Compare commits

...
17 Commits
Author SHA1 Message Date
zemion d1d4b3f44e Swith to v0.20.3
Verify / verify (push) Canceled after 0s
2026-09-03 10:31:09 +02:00
zemion 11a2c140ce chore(portal): include translator-tools v0.1.2 in v0.20.3 release
Verify / verify (push) Canceled after 0s
2026-09-03 09:49:09 +02:00
zemion 3b1a13b84d chore(portal): bump embedded release to 0.20.2 with translator-tools 0.1.1
Verify / verify (push) Canceled after 0s
2026-09-03 09:16:53 +02:00
zemion cd54847af8 chore(portal): add deploy helper for untagged HEAD
Verify / verify (push) Canceled after 0s
2026-09-03 08:40:49 +02:00
zemion 9dbbdb5ed2 commit containerfile
Verify / verify (push) Canceled after 0s
2026-09-03 01:01:29 +02:00
zemion f3c634120c toolbox-portal: update translator-tools to v0.1.1
Verify / verify (push) Canceled after 0s
2026-09-02 23:58:17 +02:00
zemion ae74d22cde chore(toolbox-portal): default compose to release 0.20.1
Verify / verify (push) Canceled after 0s
2026-09-02 22:19:44 +02:00
zemion 4a664e90eb chore(toolbox-portal): bump toolbox release version for translator inclusion
Verify / verify (push) Canceled after 0s
2026-09-02 22:10:31 +02:00
zemion 13af32f535 feat(toolbox-portal): include translator-tools in release lock
Verify / verify (push) Canceled after 0s
2026-09-02 21:52:15 +02:00
zemion 965a776aad Release Toolbox v0.20.0
Verify / verify (push) Canceled after 0s
2026-09-02 13:44:29 +02:00
zemion 45dcaff659 Release Toolbox v0.19.0 2026-09-01 16:29:17 +02:00
zemion ea5f76554a Publish Toolbox 0.18.1 with local-only Random Tools 2026-09-01 08:32:15 +02:00
zemion 08a01d843a feat: publish Toolbox 0.18.0 with sixteen new tools 2026-09-01 03:02:08 +02:00
zemion d2d0c9098d feat: publish Toolbox 0.17.0 with Colour and Office Tools 2026-09-01 00:54:22 +02:00
zemion 01f6c59adf feat: publish Toolbox 0.16.0 with Sudoku Tools 0.2.1 2026-08-31 16:28:36 +02:00
zemion bc07e13e3b feat: publish Toolbox 0.15.0 with Sudoku Tools 0.2.0 2026-08-31 08:44:44 +02:00
zemion 7bd34371a9 feat: publish Toolbox 0.14.0 with Sudoku Tools 2026-08-30 14:27:22 +02:00
26 changed files with 2287 additions and 193 deletions
+2 -2
View File
@@ -5,5 +5,5 @@ TRAEFIK_NETWORK=internal
TRAEFIK_CERT_RESOLVER=netcup
# Keep these two values paired when deploying a newer published toolbox release.
TOOLBOX_RELEASE_VERSION=0.13.0
TOOLBOX_RELEASE_SHA256=ae8d96906ad6794c1c387863dbd0d6d31e1c5deeef7640362f8a479dbf3f3891
TOOLBOX_RELEASE_VERSION=0.20.3
TOOLBOX_RELEASE_SHA256=1e743fda8f6d1ca5c77798029351585bf6673a3410892d27e5ad17c9f6bcf0bf
+35
View File
@@ -0,0 +1,35 @@
name: Verify
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
concurrency:
group: verify-${{ gitea.repository }}-${{ gitea.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 60
env:
CI: 'true'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
cache: npm
- name: Select declared npm version
run: npm install --global npm@11.17.0
- name: Install dependencies
run: npm ci
- name: Audit runtime dependencies
run: npm audit --omit=dev --audit-level=moderate
- name: Check, test, and build
run: npm run check
+46 -2
View File
@@ -2,8 +2,8 @@ ARG NGINX_IMAGE=nginxinc/nginx-unprivileged:1.31.3-alpine@sha256:18d67281256ded3
FROM ${NGINX_IMAGE} AS release
ARG TOOLBOX_RELEASE_VERSION=0.13.0
ARG TOOLBOX_RELEASE_SHA256=ae8d96906ad6794c1c387863dbd0d6d31e1c5deeef7640362f8a479dbf3f3891
ARG TOOLBOX_RELEASE_VERSION=0.20.3
ARG TOOLBOX_RELEASE_SHA256=1e743fda8f6d1ca5c77798029351585bf6673a3410892d27e5ad17c9f6bcf0bf
ARG TOOLBOX_RELEASE_BASE_URL=https://git.add-ideas.de/lotobo/toolbox-portal/releases/download
RUN set -eu; \
@@ -25,6 +25,50 @@ RUN set -eu; \
test -f /tmp/toolbox/apps/regex/toolbox-app.json; \
test -f /tmp/toolbox/apps/svg/toolbox-app.json; \
test -f /tmp/toolbox/apps/auth/toolbox-app.json; \
test -f /tmp/toolbox/apps/sudoku/toolbox-app.json; \
test -f /tmp/toolbox/apps/colour/toolbox-app.json; \
test -f /tmp/toolbox/apps/office/toolbox-app.json; \
test -f /tmp/toolbox/apps/image/toolbox-app.json; \
test -f /tmp/toolbox/apps/file/toolbox-app.json; \
test -f /tmp/toolbox/apps/epub/toolbox-app.json; \
test -f /tmp/toolbox/apps/archive/toolbox-app.json; \
test -f /tmp/toolbox/apps/privacy/toolbox-app.json; \
test -f /tmp/toolbox/apps/crypto/toolbox-app.json; \
test -f /tmp/toolbox/apps/barcode/toolbox-app.json; \
test -f /tmp/toolbox/apps/network/toolbox-app.json; \
test -f /tmp/toolbox/apps/geo/toolbox-app.json; \
test -f /tmp/toolbox/apps/helper/toolbox-app.json; \
test -f /tmp/toolbox/apps/rand/toolbox-app.json; \
test -f /tmp/toolbox/apps/data/toolbox-app.json; \
test -f /tmp/toolbox/apps/diff/toolbox-app.json; \
test -f /tmp/toolbox/apps/time/toolbox-app.json; \
test -f /tmp/toolbox/apps/text/toolbox-app.json; \
test -f /tmp/toolbox/apps/translator/toolbox-app.json; \
test -f /tmp/toolbox/apps/unicode/toolbox-app.json; \
test -f /tmp/toolbox/apps/flow/toolbox-app.json; \
test -f /tmp/toolbox/apps/subtitle/toolbox-app.json; \
test -f /tmp/toolbox/apps/midi/toolbox-app.json; \
test -f /tmp/toolbox/apps/3d/toolbox-app.json; \
test -f /tmp/toolbox/apps/query/toolbox-app.json; \
test -f /tmp/toolbox/apps/scan/toolbox-app.json; \
test -f /tmp/toolbox/apps/package/toolbox-app.json; \
test -f /tmp/toolbox/apps/label/toolbox-app.json; \
test -f /tmp/toolbox/apps/font/toolbox-app.json; \
test -f /tmp/toolbox/apps/fixture/toolbox-app.json; \
test -f /tmp/toolbox/apps/minimize/toolbox-app.json; \
test -f /tmp/toolbox/apps/format-lab/toolbox-app.json; \
test -f /tmp/toolbox/apps/repro/toolbox-app.json; \
test -f /tmp/toolbox/apps/schema/toolbox-app.json; \
test -f /tmp/toolbox/apps/log/toolbox-app.json; \
test -f /tmp/toolbox/apps/binary/toolbox-app.json; \
test -f /tmp/toolbox/apps/git/toolbox-app.json; \
test -f /tmp/toolbox/apps/api/toolbox-app.json; \
test -f /tmp/toolbox/apps/mail/toolbox-app.json; \
test -f /tmp/toolbox/apps/calendar/toolbox-app.json; \
test -f /tmp/toolbox/apps/contact/toolbox-app.json; \
test -f /tmp/toolbox/apps/diagram/toolbox-app.json; \
test -f /tmp/toolbox/apps/token/toolbox-app.json; \
test -f /tmp/toolbox/apps/device/toolbox-app.json; \
rm "/tmp/${archive}"
FROM ${NGINX_IMAGE}
+200 -83
View File
@@ -1,7 +1,7 @@
# add·ideas Toolbox Portal
`toolbox-portal` is the static launcher and release assembler for the add·ideas
browser toolbox. Version `0.2.15` reads one same-origin catalogue, shows each app
browser toolbox. Version `0.2.23` reads one same-origin catalogue, shows each app
as a compact launch tile, and keeps personal pins, drag-and-drop ordering,
visibility, and appearance in the current browser. Pinned tools have their own
section; search, category, and clickable tag filters stay close to the tool
@@ -30,14 +30,25 @@ npm run build
npm run dev
```
The package lock resolves the `^0.2.3` SDK ranges to the published `0.2.3`
The package lock resolves the `^0.3.0` SDK ranges to the published `0.3.0`
packages. A sibling SDK checkout is only needed when intentionally developing
the SDK and portal together.
Vite uses `base: './'`, so the built portal works at `/` or a nested static path.
The development catalogue at `public/toolbox.catalog.json` points to assembled
paths (`./apps/pdf/`, `./apps/xslt/`, `./apps/onenote/`, `./apps/av/`,
`./apps/regex/`, `./apps/svg/`, and `./apps/auth/`).
`./apps/regex/`, `./apps/svg/`, `./apps/auth/`, `./apps/sudoku/`,
`./apps/colour/`, `./apps/office/`, `./apps/image/`, `./apps/file/`,
`./apps/epub/`, `./apps/archive/`, `./apps/privacy/`, `./apps/crypto/`,
`./apps/barcode/`, `./apps/network/`, `./apps/geo/`, `./apps/helper/`,
`./apps/rand/`, `./apps/data/`, `./apps/diff/`, `./apps/time/`,
`./apps/text/`, `./apps/unicode/`, `./apps/flow/`, `./apps/subtitle/`,
`./apps/midi/`, `./apps/3d/`, `./apps/query/`, `./apps/scan/`,
`./apps/package/`, `./apps/label/`, `./apps/font/`, `./apps/fixture/`,
`./apps/minimize/`, `./apps/format-lab/`, `./apps/repro/`, `./apps/schema/`,
`./apps/log/`, `./apps/binary/`, `./apps/git/`, `./apps/api/`, `./apps/mail/`,
`./apps/calendar/`, `./apps/contact/`, `./apps/diagram/`, `./apps/token/`, and
`./apps/device/`).
