway implements StoreCatalogGateway {
return Promise.resolve()
}
+ /**
+ * Take a whole store off this machine.
+ *
+ * The order is the whole of it. `state.json` is the only record of what this store
+ * put where — which payload, which icon, which menu entry — so the games have to go
+ * *before* the home does. Delete the home first and every one of those files is an
+ * orphan nothing will ever be able to identify, least of all a later install of the
+ * same store into the same folder.
+ *
+ * The token goes too: a credential for a store that is no longer here is a secret
+ * kept for nothing.
+ */
+ public removeStore (store: InstalledStore, progress: EngineProgressListener = {}): Promise {
+ const engine = this.openStore(store, progress)
+ const installed = engine.state.readState()
+ const count = installed.size
+
+ engine.installer.purge(engine.layout, installed)
+ engine.state.writeState(installed)
+ engine.launchers.refreshMenu(engine.layout)
+ engine.log(`removed ${String(count)} installed title(s)`)
+
+ this.credentials.clearToken(store.id)
+ this.stores.removeHome(store.home)
+ engine.log(`removed the store home ${store.home}`)
+ return Promise.resolve()
+ }
+
public async readAccount (store: InstalledStore): Promise {
const engine = this.openStore(store, {})
const descriptor = await engine.service.fetchDescriptor()
@@ -375,6 +407,21 @@ function toAccount (descriptor: ServiceDescriptor, token: string | null): StoreA
return { signInAvailable: available, signedIn: available && token !== null }
}
+/**
+ * Removing a store needs the repository that found it; nothing else here does.
+ *
+ * The default refuses rather than pretending. A gateway assembled without one — the
+ * smoke test — reads catalogs perfectly well, and should say so plainly if somebody
+ * asks it to delete something, instead of silently doing nothing.
+ */
+const NO_STORES: InstalledStoreRepository = {
+ findAll: (): readonly [] => [],
+ findByHome: (): null => null,
+ readRoots: (): readonly [] => [],
+ resolveDefaultHome: (storeId: string): string => storeId,
+ removeHome: (): never => { throw new Error('this gateway was built without a store repository') }
+}
+
/**
* A client with nowhere to keep a token is a client that is never signed in.
*
diff --git a/src/infrastructure/repositories/FileSystemInstalledStoreRepository.ts b/src/infrastructure/repositories/FileSystemInstalledStoreRepository.ts
index 968e675..1d04400 100644
--- a/src/infrastructure/repositories/FileSystemInstalledStoreRepository.ts
+++ b/src/infrastructure/repositories/FileSystemInstalledStoreRepository.ts
@@ -13,8 +13,10 @@ const CONFIG_FILE_NAME = 'config.json'
* Finds stores where they were put.
*
* The roots are searched in the shell installers' own order — those homes are still
- * valid stores — and `STORE_ROOT` comes first so a sandbox can be driven without
- * touching a working installation, which is how this repository is tested.
+ * valid stores. `STORE_ROOT` replaces the lot: a sandbox has to be a sandbox, and it
+ * only prepended before, so a "sandboxed" run still listed the real stores, could
+ * switch to one, and — now that stores can be removed — could delete one. The README
+ * always said "instead of the real one"; this is the behaviour catching up.
*/
export class FileSystemInstalledStoreRepository implements InstalledStoreRepository {
public findAll (): readonly InstalledStore[] {
@@ -34,10 +36,11 @@ export class FileSystemInstalledStoreRepository implements InstalledStoreReposit
}
public readRoots (): readonly string[] {
+ const override = process.env['STORE_ROOT']
+ if (override !== undefined && override.length > 0) return [override]
+
const home = os.homedir()
const roots: string[] = []
- const override = process.env['STORE_ROOT']
- if (override !== undefined && override.length > 0) roots.push(override)
const xdgDataHome = process.env['XDG_DATA_HOME']
if (xdgDataHome !== undefined && xdgDataHome.length > 0) {
roots.push(path.join(xdgDataHome, STORE_DIRECTORY_NAME))
@@ -58,6 +61,22 @@ export class FileSystemInstalledStoreRepository implements InstalledStoreReposit
return path.join(root, `${storeId}${DESKTOP_STORE_ENGINE.homeSuffix}`)
}
+ /**
+ * Remove a store home, and only one this repository actually found.