Those manifests will correctly appear as unavailable until an assembled release
is being served.
@@ -69,7 +80,7 @@ privacy and executable-code warning. Light, dark, and system modes are supported
## Production deployment behind Traefik
The committed `compose.yaml` is the shortest production path. Its release
container downloads the immutable Toolbox 0.13.0 ZIP during the image build,
container downloads the immutable Toolbox 0.20.0 ZIP during the image build,
verifies SHA-256 before extracting it, and then copies only the verified static
files into the pinned unprivileged nginx image. Node.js and a local portal
assembly are not required on the deployment host.
@@ -88,7 +99,17 @@ Deploy a fresh clone with:
```sh
git clone https://git.add-ideas.de/lotobo/toolbox-portal.git
cd toolbox-portal
docker compose up -d --build
./scripts/deploy-update.sh
```
If you prefer the inline command:
```sh
git fetch origin --tags && \
git pull --ff-only origin main && \
{ TAG="$(git describe --tags --exact-match 2>/dev/null || git describe --tags --abbrev=0 2>/dev/null || true)"; \
if [ -n "$TAG" ]; then echo "$TAG"; else echo "warning: no matching tags found"; fi; } && \
docker compose up -d --build && \
docker compose ps
```
@@ -100,6 +121,26 @@ release version, and matching checksum can be overridden through environment
variables; copy `.env.example` to `.env` only when an override is needed. For
example, set `TOOLBOX_HOST=staging.toolbox.add-ideas.de` for a staging host.
## One-shot release wrapper
For release assembly and publishing, use the repository-local wrapper:
```sh
./scripts/release.sh
```
That script performs (in order):
- optional `npm test`
- `npm run build`
- `npm run assemble` (using the lockfiles `releaseVersion`)
- tag and push (`v<releaseVersion>`)
- publish/update a Gitea release and upload
`add-ideas-toolbox-<version>.zip` and `.sha256`
Useful flags include `--skip-tests`, `--skip-git-push`, `--skip-publish`,
`--tag`, `--owner`, `--repo`, and `--dry-run`.
The same container also exposes only the packaged authentication app at
`https://auth.toolbox.add-ideas.de/`. Traefik adds the internal `/apps/auth`
prefix while the public URL remains `/`, so assets remain relative and the browser
@@ -133,10 +174,16 @@ The app release should also publish a matching `.sha256` sidecar. The manifest
must declare the pinned reverse-DNS id and version. Application and portal
versions are independent.
`release/toolbox.lock.json` is the reviewed v0.13.0 lock. Its URLs and checksums
pin the published PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote Tools 0.3.4,
Audio & Video Tools 0.3.0, Regex Tools 0.4.2, SVG Tools 0.1.0, and OTP & Passkey
Tools 0.3.0 release bytes. Use
`release/toolbox.lock.json` is the reviewed Toolbox v0.20.0 / Portal v0.2.23
lock. Its URLs and checksums pin PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote
Tools 0.3.4, Audio & Video Tools 0.3.0, Regex Tools 0.4.2, OTP & Passkey Tools
0.3.1, Sudoku Tools 0.2.1, and the coordinated 0.2.0 releases of SVG, Colour,
Office, Image, File, EPUB, Archive, Privacy, Crypto, Barcode, Network, Geo,
Helper, Random, Data, Diff, Time, Text, Unicode, Flow, Subtitle, MIDI, 3D,
Query, Scan, Package, Label, Font, Fixture, Minimize, Format Lab, Repro, Schema,
Log, Binary, Git, API, Mail, Calendar, Contact, Diagram, Token, and Device
Tools.
Use
`release/toolbox.lock.example.json` as the template for a future release and
verify every downloaded asset before committing updated values. Artifacts may be:
@@ -157,7 +204,7 @@ npm run assemble -- \
--lock release/toolbox.lock.json \
--portal-dist dist \
--output build/toolbox \
--archive build/add-ideas-toolbox-0.13.0.zip
--archive build/add-ideas-toolbox-0.20.0.zip
```
Existing output is refused. Pass `--force` only when replacing those exact
@@ -179,10 +226,53 @@ build/toolbox/
├── av/
├── regex/
├── svg/
── auth/
── auth/
├── sudoku/
├── colour/
├── office/
├── image/
├── file/
├── epub/
├── archive/
├── privacy/
├── crypto/
├── barcode/
├── network/
├── geo/
├── helper/
├── rand/
├── data/
├── diff/
├── time/
├── text/
├── unicode/
├── flow/
├── subtitle/
├── midi/
├── 3d/
├── query/
├── scan/
├── package/
├── label/
├── font/
├── fixture/
├── minimize/
├── format-lab/
├── repro/
├── schema/
├── log/
├── binary/
├── git/
├── api/
├── mail/
├── calendar/
├── contact/
├── diagram/
├── token/
└── device/
build/add-ideas-toolbox-0.13.0.zip
build/add-ideas-toolbox-0.13.0.zip.sha256
build/add-ideas-toolbox-0.20.0.zip
build/add-ideas-toolbox-0.20.0.zip.sha256
```
The assembler verifies SHA-256 before opening an artifact, validates every app
@@ -203,7 +293,7 @@ directory separately:
```sh
npm run package:static -- \
--input build/toolbox \
--output artifacts/add-ideas-toolbox-0.13.0.zip
--output artifacts/add-ideas-toolbox-0.20.0.zip
```
This also emits a `.sha256` sidecar.
@@ -211,29 +301,34 @@ This also emits a `.sha256` sidecar.
## Local assembled container and publication
`Containerfile` serves only the assembled files with unprivileged nginx on port 8080. It adds restrictive browser headers, same-origin isolation, explicit
`application/javascript` for `.mjs` engine modules and `application/wasm`,
`application/javascript` for `.mjs` engine modules, `application/wasm`, and
`application/gzip` for the bundled Scan OCR language model,
immutable caching only for Vite-hashed assets and narrowly matched
semver-versioned FFmpeg core files, and revalidation for all other files. The
opaque-origin SVG preview iframe loads its packaged controller with a URI-exact
CORS and cross-origin resource-policy exception; all other files retain the
same-origin policy and every normal security header. Camera access is denied on
the shared Toolbox host and granted only to the dedicated
`auth.toolbox.add-ideas.de` origin, where Auth Tools still requests it only
after an explicit user action. If `AUTH_TOOLS_HOST` is customized, update the
exact host entry in `deploy/nginx.conf` and Auth Tools' pinned WebAuthn host at
the same time; the default-deny fallback deliberately does not infer camera
grants from request paths.
Assemble first, then:
same-origin policy and every normal security header. Camera access is denied by
default. It is granted to the dedicated `auth.toolbox.add-ideas.de` origin and,
on the shared Toolbox host, only to `/apps/barcode/`, `/apps/scan/`, and
`/apps/device/`. Device Tools alone additionally receives microphone and screen-
capture policy at its exact path; every probe remains explicitly user initiated.
If `AUTH_TOOLS_HOST` is customized, update
the exact host entry in `deploy/nginx.conf` and Auth Tools' pinned WebAuthn host
at the same time. Every Toolbox app, including Random Tools, is constrained to
same-origin connections. Random Tools implements its random generators locally
with browser APIs and never calls a third-party randomness service.
The packaged policy intentionally does not grant CSP `unsafe-eval`. SaxonJS's
`ixsl:eval()` extension is therefore unsupported in this deployment profile;
normal local XML/XSLT transformations do not require that permission.
Assemble first, then:
```sh
podman build -f Containerfile \
-t git.add-ideas.de/lotobo/toolbox:0.13.0 .
-t git.add-ideas.de/lotobo/toolbox:0.20.0 .
podman run --rm -p 8080:8080 \
git.add-ideas.de/lotobo/toolbox:0.13.0
git.add-ideas.de/lotobo/toolbox:0.20.0
```
For a direct-port local deployment after assembly, use the separate example:
@@ -250,8 +345,8 @@ docker login git.add-ideas.de
docker buildx build \
--platform linux/amd64,linux/arm64 \
--file Containerfile.release \
--tag git.add-ideas.de/lotobo/toolbox:0.13.0 \
--tag git.add-ideas.de/lotobo/toolbox:0.13 \
--tag git.add-ideas.de/lotobo/toolbox:0.20.0 \
--tag git.add-ideas.de/lotobo/toolbox:0.20 \
--push .
```
@@ -273,11 +368,11 @@ needs permission to push code, releases, and container packages to
3. Verify downloaded app assets with `sha256sum -c <asset>.sha256`; copy those
exact values into a reviewed toolbox lock.
4. Run the assembler and serve `build/toolbox` from a nested test path. Open
all seven apps, switch between them, and confirm the encoded `toolbox`
all 50 apps, switch between them, and confirm the encoded `toolbox`
context.
5. Verify the distribution with
`(cd build && sha256sum -c add-ideas-toolbox-0.13.0.zip.sha256)`.
6. Commit the reviewed lock, tag the toolbox release (for example `v0.13.0`), and
`(cd build && sha256sum -c add-ideas-toolbox-0.20.0.zip.sha256)`.
6. Commit the reviewed lock, tag the toolbox release (for example `v0.20.0`), and
push the branch and tag to Gitea.
7. In Gitea, open **Releases → New release**, select the tag, and upload the
static ZIP plus its `.sha256` file. Do not use a mutable “latest” URL in a
@@ -290,70 +385,92 @@ the exact tag, install with `npm ci`, run the same verification/assembly command
and upload only the already-created ZIP/checksum and OCI image. The workflow
must not re-resolve app versions or substitute a newer release.
## Toolbox 0.20.0 portfolio expansion
Toolbox 0.20.0 publishes the coordinated multi-repository depth pass. It adds:
- bounded byte/stream/worker/blob helpers, manifest I/O and capability profiles,
versioned evidence envelopes, and same-origin one-time artifact transfers;
- deeper batch, conversion, safe-share, schema, semantic diff, reproducibility,
archive, text, Unicode, colour, random, network, barcode, crypto and geospatial
workflows;
- richer EPUB, Office, SVG, image, subtitle, MIDI, 3D, scan, label, font,
diagram, design-token and structured-flow authoring/inspection, including
bounded HTML/Markdown/text-to-EPUB adaptation and TTC/OTC face inspection;
- modern PBES2/PBKDF2 PKCS #12 inspection, structural 7z/RAR inventory, and
OpenAPI 3.1/3.2 webhook receiver analysis with explicit fail-closed limits;
- expanded Query, Fixture, Minimize, Format Lab, Binary, Git, API, Mail,
Calendar, Contact, Log and Device evidence and interoperability; and
- repository-native Gitea verification workflows covering formatting, lint,
unit tests, production builds, Toolbox smoke checks, runtime dependency audit
and browser tests where applicable.
Every addition remains local-first, bounded and explicit about unsupported
formats or incomplete standards coverage. The release order is Toolbox SDK
`0.3.0`, `@add-ideas/toolbox-helpers@0.2.0`, the 43 app releases at `0.2.0`, and
Portal `0.2.23` with aggregate Toolbox `0.20.0`. The reviewed lock pins those
exact immutable app archives and checksums.
## Existing tools
| Tool | State and boundary | Principal workflows | Important concrete scope | Critical considerations and integrations |
| ------------------- | --------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| -------------------- | ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **`pdf-tools`** | Existing; dedicated repository | Merge, split, reorder, rotate and export PDF pages | Thumbnail workspace; multi-document operations; ZIP and PDF output; saved local workspace | Workers and IndexedDB; large-document memory control; future signature inspection through `crypto-tools`; metadata and safe-sharing through `privacy-tools` |
| **`xslt-tools`** | Existing; dedicated repository | Develop, test and run XSLT transformations | XML/XSLT editors; transformation results; local files; saved projects; validation and diagnostics | Lazy SaxonJS loading; relocatable assets; useful handoffs to `data-tools`, `schema-tools` and `diff-tools` |
| **`onenote-tools`** | Existing rich-reader release; dedicated repository | Open, browse, inspect and export OneNote sections and packages locally | Desktop/unfragmented FSSHTTPB `.one`/`.onetoc2`; none/LZX/MSZIP/Quantum and multi-cabinet `.onepkg`; trees, rich text, images, tables, ink, attachments and export | Native TypeScript worker with no Wasm; bounded parsing, rendering and export; fragmented FSSHTTP fails safely; no editing or pixel-perfect fidelity |
| **`av-tools`** | Existing local-first v0.3.0 release; dedicated repository | Convert and lightly edit audio and video locally in the browser | Immediate native playback and basic file information; progressive stream inspection on demand; quick conversion; trim, split and crossfade concatenate; crop, resize, normalize, fades, waveform, metadata, chapters, subtitles, scene thumbnails/contact sheets, presets and export | Reviewed ffmpeg.wasm 0.12.10 ST/MT build with verified Opus and bundled label font; bounded queue, temporary storage and resource policy; isolation enables MT with automatic ST fallback; versioned core assets are immutable |
| **`regex-tools`** | Current local-first v0.4.2 release; dedicated repository | Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions | Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence | Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics |
| **`svg-tools`** | Initial local-first v0.1.0 release; dedicated repository | Inspect and edit SVG source, structure, geometry, references and accessibility locally | Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; CSS animation preview; exact, sanitized, raster and project export | Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository |
| **`auth-tools`** | Current local-first v0.3.0 release; dedicated repository | Generate, migrate and diagnose OTP credentials, and inspect, verify and test WebAuthn/passkey ceremonies locally | HOTP/TOTP/OCRA with time travel, resynchronization and rotation planning; QR, Google, Aegis and encrypted PSKC migration; WebAuthn extension experiments and replayable traces; assertion, attestation, signer-chain and historical metadata-policy evaluation | Authentication material remains memory-only unless explicitly exported; redaction is deliberate but not a secrecy guarantee; live ceremonies and camera scanning are enabled only at the exact dedicated `auth.toolbox.add-ideas.de` origin, while the shared Portal path remains inspect-only; no raw CTAP administration |
| **`svg-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect and edit SVG source, structure, geometry, references and accessibility locally | Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; app-owned, validated opacity-animation preview; exact, sanitized, raster and project export | Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository |
| **`auth-tools`** | Current local-first v0.3.1 release; dedicated repository | Generate, migrate and diagnose OTP credentials, and inspect, verify and test WebAuthn/passkey ceremonies locally | HOTP/TOTP/OCRA with time travel, resynchronization and rotation planning; QR, Google, Aegis and encrypted PSKC migration; WebAuthn extension experiments and replayable traces; assertion, attestation, signer-chain and historical metadata-policy evaluation | Authentication material remains memory-only unless explicitly exported; redaction is deliberate but not a secrecy guarantee; live ceremonies and camera scanning are enabled only at the exact dedicated `auth.toolbox.add-ideas.de` origin, while the shared Portal path remains inspect-only; v0.3.1 corrects source provenance and cross-timezone artifact reproducibility; no raw CTAP administration |
| **`sudoku-tools`** | Current local-first v0.2.1 release; dedicated repository | Set, play, generate, analyse and solve classic, Killer and rich variant Sudoku locally | 4×416×16 grids; registry-backed constraint packs including cages, lines, dots, XV, inequalities, indexing and Fog of War; staged hints, candidate maintenance, advanced logical techniques, setter quality checks, mixed-variant generation, source-preserving f-puzzles/SudokuPad interoperability, autosave recovery and searchable local projects | Worker-bounded solving, generation and quality analysis; strict inert imported-visual validation; fog-safe play assistance; IndexedDB history with memory fallback; stable workspace geometry, responsive zoom and pan, a 3×3 standard keypad, tap selection, patterned colours, accessibility controls and an offline-capable PWA shell |
| **`colour-tools`** | Current local-first v0.2.0 release; dedicated repository | Convert, composite, interpolate, pick, sample, analyse and export colours locally | General colour conversion; arbitrary RGBA compositing; multi-stop colour steps and gradient editing; large visual/native/EyeDropper pickers; local image sampling and palette extraction; contrast, gamut, Delta E and colour-vision analysis; harmonies; DTCG 2025.10 token import/export with local reference resolution; directional contrast matrices; CSS and recipe export | Processing and image access remain local; colour spaces, encoded versus linear-light compositing, interpolation and gamut-mapping assumptions are explicit; mathematical conversion is distinguished from display simulation; integrates with SVG, image and token tools |
| **`office-tools`** | Current local-first v0.2.0 read-only release; dedicated repository | Open, inspect and view word-processing documents, spreadsheets and presentations locally; download exact source copies and bounded ODF semantic exports | DOCX/DOCM/DOTX/DOTM, XLSX/XLSM/XLTX/XLTM and PPTX/PPTM/POTX/POTM/PPSX/PPSM plus ODT/ODS/ODP; search/navigation/zoom; text, tables, images, styles, metadata, cached formula values and notes; exact source-copy plus ODF text/CSV/outline/JSON export | Bounded worker-based inert package and XML parsers never execute macros, scripts, formulas, active content or external resources; legacy binary DOC, XLS and PPT are unsupported; viewing is intentionally read-only and does not promise pixel-perfect Office-suite layout fidelity |
| **`image-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, crop, rotate, resize, preview before/after and batch-convert static raster images locally | Static JPEG/PNG/WebP; bounded pre-decode animation/profile inspection; synchronized 25400% source/result zoom; pointer/keyboard crop and fit/fill/exact resize; versioned recipes; cancellable batch ZIP with per-image reports; capability-probed PNG/JPEG/WebP export | Animated and multi-picture inputs are inspect-only; canvas re-encoding does not preserve arbitrary metadata, ICC profiles, HDR precision or byte identity |
| **`file-tools`** | Current local-first v0.2.0 release; dedicated repository | Identify, inspect, hash, compare, inventory, rename-copy, split and join local files | Signature and claimed-MIME comparison; paged hex/ASCII and strings; SHA-256/SHA-512; deterministic manifests; duplicate candidates; collision-safe rename/copy plans; byte-exact split/join | Detection and entropy are heuristics rather than validation or malware analysis; rename operations export safe copies and never mutate the source filesystem |
| **`epub-tools`** | Current local-first v0.2.0 release; dedicated repository | Read, inspect and validate EPUB 2/3 publications; adapt text formats, edit metadata and covers, and rebuild EPUBs locally | EPUB 2/3 package/nav/spine inspection; determinate open progress; sandboxed reflow/fixed-layout reading with packaged CSS/fonts/images/media; bounded HTML/XHTML/Markdown/text adapters; search, bookmarks and annotations; metadata/cover editing; text/Markdown/safe-HTML/chapter/report exports; normalized rebuilds with IDPF font-obfuscation preservation | Strict bounded ZIP and XML handling; active and external content are blocked; DRM is detected but never bypassed; focused preflight is not a complete EPUBCheck implementation |
| **`archive-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, create, compare and safely extract archive content | ZIP/ZIP64, TAR/USTAR/PAX, gzip and tar.gz plus bounded structural 7z and RAR4/RAR5 inspection; inert previews; ZipCrypto/WinZip AES read and create; deterministic unencrypted ZIP/TAR/tar.gz; cross-format comparison; selected-file verification and repackaging | Path, entry-count, expanded-size and compression-ratio limits; no direct filesystem restoration or nested expansion; multipart ZIP and 7z/RAR decompression/extraction remain unsupported; links and special entries are inventory-only and blocked from restoration |
| **`privacy-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect image metadata and make independently verified sharing copies | Deep JPEG/PNG/WebP EXIF/IPTC/XMP/profile/preview/provenance/trailing-data scans; orientation-normalized re-encoding with mandatory output rescan and pixel comparison; source/output hashes; pseudonymized safe-share and detailed JSON/ZIP reports; reusable remove/preserve/review policy evidence | Not an anonymity guarantee; verified re-encoding is limited to complete static JPEG/PNG/WebP scans, while other recognized formats are inventory/inspect-only; re-encoding can change pixels and remove colour, resolution and authenticity information; detailed reports can contain sensitive metadata |
| **`crypto-tools`** | Current local-first v0.2.0 inspection and operations release; dedicated repository | Inspect certificates, requests, CRLs, keys, encrypted PKCS #8, PKCS #12/PFX and JWK/JWKS material, and run fixed-profile local cryptographic operations | Bounded X.509/CSR/CRL, PBES2/PBKDF2 PKCS #8 and PKCS #12 inspection/decryption; JWK/JWKS and RFC 7638; explicit certificate-path checks without trust claims; DNS SAN checks; fixed-profile RSA-PSS/PKCS1, ECDSA and browser-supported Ed25519 sign/verify; RSA-OAEP and AES-256-GCM text operations | No browser/OS trust implication, complete RFC 5280 validation, revocation service, issuance, CMS/JWS, legacy PKCS #1/SEC1 conversion, legacy PKCS #12 PBE or general-purpose file cryptography; sensitive inputs remain bounded and memory-only, with documented temporary-buffer wiping |
| **`barcode-tools`** | Current local-first v0.2.0 release; dedicated repository | Generate and decode QR codes and common barcodes | SVG QR, Data Matrix, PDF417, Aztec and selected linear formats; bounded image or explicit camera decode; escaped structured QR payloads; deterministic CSV batch ZIP; common GS1 AI/FNC1/date/check-digit/decimal validation; GTIN checks; physical/raster planning and print-sized SVG export | Decoded payloads remain inert text and are never opened automatically; camera is path-scoped and user initiated; generated output, GS1 allocation and print quality still require applicable interoperability checks |