+ *
+ * The check is the point. This is the one call in the application that deletes a
+ * directory tree the *window* named, and the window is the least trusted thing here;
+ * resolving the path against what a scan returns means a caller can ask for the
+ * removal of a store, never of a path.
+ */
+ public removeHome (home: string): void {
+ const known = this.findByHome(home)
+ if (known === null) {
+ throw new Error(`not a store home on this machine: ${home}`)
+ }
+ fs.rmSync(known.home, { recursive: true, force: true })
+ }
+
private readDirectories (root: string): readonly string[] {
try {
return fs.readdirSync(root, { withFileTypes: true })
diff --git a/src/main/composition/ServiceContainer.ts b/src/main/composition/ServiceContainer.ts
index ef49c80..6f2827f 100644
--- a/src/main/composition/ServiceContainer.ts
+++ b/src/main/composition/ServiceContainer.ts
@@ -51,7 +51,7 @@ export class ServiceContainer {
const stores = new FileSystemInstalledStoreRepository()
const credentials = new SafeStorageCredentialRepository(environment)
- const catalogGateway = new NativeStoreCatalogGateway(credentials)
+ const catalogGateway = new NativeStoreCatalogGateway(credentials, stores)
const registry = new HttpStoreRegistryRepository(httpClient)
const installer = new NativeStoreEngineInstaller()
const preferencesRepository = new JsonFilePreferencesRepository(environment)
@@ -60,7 +60,9 @@ export class ServiceContainer {
this.selection = new StoreSelectionService(stores, preferences)
this.catalog = new CatalogService(catalogGateway, this.selection)
this.accounts = new AccountService(catalogGateway, this.selection)
- this.provisioning = new StoreProvisioningService(registry, installer, stores, this.selection)
+ this.provisioning = new StoreProvisioningService(
+ registry, installer, stores, this.selection, catalogGateway
+ )
this.launching = new GameLaunchService(new ElectronGameLauncher(shell), this.catalog)
this.state = new ApplicationStateService(
preferences, this.selection, this.provisioning, environment
diff --git a/src/main/diagnostics/SelfTestRunner.ts b/src/main/diagnostics/SelfTestRunner.ts
index c4f92ab..02101f0 100644
--- a/src/main/diagnostics/SelfTestRunner.ts
+++ b/src/main/diagnostics/SelfTestRunner.ts
@@ -87,9 +87,12 @@ export class SelfTestRunner {
// A gate passes on having something to do, not on having a picker: the picker
// only appears when the registry offers more than one store, and one store is
// the ordinary case. Requiring choices here failed a perfectly good window.
- // Both footer icons must be present, named and drawn: refresh and the language
- // picker are the only way to reach those two actions now that neither has a label.
- const iconsNamed = report.iconControls.length === 2 &&
+ // Every footer icon must be named and drawn. There are three — refresh, add a
+ // store, and the language picker — and none of them has a label, so an unnamed one
+ // is a button nobody can identify and the failure is silent because the glyph still
+ // draws. The count is a floor rather than an equality: a fourth control is somebody
+ // adding one, which this should not fail on; a missing one is what it guards.
+ const iconsNamed = report.iconControls.length >= 3 &&
report.iconControls.every((control: string): boolean => /^.+:1$/.test(control))
// Every installed card offers both actions, and Upgrade is enabled exactly when the
// version line says there is something newer. Uninstall is always available.
@@ -196,9 +199,12 @@ export class SelfTestRunner {
*/
private async switchStore (): Promise {
const record = asRecord(JSON.parse(await this.evaluate(`(async () => {
+ // The row is a wrapper now; the part that switches stores is the button inside
+ // it. Clicking the wrapper did nothing at all, and a click that does nothing is
+ // exactly the kind of silent break this test exists for.