| **`network-tools`** | Current offline v0.2.0 release; dedicated repository | Calculate IP networks and construct or inspect common network values | IPv4/IPv6 canonicalization and CIDR ranges plus largest-first IPv4 VLSM; URL/query parsing with password-redacted display; DNS-record construction and bounded inert zone-file parsing; CSP and HTTP security-header analysis/builder; offline MIME reference | Performs no DNS, URL, HTTP or scanning request; pasted values remain bounded and inert; results are construction and calculation aids rather than live network observations |
| **`geo-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, edit, convert, simplify, measure and analyse geospatial files locally | GeoJSON, GPX, KML and coordinate CSV; full Point/MultiPoint/LineString/MultiLineString/Polygon/MultiPolygon/nested GeometryCollection model; bounds, distance, elevation and simplification; validated feature/coordinate edits and line reversal; track inventory; local distance/bearing/midpoint ruler; coordinate-only sketch | Full geometry model retains scalar properties, while GPX/CSV conversion may flatten grouping; no topology repair, CRS transformation, basemap request or survey-grade claim; conversion losses are explicit |
| **`helper-tools`** | Current v0.2.0 app and reusable package release | Encode, convert, inspect and calculate with shared bounded primitives | Base/byte/text/URL conversion; byte cursors and streams; worker jobs; Unicode and line transforms; exact numbers and units; incremental hashes; CIDR; timestamps; hardened JSON/CSV; random primitives | Framework-free `@add-ideas/toolbox-helpers` 0.2.0 is consumed directly across the Toolbox app set; operations disclose strictness, limits and non-cryptographic seeded boundaries |
| **`rand-tools`** | Local-only v0.2.0 release; dedicated repository | Generate secure or reproducible random values through focused workspaces | Unbiased WebCrypto integers/strings; explicitly seeded deterministic generation; UUIDv4/v7 and ULID; dice, samples, shuffles, passphrases and normal values; local coin/card/date/fraction/spherical draws; exact weighted sampling; versioned executable recipes; domain-separated WebCrypto commitreveal | Secure local generation never falls back; deterministic output is reproducible rather than secret; the app makes no third-party randomness request and the Portal grants it no external network destination |
| **`data-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, format, query, infer schemas, edit, flatten and convert structured data | JSON, YAML 1.2, TOML, XML, CSV, TSV and NDJSON; exact JSON numbers; bounded tree/table/leaf views; JSON Pointer and safe path queries; sample-labelled JSON Schema inference; reviewed immutable RFC 6901 add/replace/remove edits; registry-backed all-format conversion with loss/coercion reports; spreadsheet-formula neutralization | Disposable bounded parser worker; rejects active XML constructs and unsafe object keys; conversions surface information loss and round-trip instability |
| **`diff-tools`** | Current local-first v0.2.0 release; dedicated repository | Compare text and structured files, build directory manifests and perform bounded three-way merges locally | Line/word/code-point/grapheme text diff; exact-number JSON/RFC 6902; namespace-aware XML; keyed CSV/TSV; bounded directory manifests; line-oriented three-way merge; portable reports | Normalization and ignored distinctions remain visible; bounded disposable workers and two-file hash concurrency; directory comparison is manifest-based and merge conflicts remain explicit |
| **`time-tools`** | Current local-first v0.2.0 release; dedicated repository | Convert exact timestamps, plan across IANA zones and inspect calendars, arithmetic and recurrences locally | Signed nanosecond epochs; IANA-zone/DST comparison; wall-clock versus elapsed arithmetic; explicit Unix/Vixie, GitHub Actions, Croner, Quartz and EventBridge cron dialects; RRULE previews; multi-participant meeting planner; business days; bounded ICS import with EXDATE/RDATE and recurrence overrides; escaped UTC ICS export | Uses browser IANA data and does not model leap seconds; holidays are only those supplied; custom VTIMEZONE data is inventoried but not guessed when the browser cannot execute its TZID; URLs and attachments are inert and never fetched |
| **`text-tools`** | Current local-first v0.2.0 release; dedicated repository | Build ordered, inspectable plain-text transformation pipelines | Ordered literal/line transforms; locale case, Unicode normalization and transliteration; strict escape/decode stages; RFC-style quoted CSV column selection; explicit UTF-8, UTF-16LE and Latin-1 file decoding with byte evidence; versioned recipes and paired text/provenance artifacts | Exact source/result and per-step changes stay visible; compatibility normalization, transliteration, narrow encodings and selected transforms may be lossy; artifact evidence is portable, but automatic Toolbox handoff is not enabled in v0.2.0 |
| **`unicode-tools`** | Current local-first v0.2.0 release; dedicated repository | Search and inspect Unicode characters, emoji, scripts, text and confusables | Checksum-pinned Unicode 17.0 catalogue and virtualized code chart; name/alias/code-point search; emoji and named sequences with bounded variant construction; UTF-8/UTF-16/escape and grapheme inspection; normalization; UTS #39 skeleton, Identifier_Status/Type and restriction evidence; selected Unihan fields; source-identity reports | Official Unicode data is redistributed under Unicode-3.0 and no symbol-site content is scraped; unassigned, private-use, noncharacter and surrogate states remain distinct; constructed emoji do not claim RGI or font support; confusable/mixed-script findings are review signals, not verdicts |
| **`flow-tools`** | Current local-first v0.2.0 release; dedicated repository | Design and run deterministic structured-data pipelines | Bounded JSON, CSV, NDJSON and XML sources; select, rename, filter, map, sort, group, join, type-format, deduplicate, slice and explode stages; per-stage snapshots, analysis and loss notes; validated recipes plus JSON/CSV and inert pipeline-SVG export | 2 MiB sources, 10,000 input rows, 20,000 expanded rows, 200 fields, 30 stages and 256 KiB recipes; no arbitrary code, eval, plug-in or network stage |
| **`subtitle-tools`** | Current local-first v0.2.0 release; dedicated repository | Edit, validate, synchronize, compare and convert captions | Bounded SRT, WebVTT, ASS/SSA and flat-profile TTML/DFXP; cue add/duplicate/split/merge/delete and direct editing; shift/stretch, frame-rate conversion and snapping; editorial diagnostics and index-aligned revision comparison; immediate media playback with cancellable waveform extraction and navigation; explicit UTF-8/UTF-16/Latin-1 decoding | Preserves format-specific data where possible and reports conversion loss; TTML regions, styling definitions and inherited timing are inspected but not laid out and export is a flat resource-free profile; no speech recognition, automatic alignment, semantic comparison or pixel-perfect ASS rendering |
| **`midi-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, visualize, edit, audition and export Standard MIDI files | SMF type 0/1 events and metadata; worker-backed edit/export with progress and cancellation; tempo/time/key timelines and piano roll; paired-note editing, transpose, quantize, tempo, crop and channel operations with undo; Web Audio preview and opt-in Web MIDI output; bounded local SF2/SF3 structure inspection; deterministic MIDI/CSV/JSON export | 8 MiB, 256-track and 250,000-event caps; PPQN only; Web MIDI is permission-gated and sends channel-note messages without SysEx; SF2/SF3 is inspection-only; the bounded sine preview is not a General MIDI or SoundFont renderer |
| **`3d-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, preview, repair and export triangle meshes | OBJ, binary/ASCII STL, ASCII/binary little-endian PLY and embedded glTF/GLB 2; selected-scene hierarchy/TRS/matrix and instancing flattening; material, node, bounds, area and degeneracy statistics; worker-backed capped WebGL preview; normal/degeneracy repair and transform baking; normalized OBJ, binary STL and ASCII PLY export | 32 MiB and one-million-vertex/triangle caps; glTF is an embedded FLOAT POSITION/NORMAL TRIANGLES subset with no external assets, sparse accessors, animation, skins, texture or compression decoding; selected-scene transforms and instances are baked into the normalized mesh, but source material graphs are not recreated |
| **`query-tools`** | Current local-first v0.2.0 release; dedicated repository | Query structured local data through bounded row and path languages | JSON, CSV, NDJSON and inert XML with raw inference/precision evidence; parsed SQL/path syntax trees; focused SQL-like and JSONPath-like modes; optional bounded read-only DuckDB-WASM SELECT mode; table/tree/JSON views, saved queries and JSON/CSV/NDJSON export | Built-in modes are not full SQL, JSONPath or JMESPath; 2 MiB/10,000-row-or-value/200-field/200,000-node caps; DuckDB is capped at 10,000 input and 1,000 result rows, 128 MiB, 30-second startup and ten-second queries with no files, network, extensions, DDL/DML, COPY or PRAGMA; hosting needs correct WASM MIME/cache and scoped `wasm-unsafe-eval` |
| **`scan-tools`** | Current local-first v0.2.0 release; dedicated repository | Correct photographed pages, run optional OCR and assemble local output | Up to 24 PNG/JPEG/WebP pages; precise four-corner projective correction, rotate/deskew, tonal, grayscale and threshold controls in cancellable workers with bounded fallback; drag reorder; PNG/JPEG and image-only PDF export; bundled same-origin English OCR with word geometry plus text, hOCR, TSV and combined multipage-text export | Camera is exact-path and opt-in; strict pixel/byte/page caps; English-only OCR may use roughly 100300 MiB transient memory and is not an accuracy guarantee; no PDF input, automatic corners, handwriting guarantee, shadow/finger removal or searchable PDF text layer |
| **`package-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect and compare ZIP/ZIP64 compound packages | ZIP/ZIP64 tree and risk diagnostics; EPUB, OOXML, ODF, JAR, APK and WebExtension adapters; relationships, manifests and orphan evidence; signature-material/digest plus dependency/licence inventories; bounded text/media preview and verified entry download/share; decompressed SHA-256 comparison with safe semantic diffs; JSON inventory export | Inspection is not a specialized renderer, APK signing-block decoder, signature/trust verifier, dependency resolver, vulnerability scanner or legal licence interpretation; encrypted, split, unsafe, unsupported and over-budget entries stay inventory-only; an explicitly chosen OS share target may upload an entry even though the app itself does not |
| **`label-tools`** | Current local-first v0.2.0 release; dedicated repository | Merge local records into printable labels, badges and asset tags | CSV/JSON mapping; visual text/image/barcode/shape template designer with drag, keyboard and exact-unit positioning; serial/random values; ten QR/1D/2D barcode formats; stock/custom grids, calibration and marks; template JSON; paginated preview; physical-size SVG, deterministic multi-page ZIP and vector PDF export | 2 MiB/2,000-row/100-field data bounds and bounded images/pages; stock names are geometries, not vendor certification; system fonts are not embedded; vector PDF uses built-in Helvetica/WinAnsi, visibly replaces unsupported characters and omits WebP images, so it is print-dimensioned rather than archival/press quality |
| **`font-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, compare, preview and prepare local fonts | TTF, OTF, WOFF, WOFF2, TTC and OTC metadata/tables; Unicode coverage, variable axes, GSUB/GPOS inventories and embedding signals; sandboxed shaping/fallback comparison; safe CSS; validated collection face selection; rights-confirmed static glyf/CFF subset with loss report | Disposable eight-second worker and strict file/table/face/glyph bounds; WOFF2 is decoded locally and TTC/OTC faces are reconstructed only for bounded in-memory preview; WOFF2/collection subset and collection export remain disabled; fsType is technical evidence, variable flattening is unsupported and browser shaping is not a HarfBuzz reference |
| **`fixture-tools`** | Current local-first v0.2.0 release; dedicated repository | Generate deterministic synthetic test fixtures | Focused JSON Schema, SQL DDL, XSD, CSV-heading and portable-model import; scalar/composite uniqueness and foreign keys; dependency-topological generation with uniform, sequential, normal and constant distributions; boundary/intentional-negative cases and a violation ledger; coverage matrix; person/network/commerce provider profiles; JSON/CSV/NDJSON/XML/SQL/recipe export | Importers are documented subsets; remote references, schema code, database access, XML entities, unsupported XSD/SQL constructs and cyclic relational recipes are rejected; 2 MiB input, 20 tables, 100 fields/table, 50,000 rows, 100,000 values and 8 MiB/output caps; synthetic data is not anonymization and seeded output is reproducible, not secret |
| **`minimize-tools`** | Current local-first v0.2.0 release; dedicated repository | Reduce failing inputs while continuously preserving a selected predicate | Line/token/code-point and structure-aware JSON/XML reduction; literal, syntax, timing, isolated-regex, focused JSON Schema and restricted local-XSLT predicates with failure-signature preservation; single/majority/strict retry voting and flaky evidence; bounded multi-file bundle adapters; budgets, cancellation and deterministic minimized-case/trace/report export | Locally minimal under attempted transformations and budget, not globally shortest; schema/XSLT subsets fail closed; 2 MiB input, 2,000-test/30-second, one-second-regex and 200-XSLT-test caps; bundles are limited to 100 files/4 MiB and adapters neither emulate a filesystem nor execute a target program |
| **`format-lab`** | Current local-first v0.2.0 release; dedicated repository | Explore conversion paths and measure representative round-trip loss | Conservative data/image/AV/subtitle format graphs; executable JSON/NDJSON/CSV/typed-XML record conversion; property selection and loss-aware path ranking; measured round trips beside catalogue expectations; versioned evidence envelopes and catalogue export; masked-offset signature catalogue; deterministic edge-case corpus and reports | Media graphs plan handoffs rather than duplicate codecs; executable conversion handles bounded canonical records, not arbitrary documents; catalogue expectations are not file measurements; signature hits suggest likely containers but do not validate safety or format conformance; catalogue-only formats are not claimed executable |
| **`repro-tools`** | Current local-first v0.2.0 release; dedicated repository | Build, compare, sign and package reproducible local file inventories | Cancellable streamed SHA-256/SHA-512 manifests with deterministic paths and JSON/CSV; reference comparison; fixed-metadata ZIP; streaming ZIP-content manifests and compression-independent comparison; CycloneDX/SPDX/npm-lock inventory with portable evidence and explicit non-conformant local provenance; optional memory-only P-256 signature envelope | 64 MiB/file, 256 MiB/selection and 10,000-entry caps; ZIP creation is capped at 128 MiB and inspection at 5,000 entries/256 MiB expanded; signatures prove integrity only relative to an independently authenticated public key and are intentionally not byte-reproducible; provenance makes no SLSA, authority or builder-identity claim |
| **`schema-tools`** | Hardened local-first v0.2.0 release; dedicated repository | Inspect, validate, compare and derive examples from schema workspaces | Local JSON Schema/OpenAPI reference graphs; focused JSON Schema validation; OpenAPI operation/sample/change analysis; XSD, Relax NG and Schematron structure; bounded heuristic XML samples | Remote/escaping references, entities, code and XPath are blocked; JSON Schema/OpenAPI support is a documented subset, while XML languages receive structural inspection rather than complete instance validation; shared work/node/depth/text/output budgets, linear cached traversal and well-formed XML fallbacks are regression-tested |
| **`log-tools`** | Current local-first v0.2.0 release; dedicated repository | Stream, inspect, correlate, redact and export large logs | Incremental UTF-8 file scan; plain, JSONL, nginx, syslog and logfmt parsing with configurable Java/.NET/Python/generic multiline assembly; whole-scan aggregates; bounded multi-file temporal merge with trace/span and request-ID correlation; search/filter and deterministic redaction; OTLP/JSON plus CSV/NDJSON/text export, including a complete cancellable second pass with direct-file or bounded-Blob output | Eight-GiB gate and five-million-line stop without whole-file strings; interactive search/redaction uses a 10,000-record/32 MiB preview, while complete single-source export reapplies filters and recipes in a second streaming pass; multi-file correlation uses explicitly bounded retained evidence; parsers and auto/multiline detection are focused heuristics |
| **`binary-tools`** | Current local-first v0.2.0 release; dedicated repository | Convert, inspect and decode byte-oriented values | Synchronized UTF-8/hex/Base64/Base32/Base58; checked byte insert/replace/delete; exact and wildcard search with isolated-worker deadline; paged byte inspector and endian integer/float/timestamp interpretations; bookmarks and audited PNG/RIFF/ELF templates; CBOR, MessagePack, strict DER and schema-assisted Protocol Buffers | Inert with no requests or evaluation; 1 MiB input/edit/output, depth-64 and 10,000-node bounds; Base58 and search patterns are capped at 4 KiB and large searches use a five-second disposable worker; protobuf groups/full generated runtime and complete template-based format validation are out of scope |
| **`git-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect and author Git interchange text without repository access | Unified/git patch inspection and bounded authoring; exact atomic patch apply/reverse against explicit text snapshots with JSON/ZIP export; layered `.gitignore` plus tracked-state explanations; root `.gitattributes` evaluation; SemVer ranges; Conventional Commit build/lint and advisory release plan; changelog normalization | Patch/diff-matrix/snapshot bounds; patch application is exact, atomic and text-only against an explicit local JSON snapshot; ignore analysis models layered supplied global/info/nested sources and tracked state but not command-line excludes or submodule boundaries; attribute macros/nested attribute files are unsupported; no workspace or `.git` access |
| **`api-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect and compare HTTP and event API descriptions and check saved HTTP evidence | Bounded JSON/YAML OpenAPI 3.03.2 and AsyncAPI 2.03.1; local multi-file `$ref`; path/webhook/channel/message navigation; security inventory and focused examples; inert curl/Fetch/Python text; conservative revision comparison; HAR 1.2 coverage and focused contract checks | Never executes HTTP, opens a broker connection, follows URLs, resolves remote references or stores credentials; focused OpenAPI/AsyncAPI/JSON Schema validation, examples and HAR checks are not a complete validator, code generator, HTTP/broker client, proxy or security scanner |
| **`mail-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, thread, compare, download and redact EML/MIME and mbox content | Original-octet EML/MIME with RFC 2047 and RFC 2231 headers; bounded multipart/nested-message tree; Base64/quoted-printable and byte-safe attachments; mbox/mboxrd threading/search; text and opaque sandboxed HTML with safe local CID images; auth-header diagnostics plus pasted-key RSA/Ed25519 DKIM verification; canonical and deeper redacted export | Remote/active HTML is removed and never loaded; no mail/DNS contact, mailbox client, decryption, sender-identity, malware or anonymity claim; local DKIM verification proves preserved bytes only against the pasted key and cannot establish that key's authenticity or currency; canonical/redacted export does not promise byte identity |
| **`calendar-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, repair, merge and reconcile iCalendar data | RFC 5545 events, VTODO, VJOURNAL, VFREEBUSY, VALARM, attendees and VTIMEZONE; recurrence preview with moved/cancelled/duration-changing/RANGE=THISANDFUTURE overrides; duplicate/overlap diagnostics and UID/RECURRENCE-ID merge; canonical repair and DST evidence; agenda/month views, bounded event/task authoring and free-slot planning; lossless jCal and focused JSCalendar Event/Task interchange | 4 MiB plus line/component/event and recurrence-horizon caps; browser IANA data and focused recurrence interpretation are evidence, not a calendar-server implementation; JSCalendar is a focused Event/Task adapter with explicit loss warnings |
| **`contact-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect, edit, convert and reconcile sensitive contacts | vCard 2.1/3/4 parsing, core editing and canonical export; bounded quoted-printable/Base64 decoding plus grouped and unmapped-property preservation; inferred reviewable CSV mapping; jCard and focused JSContact import/export with loss evidence; duplicate candidates, conflict-reporting merge and bounded local vCard QR | 2 MiB, 50,000-line and 2,000-contact caps; encoded properties are capped at 64 KiB and malformed encodings retain raw evidence; JSContact support is focused and unsupported values are surfaced rather than silently lost; no persistence or telemetry |
| **`diagram-tools`** | Current local-first v0.2.0 release; dedicated repository | Author safe deterministic text diagrams and export accessible graphics | Independent script-free flow/graph, sequence, class, state, entity-relationship, mind-map and timeline grammars; line diagnostics, examples, pan/zoom, normalized JSON, deterministic SVG/2× PNG and accessible textual outline/source export | Not full Mermaid or Graphviz; directives, clicks, styles, scripts, HTML and remote assets are rejected; 50,000-character, 2,000-line, 200-node, 500-edge and 20-megapixel caps |
| **`token-tools`** | Current local-first v0.2.0 release; dedicated repository | Edit, validate, theme and export design tokens | DTCG-style nested `$type`/`$value` JSON with inherited groups plus local sets/themes/modes; recursive aliases inside composite values with cycle/missing/type diagnostics; colour, dimension, duration, font, Bézier, stroke, border, transition, gradient, typography, shadow and scalar tokens; W3C-style JSON, CSS, Sass, Android and Swift export with collision and loss reports | The `$sets`/`$themes` wrapper is app-specific; 1 MiB, depth-64, 10,000-token and 50,000-node bounds; malformed wrappers, unknown types and token/group conflicts fail explicitly; Android/Swift composite output requires project conventions and unsupported values are reported as losses |
| **`device-tools`** | Current local-first v0.2.0 release; dedicated repository | Inspect browser capability evidence without creating a device fingerprint | Passive context/display/input/accessibility/media/storage/PWA/API inventory; individually initiated permission, storage, WebGL/WebGPU, media-device, battery, network, camera, microphone and screen probes; pasted Toolbox-manifest compatibility analysis with required/optional/unknown capability evidence; opt-in MediaCapabilities codec lab; deterministic bucketed JSON/CSV reports | No identifier, uniqueness score, high-entropy report, recording, persistence, canvas/audio fingerprint or passive permission prompt; sensitive probes are exact-path and individually initiated, returned tracks stop immediately, and downloaded reports bucket precision; results are capability evidence, not a reliability guarantee |
## Planned tools
| Tool | State and boundary | Principal workflows | Important concrete scope | Critical considerations and integrations |
| -------------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **`flow-tools`** | Later platform layer | Compose local processing operations across tools | Example: CSV → filter → QR generation → SVG template → PDF → ZIP; reusable recipes; typed inputs and outputs; progress and cancellation | Do not load complete React applications into one runtime; expose separate worker-safe operation packages only after several apps have stable operations |