const other = [...document.querySelectorAll('#store-list .store-row')]
.find((row) => !row.classList.contains('is-active'))
- other.click()
+ other.querySelector('.store-row-open').click()
await new Promise((done) => setTimeout(done, ${String(SWITCH_SETTLE_DELAY_MS)}))
return JSON.stringify({
storeId: document.getElementById('store-id').textContent,
diff --git a/src/main/ipc/StoreIpcController.ts b/src/main/ipc/StoreIpcController.ts
index fded699..2850f95 100644
--- a/src/main/ipc/StoreIpcController.ts
+++ b/src/main/ipc/StoreIpcController.ts
@@ -27,8 +27,12 @@ export class StoreIpcController {
this.handleListRegistry())
router.handle(IPC_CHANNELS.storeInstallStore, async (store: unknown): Promise =>
this.handleInstallStore(store))
+ router.handle(IPC_CHANNELS.storeInstallCatalog, async (url: unknown): Promise =>
+ this.handleInstallCatalog(requireString(url, 'catalogUrl')))
router.handle(IPC_CHANNELS.storeSelectStore, (home: unknown): StoreSelectionDto =>
this.handleSelectStore(requireString(home, 'home')))
+ router.handle(IPC_CHANNELS.storeRemoveStore, async (home: unknown): Promise =>
+ this.handleRemoveStore(requireString(home, 'home')))
}
/**
@@ -60,7 +64,39 @@ export class StoreIpcController {
})
}
+ /**
+ * A catalog somebody typed, rather than one the registry offered.
+ *
+ * Only the address crosses the bridge. The name is derived from it and the
+ * configuration comes from the engine's defaults, so a typed URL can no more decide
+ * where files land than a registry record can.
+ */
+ private async handleInstallCatalog (catalogUrl: string): Promise {
+ return this.guard.run(async (): Promise => {
+ const installed = await this.provisioning.installCatalog(
+ catalogUrl, null, this.streams.asProgressListener()
+ )
+ return this.storeMapper.toDto(installed)
+ })
+ }
+
private handleSelectStore (home: string): StoreSelectionDto {
return { store: this.storeMapper.toDto(this.selection.selectStore(home)) }
}
+
+ /**
+ * Remove a store by its home.
+ *
+ * The home is resolved against the stores actually on this machine before anything
+ * is deleted — the window names a store, never a path. Guarded, because it uninstalls
+ * every title the store put here and a second engine call across that would be
+ * working on files this one is removing.
+ */
+ private async handleRemoveStore (home: string): Promise {
+ await this.guard.run(async (): Promise => {
+ await this.provisioning.removeStore(
+ this.selection.requireStoreAt(home), this.streams.asProgressListener()
+ )
+ })
+ }
}
diff --git a/src/preload/preload.ts b/src/preload/preload.ts
index 6637aca..cffa6af 100644
--- a/src/preload/preload.ts
+++ b/src/preload/preload.ts
@@ -56,8 +56,12 @@ const bridge: BridgeApi = {
ipcRenderer.invoke(IPC_CHANNELS.storeListRegistry) as Promise,
installStore: async (store: RegistryStoreDto): Promise =>
ipcRenderer.invoke(IPC_CHANNELS.storeInstallStore, store) as Promise,
+ installCatalog: async (catalogUrl: string): Promise =>
+ ipcRenderer.invoke(IPC_CHANNELS.storeInstallCatalog, catalogUrl) as Promise,
selectStore: async (home: string): Promise =>
ipcRenderer.invoke(IPC_CHANNELS.storeSelectStore, home) as Promise,
+ removeStore: async (home: string): Promise =>
+ ipcRenderer.invoke(IPC_CHANNELS.storeRemoveStore, home) as Promise,
openFolder: async (directory: string): Promise =>
ipcRenderer.invoke(IPC_CHANNELS.appOpenFolder, directory) as Promise,
diff --git a/src/renderer/RendererApplication.ts b/src/renderer/RendererApplication.ts
index 6a86e22..7c0fd24 100644
--- a/src/renderer/RendererApplication.ts
+++ b/src/renderer/RendererApplication.ts
@@ -72,6 +72,7 @@ export class RendererApplication {
})
this.sideMenu = new SideMenuView({
onSelectStore: (home: string): void => { void this.stores.selectStore(home) },
+ onRemoveStore: (home: string, name: string): void => { void this.stores.removeStore(home, name) },
onAddStore: (): void => { void this.stores.offerStores() },
onRefresh: (): void => { void this.catalog.refresh() },
onSelectCategory: (filter: CategoryFilter): void => { this.store.applyFilter(filter) },
diff --git a/src/renderer/controllers/StoreController.ts b/src/renderer/controllers/StoreController.ts
index 29ab09c..9aecc09 100644
--- a/src/renderer/controllers/StoreController.ts
+++ b/src/renderer/controllers/StoreController.ts
@@ -41,11 +41,30 @@ export class StoreController {
const messages = state.messages
const result = await this.bridge.listRegistryStores()
+ // A typed address works whatever the registry said — that is the point of it — so
+ // it is attached to every one of the three outcomes below, including the two that
+ // used to be dead ends.