| **`file-tools`** | High priority; dedicated repository | Identify, inspect and organize local files | Magic-byte detection; hex view; decoded strings; checksums; directory manifests; split/join; duplicate detection; trailing-data detection; batch-rename preview | All inputs are untrusted; format inspectors require strict size and nesting limits; natural entry point to archive, privacy, crypto and package tools |
| **`image-tools`** | High priority; dedicated repository | Edit and batch-process raster images | Crop, resize, rotate, compress, convert, contact sheets, sprites, responsive sets, favicon generation, metadata removal and visual quality comparison | Use workers and off-main-thread rendering; preserve or deliberately remove colour profiles; integrate with colour, SVG, PDF and privacy tools |
| **`subtitle-tools`** | Medium priority; dedicated repository | Edit, validate and synchronize captions | SRT, WebVTT and ASS; timing shifts; stretching; frame-rate conversion; overlap and reading-speed checks; waveform synchronization; revision comparison | Direct integration with `av-tools`; preserve style information when supported and disclose conversion losses |
| **`midi-tools`** | Medium specialist app | MIDI event inspection and editing; transpose, quantize, tempo maps and controller data; device access should remain optional | |
| **`3d-tools`** | Large specialist app | Inspect STL, OBJ and glTF; dimensions, bounding boxes, mesh simplification and common geometry defects; worker/GPU use and file limits | |
| **`query-tools`** | High-value but large; dedicated repository | Analyse local tabular and relational data with SQL | CSV, JSON, NDJSON, Parquet and SQLite; schema inference; joins; aggregation; pivots; charts; export to common data formats | WASM memory and streaming; distinguish this analytical product from document-oriented `data-tools`; query work must remain local |
| **`epub-tools`** | Medium app | EPUB inspection, metadata and cover editing, link validation, chapter extraction and structural repair; sanitize embedded HTML and SVG | |
| **`scan-tools`** | Large app | Camera/document correction; crop, deskew and threshold; page assembly; local OCR; PDF output; model downloads and memory use must be explicit | |
| **`office-tools`** | Medium-to-large app | Inspect rather than reproduce an office suite: package structure, relationships, metadata, comments, embedded images and basic repairs | |
| **`package-tools`** | Medium priority | Inspect compound and package-based formats | EPUB; DOCX/XLSX/PPTX; ODF; JAR; APK; browser extensions; package trees; manifests; relationships; embedded media; signatures; orphaned parts | Generic container inspector with format adapters; complements rather than replaces `onenote-tools`, `epub-tools` and `office-tools` |
| **`archive-tools`** | Medium-to-high priority; dedicated repository | Inspect, create, compare and extract archives | ZIP, TAR, gzip and selected additional formats; selective extraction; content preview; deterministic archives; timestamp normalization; archive comparison | Expansion-ratio, entry-count and total-size limits; traversal-safe extraction; never execute extracted files |
| **`privacy-tools`** | High priority; dedicated repository | Inspect and remove metadata before sharing | EXIF and GPS; document author/comments; embedded thumbnails; PDF metadata and attachments; hidden package entries; AV tags; personal filenames; structured safe-sharing report | Never promise absolute anonymity; explicitly state inspected, removed, preserved and unsupported structures; integrate with most file-oriented apps |
| **`crypto-tools`** | Planned; dedicated repository | Inspect keys, certificates and signatures; validate chains | X.509 PEM/DER, CSR, CRL, PKCS #8, encrypted PKCS #8, PKCS #12/PFX, JWK/JWKS; key/certificate matching; path construction; hostname, purpose and time checks; CMS/JWS later | Inspection-first; explicit trust anchors; no implication that browser/OS trust stores are used; no private-key persistence; offline revocation first; network checks opt-in; restrictive CSP and worker isolation |
| **`barcode-tools`** | Planned; dedicated repository | Generate, inspect and decode QR and barcodes | QR, common one- and two-dimensional codes; camera/image decoding; GS1 assistance; CSV batch generation; quiet-zone and print-size checks; structured payload builders | Treat decoded payloads as untrusted; never open links automatically; camera permission must be optional; integrate with `label-tools`, `contact-tools` and `crypto-tools` |
| **`label-tools`** | Medium priority; dedicated repository | Generate labels and badges from templates and data | CSV/JSON merge into SVG templates; QR/barcode fields; serial numbers; A4 label sheets; badges; asset tags; cut marks; calibration | Strong suite demonstration linking data, SVG, barcode, random and PDF capabilities; print dimensions must be explicit and testable |
| **`font-tools`** | Medium priority; dedicated repository | Inspect, preview and prepare fonts | Glyph coverage; variable axes; metadata; fallback comparison; subsetting; CSS generation; arbitrary-text previews | Font licensing and embedding restrictions must be visible; use untrusted-font isolation and strict parser limits |
| **`fixture-tools`** | Medium priority | Generate deterministic test data | JSON Schema, XSD, SQL DDL, CSV headings or interactive models to JSON, CSV, XML, SQL and NDJSON; foreign keys; distributions; boundary and invalid cases | Seeded reproducibility; uniqueness constraints; privacy-safe synthetic data; natural extension of `rand-tools` |
| **`minimize-tools`** | Distinctive specialist tool | Reduce a failing input while preserving a failure | Minimize XML triggering an XSLT error; shortest regex pathological input; smallest JSON schema failure; selectable failure predicates | Expensive repeated execution must be bounded and cancellable; record the exact predicate and transformation versions |
| **`format-lab`** | Later, distinctive product | Explore conversion paths and information loss | Format graph; round-trip tests; property preservation; type coercion; metadata loss; recommended path selection across data, image, AV and subtitle formats | No conversion should be described as lossless without testing relevant properties |
| **`repro-tools`** | Medium-to-later | Create manifests and provenance records | File hashes; directory manifests; operation history; tool/version/parameter records; deterministic package creation; verification reports | Useful foundation for reproducible workflows and signed manifests; integrates with crypto, archive and flow tools |
| **`schema-tools`** | Dedicated specialist app | Validate, inspect and generate examples for JSON Schema, XSD, Relax NG, Schematron and OpenAPI; visualize references and incompatibilities | |
| **`log-tools`** | Dedicated app | Stream and filter large logs; parse common formats; correlate records; build timelines; extract fields; anonymize values; avoid loading the complete file into memory | |
| **`network-tools`** | Helper family or small app | IPv4/IPv6 subnetting; CIDR ranges; URL and query parsing; DNS-record construction; HTTP headers; CSP generation; MIME lookup; avoid turning it into an intrusive scanner | |
| **`binary-tools`** | Dedicated specialist app | Base64, hexadecimal, CBOR, MessagePack, ASN.1 and Protocol Buffers; schema-assisted decoding; byte-range highlighting; strict depth and size limits | |
| **`git-tools`** | Small-to-medium app | Patch inspection and editing; `.gitignore` testing; semantic-version comparison; conventional commits; changelog normalization; no repository-hosting dependency | |
| **`api-tools`** | Medium app | OpenAPI validation; request and response examples; curl and client-command generation; saved HTTP-exchange inspection; direct browser requests remain subject to CORS | |
| **`mail-tools`** | Medium app | EML and MIME inspection; header analysis; attachment extraction; body-part comparison; HTML mail must be heavily sandboxed | |
| **`calendar-tools`** | Small-to-medium app | ICS inspection, merging, deduplication, repair, recurrence visualization and timezone diagnostics | |
| **`contact-tools`** | Small-to-medium app | vCard inspection and editing; CSV mapping; deduplication; contact QR generation; treat all contact data as sensitive | |
| **`geo-tools`** | Medium app | GeoJSON, GPX, KML and coordinate CSV; format conversion; track simplification; distance/elevation analysis; coordinate-reference assumptions must be explicit | |
| **`diagram-tools`** | Medium app | Code and visual editing for Mermaid, Graphviz and related representations; renderers require sanitization and sandboxing | |
| **`token-tools`** | Small-to-medium app | Design-token editing and conversion between JSON, CSS custom properties, Sass, Android and iOS forms; integrate with colour and SVG tools | |
| **`device-tools`** | Specialist app | Serial terminal, sensor logger, microcontroller console and controlled firmware installation; explicit permission and browser-capability checks | |
## Planned helpers
Helpers export funcionality for other tools to use. They may also present a tool surface to be used directly
| Tool | State and boundary | Principal workflows | Important concrete scope | Critical considerations and integrations |
| ------------------- | ------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| **`helpers-tools`** | One shared artifact with deep links | Stateless Base64, URL encoding, case conversion, number bases, Unicode code points, unit conversion, small checksums, subnet and timestamp calculators; avoid a repository per calculator | |
| **`colour-tools`** | Planned; small-to-medium dedicated repository | Colour conversion, calculation and palette work | sRGB, Display P3, Lab, LCH, OKLab and OKLCH; gamut mapping; contrast; colour-vision simulation; gradients; palette extraction; design-token export | Make colour-space assumptions explicit; distinguish mathematical conversion from display simulation; integrate with SVG, image and token tools |
| **`rand-tools`** | Planned; small dedicated repository | Generate random numbers, strings, identifiers and samples | Cryptographically secure generation; deterministic seeded generation; UUIDs, ULIDs, passphrases, dice notation, distributions, weighted selection and shuffling | Clearly separate secure randomness from reproducible pseudorandomness; no misleading “strength” claims; natural foundation for `fixture-tools` |
| **`data-tools`** | High priority; dedicated repository | Inspect, edit, validate, query and convert structured data | JSON, YAML, TOML, XML, CSV and NDJSON; tree/table/source views; schema inference; flattening; filtering; field mapping; JSONPath-style queries; conversion recipes | Every conversion should disclose information loss, coercion and round-trip instability; XML-specialist workflows hand off to `xslt-tools` |
| **`diff-tools`** | High priority; dedicated repository or shared engine plus UI | Compare documents and files semantically | Text; JSON object-aware comparison; XML normalization; CSV keyed comparison; images with overlay/heatmap; archives and directories; PDF pages; optional audio waveform comparison | Normalization and ignored properties must be visible; produce portable reports and standard patch formats where possible |
| **`text-tools`** | Medium priority; one app with deep-linked panels | Transform and normalize plain text | Unicode normalization; line-ending conversion; encoding; sorting; deduplication; case changes; transliteration; escaping; column operations; transformation pipelines | Preserve exact input/output visibility; warn about lossy encodings and Unicode confusables; integrate regex operations |
| **`time-tools`** | Medium priority; small dedicated app or helper family | Work with dates, timestamps, time zones and recurrences | Unix timestamps; date arithmetic; durations; ISO 8601; timezone comparison; cron; RRULE; ICS generation; business days; DST-transition visualization | Visualize actual recurrence instances and ambiguous/skipped local times; do not rely on simplified fixed-offset calculations |
No unreleased applications are currently listed here. New ideas should be added
only after their intended local-processing boundary and first honest release
scope are documented; shipped applications remain in the Existing tools table.