+ const custom = {
+ label: messages.customTitle,
+ hint: messages.customHint,
+ actionLabel: messages.customAction,
+ perform: (catalogUrl: string): void => { void this.installCatalog(catalogUrl) }
+ }
+ // Only where there is something to go back to. On a machine with no store the grid
+ // behind this screen is empty, and "Cancel" would lead nowhere. Spread rather than
+ // an `undefined` value: the strict optional-property rule treats "absent" and
+ // "present but undefined" as different things, and here they genuinely are.
+ const cancel = state.currentStore === null
+ ? {}
+ : { cancel: { label: messages.cancel, perform: (): void => { this.store.applyGate(null) } } }
+
if (result.error !== null) {
this.store.applyGate({
title: messages.registryFailed,
body: `${result.sourceUrl}\n\n${result.error}`,
- action: { label: messages.registryRetry, perform: (): void => { void this.offerStores() } }
+ action: { label: messages.registryRetry, perform: (): void => { void this.offerStores() } },
+ custom,
+ ...cancel
})
return
}
@@ -53,7 +72,9 @@ export class StoreController {
if (result.stores.length === 0) {
this.store.applyGate({
title: messages.setupTitle,
- body: `${messages.registryEmpty}\n\n${result.sourceUrl}`
+ body: `${messages.registryEmpty}\n\n${result.sourceUrl}`,
+ custom,
+ ...cancel
})
return
}
@@ -67,10 +88,65 @@ export class StoreController {
if (chosen !== null) void this.installStore(chosen)
}
},
- choices: result.stores
+ choices: result.stores,
+ custom,
+ ...cancel
})
}
+ /**
+ * Take a store off this machine, with what that costs stated first.
+ *
+ * The confirmation names the number of installed titles, because that is the part
+ * somebody would not otherwise expect: removing a store uninstalls everything it
+ * put here. Leaving them behind would be worse — the store's state file is the only
+ * record of which files belong to it, so orphans would be permanent.
+ */
+ public async removeStore (home: string, name: string): Promise {
+ const state = this.store.readState()
+ const messages = state.messages
+ const installed = state.currentStore?.home === home
+ ? state.games.filter((game): boolean => game.installed).length
+ : null
+
+ const question = installed === null
+ ? messages.removeStoreConfirm.replace('%{store}', name)
+ : messages.removeStoreConfirmGames
+ .replace('%{store}', name)
+ .replace('%{count}', String(installed))
+ if (!window.confirm(question)) return
+
+ try {
+ await this.bridge.removeStore(home)
+ this.store.applyAppState(await this.bridge.readState())
+ const remaining = this.store.readState().currentStore
+ this.store.applyGate(null)
+ if (remaining === null) {
+ await this.offerStores()
+ return
+ }
+ await this.catalog.refresh()
+ } catch (error: unknown) {
+ this.log.appendLine(error instanceof Error ? error.message : String(error))
+ }
+ }
+
+ private async installCatalog (catalogUrl: string): Promise {
+ const messages = this.store.readState().messages
+ this.store.applyProgress({ total: 0, done: 0, label: messages.setupWorking })
+ try {
+ await this.bridge.installCatalog(catalogUrl)
+ this.store.applyAppState(await this.bridge.readState())
+ this.store.applyGate(null)
+ await this.catalog.refresh()
+ await this.catalog.syncGames([])
+ } catch (error: unknown) {
+ this.log.appendLine(error instanceof Error ? error.message : String(error))
+ } finally {
+ this.store.applyProgress(null)
+ }
+ }
+
private async installStore (chosen: RegistryStoreDto): Promise {
const messages = this.store.readState().messages
this.store.applyProgress({ total: 0, done: 0, label: messages.setupWorking })
diff --git a/src/renderer/index.html b/src/renderer/index.html
index 7581a0b..3c53b25 100644
--- a/src/renderer/index.html
+++ b/src/renderer/index.html
@@ -33,7 +33,6 @@
-
+
+