## Licensing
+1 -1
View File
@@ -3,7 +3,7 @@ services:
build:
context: .
dockerfile: Containerfile
image: git.add-ideas.de/lotobo/toolbox:0.13.0
image: git.add-ideas.de/lotobo/toolbox:0.20.3
restart: unless-stopped
read_only: true
ports:
+3 -3
View File
@@ -6,9 +6,9 @@ services:
context: .
dockerfile: Containerfile.release
args:
TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.13.0}"
TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-ae8d96906ad6794c1c387863dbd0d6d31e1c5deeef7640362f8a479dbf3f3891}"
image: "git.add-ideas.de/lotobo/toolbox:${TOOLBOX_RELEASE_VERSION:-0.13.0}"
TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.20.3}"
TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-66f02f95092ef80b9e49cda91c8401400e2ee1d2c640ab20a3a7810bf265c2c7}"
image: "git.add-ideas.de/lotobo/toolbox:${TOOLBOX_RELEASE_VERSION:-0.20.3}"
restart: unless-stopped
read_only: true
tmpfs:
+14 -4
View File
@@ -14,9 +14,12 @@ map $uri $toolbox_access_control_allow_origin {
"/apps/svg/canvas-frame-controller.js" "*";
}
map $host $toolbox_permissions_policy {
default "camera=(), microphone=(), geolocation=(), payment=(), usb=()";
"auth.toolbox.add-ideas.de" "camera=(self), microphone=(), geolocation=(), payment=(), usb=()";
map "$host:$uri" $toolbox_permissions_policy {
default "camera=(), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";
"~^auth\.toolbox\.add-ideas\.de:" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";
"~^[^:]+:/apps/barcode(?:/|$)" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";
"~^[^:]+:/apps/scan(?:/|$)" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";
"~^[^:]+:/apps/device(?:/|$)" "camera=(self), microphone=(self), display-capture=(self), geolocation=(), payment=(), usb=()";
}
server {
@@ -37,7 +40,7 @@ server {
add_header Cross-Origin-Resource-Policy $toolbox_resource_policy always;
add_header Access-Control-Allow-Origin $toolbox_access_control_allow_origin always;
add_header Permissions-Policy $toolbox_permissions_policy always;
add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self' data:; connect-src 'self'; worker-src 'self' blob:; manifest-src 'self'" always;
add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self' data: blob:; connect-src 'self'; worker-src 'self' blob:; manifest-src 'self'" always;
add_header Cache-Control $toolbox_cache_control always;
gzip on;
@@ -63,6 +66,13 @@ server {
try_files $uri =404;
}
location ~* ^/apps/scan/ocr/lang/[a-z0-9_-]+\.traineddata\.gz$ {
types {
application/gzip gz;
}
try_files $uri =404;
}
location ~* \.(?:css|js|mjs|woff2?|png|jpe?g|gif|webp|svg|ico|webmanifest)$ {
try_files $uri =404;
}
+47 -47
View File
@@ -1,16 +1,16 @@
{
"name": "@add-ideas/toolbox-portal",
"version": "0.2.15",
"version": "0.2.23",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "@add-ideas/toolbox-portal",
"version": "0.2.15",
"version": "0.2.23",
"license": "AGPL-3.0-only",
"dependencies": {
"@add-ideas/toolbox-contract": "^0.2.3",
"@add-ideas/toolbox-shell-react": "^0.2.3",
"@add-ideas/toolbox-contract": "^0.3.0",
"@add-ideas/toolbox-shell-react": "^0.3.0",
"@dnd-kit/core": "^6.3.1",
"@dnd-kit/sortable": "^10.0.0",
"@dnd-kit/utilities": "^3.2.2",
@@ -44,18 +44,18 @@
}
},
"node_modules/@add-ideas/toolbox-contract": {
"version": "0.2.3",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-contract/-/0.2.3/toolbox-contract-0.2.3.tgz",
"integrity": "sha512-T0PVSuMT40GjTDfQJhEEY3ZawQq8zz1/ry95JdKI6W39CdLacaRXdGnEpDCMHt+jUbf1Jz7Nat/M5dFCgKVM9A==",
"version": "0.3.0",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-contract/-/0.3.0/toolbox-contract-0.3.0.tgz",
"integrity": "sha512-dKrK7BjOFwqJaBfJuhKxZKIld4sH0AKjEn6a0yLnbdMUFY+fFv4VSLGV2tNSBD016gumc2iNqOjUj/ld7x4rtA==",
"license": "Apache-2.0"
},
"node_modules/@add-ideas/toolbox-shell-react": {
"version": "0.2.3",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-shell-react/-/0.2.3/toolbox-shell-react-0.2.3.tgz",
"integrity": "sha512-DT5lQDH48BFkFcmFLZnQh7+Cm73JzBPcmp5WzUXypfkUXpEyDYHzaXgmW4kZ0edSwh4RK4sPmx+JPtK0X4aKCQ==",
"version": "0.3.0",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-shell-react/-/0.3.0/toolbox-shell-react-0.3.0.tgz",
"integrity": "sha512-74p6JzAOG0YCAKdlc1hLofV4ZIko7vb448S75cIiM88PKm93EHl5VD7g8YVyfM56Ui97UY9dmy+Whiq4sGzpsg==",
"license": "Apache-2.0",
"dependencies": {
"@add-ideas/toolbox-contract": "0.2.3"
"@add-ideas/toolbox-contract": "0.3.0"
},
"peerDependencies": {
"react": ">=18 <20",
@@ -2008,9 +2008,9 @@
"license": "MIT"
},
"node_modules/baseline-browser-mapping": {
"version": "2.10.43",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.10.43.tgz",
"integrity": "sha512-AjYpR78kDWAY3Efj+cDTFH9t9SCoL7OoTp1BOb0mQV7S+6CiLwnWM3FyxhJtdPufDFKzmCSFoUncKjWgJEZTCQ==",
"version": "2.11.20",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.20.tgz",
"integrity": "sha512-H0ulySigv6icDJ1F7SjtdCD6PrhTpdYCmP0CactWy1+ekh0AFd0o1Wn5T8b+hnTmdBx19u9yhL6wvCylXMY7zw==",
"dev": true,
"license": "Apache-2.0",
"bin": {
@@ -2031,9 +2031,9 @@
}
},
"node_modules/brace-expansion": {
"version": "5.0.8",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
"version": "5.0.9",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz",
"integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==",
"dev": true,
"license": "MIT",
"dependencies": {
@@ -2044,9 +2044,9 @@
}
},
"node_modules/browserslist": {
"version": "4.28.6",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.6.tgz",
"integrity": "sha512-FQBYNK15VMslhLHpA7+n+n1GOlF1kId2xcCg7/j95f24AOF6VDYMNH4mFxF7KuaTdv627faazpOAjFzMrfJOUw==",
"version": "4.28.8",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.8.tgz",
"integrity": "sha512-V2NpofLblG64mfOtSgDhOJESZEGogzDMBv/q+W6oc4LXWP/q75eOXoOaaOu1EOadB9U4Bwx/e0yzbvwKH8zalA==",
"dev": true,
"funding": [
{
@@ -2064,11 +2064,11 @@
],
"license": "MIT",
"dependencies": {
"baseline-browser-mapping": "^2.10.42",
"caniuse-lite": "^1.0.30001803",
"electron-to-chromium": "^1.5.389",
"node-releases": "^2.0.51",
"update-browserslist-db": "^1.2.3"
"baseline-browser-mapping": "^2.11.12",
"caniuse-lite": "^1.0.30001809",
"electron-to-chromium": "^1.5.402",
"node-releases": "^2.0.53",
"update-browserslist-db": "^1.3.0"
},
"bin": {
"browserslist": "cli.js"
@@ -2113,9 +2113,9 @@
}
},
"node_modules/caniuse-lite": {
"version": "1.0.30001806",
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001806.tgz",
"integrity": "sha512-72Cuvd95zbSYPKq6Fhg8eDJRlzgWDf7/mtoZv6Qe/DYNCEBdNxoA3+rZAU2ZhGCpZlns3EssFavaZomckT5Uuw==",
"version": "1.0.30001810",
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz",
"integrity": "sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==",
"dev": true,
"funding": [
{
@@ -2319,9 +2319,9 @@
"peer": true
},
"node_modules/electron-to-chromium": {
"version": "1.5.393",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.393.tgz",
"integrity": "sha512-kiDJdIUawuEIcp9XoICKp1iTYDEbgguIPq526N1Q7jIQDeQ3CqoMx71025PI/7E48Ddtw2HuWsVjY7afEgNxmg==",
"version": "1.5.420",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.420.tgz",
"integrity": "sha512-2yD6XreGusOfNV+dUcvipJEXc3n/n7fgr7996aszTG+YY5E4mqM4tOq/3uhP129cazL9YHbVWSpc79ePotWtPA==",
"dev": true,
"license": "ISC"
},
@@ -3432,9 +3432,9 @@
"license": "MIT"
},
"node_modules/nanoid": {
"version": "3.3.16",
"resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.16.tgz",
"integrity": "sha512-bzlKTyNJ7+LdGIIwy8ijFpIqEQIvafahV7eYykJ8Cvh42EdJeODoJ6gUJXpQJvej1BddH8OqTXZNE/KfbWAu8Q==",
"version": "3.3.18",
"resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz",
"integrity": "sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==",
"dev": true,
"funding": [
{
@@ -3458,9 +3458,9 @@
"license": "MIT"
},
"node_modules/node-releases": {
"version": "2.0.51",
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.51.tgz",
"integrity": "sha512-wRNIrw4DmVLKQlbgOMdkMx27Wrpzes2hh5Jtbi2bjPd+4wJstWIqP5A+lscnqbm0xxmT5Bpg8Lec5ItEBwx6BQ==",
"version": "2.0.54",
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.54.tgz",
"integrity": "sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==",
"dev": true,
"license": "MIT",
"engines": {
@@ -3609,9 +3609,9 @@
}
},
"node_modules/postcss": {
"version": "8.5.20",
"resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.20.tgz",
"integrity": "sha512-lW616l85ucIQL+FocMmL7pQFPqBmwejrCMg+iPxyImlrANNJG9NHq/RkyCZopDhd8C3LA03PHRJDjkbGu8vvug==",
"version": "8.5.26",
"resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.26.tgz",
"integrity": "sha512-u82N74LFzG8ca+dD8puPnplTXoGH4fTPpVGuIbt36G3qvNlkvfD0lEAZSxaly3KX8TS/L1A1gsCEmvKmBcVbkQ==",
"dev": true,
"funding": [
{
@@ -3629,7 +3629,7 @@
],
"license": "MIT",
"dependencies": {
"nanoid": "^3.3.16",
"nanoid": "^3.3.17",
"picocolors": "^1.1.1",
"source-map-js": "^1.2.1"
},
@@ -4166,9 +4166,9 @@
}
},
"node_modules/undici": {
"version": "7.28.0",
"resolved": "https://registry.npmjs.org/undici/-/undici-7.28.0.tgz",
"integrity": "sha512-cRZYrTDwWznlnRiPjggAGxZXanty6M8RV1ff8Wm4LWXBp7/IG8v5DnOm74DtUBp9OONpK75YlPnIjQqX0dBDtA==",
"version": "7.29.0",
"resolved": "https://registry.npmjs.org/undici/-/undici-7.29.0.tgz",
"integrity": "sha512-IDxfleLmmbSskfWSUATiN1nfn2rDuvnMOqb5CWR92iIfojA0Ud+ulOAAEQ57LPr9rWmsreUyf5lwyao+7GNNVw==",
"dev": true,
"license": "MIT",
"engines": {
@@ -4183,9 +4183,9 @@
"license": "MIT"
},
"node_modules/update-browserslist-db": {
"version": "1.2.3",
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.2.3.tgz",
"integrity": "sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==",
"version": "1.3.2",
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.2.tgz",
"integrity": "sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==",
"dev": true,
"funding": [
{
+8 -5
View File
@@ -1,6 +1,6 @@
{
"name": "@add-ideas/toolbox-portal",
"version": "0.2.15",
"version": "0.2.23",
"license": "AGPL-3.0-only",
"private": true,
"type": "module",
@@ -18,11 +18,13 @@
"check": "npm run format:check && npm run lint && npm run test && npm run build",
"licenses:generate": "node scripts/licenses.mjs",
"assemble": "node scripts/assemble.mjs",
"package:static": "node scripts/package-static.mjs"
"package:static": "node scripts/package-static.mjs",
"release:update": "node scripts/update-release-lock.mjs",
"release": "scripts/release.sh"
},
"dependencies": {
"@add-ideas/toolbox-contract": "^0.2.3",
"@add-ideas/toolbox-shell-react": "^0.2.3",
"@add-ideas/toolbox-contract": "^0.3.0",
"@add-ideas/toolbox-shell-react": "^0.3.0",
"@dnd-kit/core": "^6.3.1",
"@dnd-kit/sortable": "^10.0.0",
"@dnd-kit/utilities": "^3.2.2",
@@ -61,5 +63,6 @@
"homepage": "https://git.add-ideas.de/lotobo/toolbox-portal",
"bugs": {
"url": "https://git.add-ideas.de/lotobo/toolbox-portal/issues"
}
},
"packageManager": "npm@11.17.0"
}
+2 -2
View File
@@ -1,8 +1,8 @@
# Corresponding source
The source code corresponding to add·ideas Toolbox Portal 0.2.15 is available at:
The source code corresponding to add·ideas Toolbox Portal 0.2.23 is available at:
https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.13.0
https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.20.0
Each bundled application contains its own `SOURCE.md`, license, and third-party
license materials. The application sources are also linked from the portal.
+176
View File
@@ -36,6 +36,182 @@
{
"manifest": "./apps/auth/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/sudoku/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/colour/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/office/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/image/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/file/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/epub/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/archive/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/privacy/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/crypto/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/barcode/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/network/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/geo/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/helper/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/rand/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/data/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/diff/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/time/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/text/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/translator/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/unicode/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/flow/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/subtitle/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/midi/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/3d/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/query/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/scan/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/package/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/label/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/font/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/fixture/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/minimize/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/format-lab/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/repro/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/schema/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/log/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/binary/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/git/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/api/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/mail/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/calendar/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/contact/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/diagram/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/token/toolbox-app.json",
"enabled": true
},
{
"manifest": "./apps/device/toolbox-app.json",
"enabled": true
}
]
}
+309 -8
View File
@@ -1,8 +1,8 @@
{
"$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1,
"releaseVersion": "0.13.0",
"portalVersion": "0.2.15",
"releaseVersion": "0.20.0",
"portalVersion": "0.2.23",
"catalogue": {
"id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox",
@@ -50,17 +50,318 @@
},
{
"id": "de.add-ideas.svg-tools",
"version": "0.1.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.1.0/svg-tools-0.1.0.zip",
"sha256": "364f14c88c4934d9c847bf76de70b89dcf564a405afd58c6703363a95fbfb6ae",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.2.0/svg-tools-0.2.0.zip",
"sha256": "2e9ed259a784a474012fb2df558bf40e97fa76e02f4336ad62ba97e1d1d15ed3",
"target": "svg"
},
{
"id": "de.add-ideas.auth-tools",
"version": "0.3.0",
"artifact": "https://git.add-ideas.de/lotobo/auth-tools/releases/download/v0.3.0/auth-tools-0.3.0.zip",
"sha256": "ac80a711a0fc00d554505e6278aa3557eca4248b6da2ac9e2bae74bc0b26e58e",
"version": "0.3.1",
"artifact": "https://git.add-ideas.de/lotobo/auth-tools/releases/download/v0.3.1/auth-tools-0.3.1.zip",
"sha256": "60e90492fb50d2ce23298b3a3af84b1e3be02bbf5dea01d478f889d65eb66f3a",
"target": "auth"
},
{
"id": "de.add-ideas.sudoku-tools",
"version": "0.2.1",
"artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.2.1/sudoku-tools-0.2.1.zip",
"sha256": "3987813a3bcd24056b9ca9607ba5d74a094d54c15b0e8a7966df7373e87df67a",
"target": "sudoku"
},
{
"id": "de.add-ideas.colour-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/colour-tools/releases/download/v0.2.0/colour-tools-0.2.0.zip",
"sha256": "4eca3968f6b93b20dbd8878addb916bd7acf0f5941e168c012ee2a87d3e16e03",
"target": "colour"
},
{
"id": "de.add-ideas.office-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/office-tools/releases/download/v0.2.0/office-tools-0.2.0.zip",
"sha256": "95f288b9b1aebdf446a358aa0e72035a2c9bd344b012bdc0facd62bb41c6df72",
"target": "office"
},
{
"id": "de.add-ideas.image-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/image-tools/releases/download/v0.2.0/image-tools-0.2.0.zip",
"sha256": "997922a0ea9151f3f9de13f6f1b1f5abd2b2b0bf47faf411573d915d28a066b8",
"target": "image"
},
{
"id": "de.add-ideas.file-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/file-tools/releases/download/v0.2.0/file-tools-0.2.0.zip",
"sha256": "c6b90e14fe8c37e799ee461eb28489f91e01e116d28fdb323fa3616b834915c4",
"target": "file"
},
{
"id": "de.add-ideas.epub-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/epub-tools/releases/download/v0.2.0/epub-tools-0.2.0.zip",
"sha256": "ac3f3758b11f243dc0b785d25e6b839a12f0d9f90ec6abdfb1ad5de1730cbd27",
"target": "epub"
},
{
"id": "de.add-ideas.archive-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/archive-tools/releases/download/v0.2.0/archive-tools-0.2.0.zip",
"sha256": "dd9016c550c01fa07591636dadfa8be02f4dba8e6592e02a0941e70f73fc10b7",
"target": "archive"
},
{
"id": "de.add-ideas.privacy-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/privacy-tools/releases/download/v0.2.0/privacy-tools-0.2.0.zip",
"sha256": "88af2ae6172651de0be4bf45d90e7fddbaac51c55ef34dfeaa66f5913ca43c85",
"target": "privacy"
},
{
"id": "de.add-ideas.crypto-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/crypto-tools/releases/download/v0.2.0/crypto-tools-0.2.0.zip",
"sha256": "8611dec2937765b0fe59a9f457ed81231856484c7c0a06da34b1f24b66f0b53a",
"target": "crypto"
},
{
"id": "de.add-ideas.barcode-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/barcode-tools/releases/download/v0.2.0/barcode-tools-0.2.0.zip",
"sha256": "9180f6a9a38786018ef27db70301e7e8b92f5ad2132601297e4e98e291a977d7",
"target": "barcode"
},
{
"id": "de.add-ideas.network-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/network-tools/releases/download/v0.2.0/network-tools-0.2.0.zip",
"sha256": "9b00eac98c2263a1fc6b34291c1d00bee0b5ac172f449da4bf44de395b754608",
"target": "network"
},
{
"id": "de.add-ideas.geo-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/geo-tools/releases/download/v0.2.0/geo-tools-0.2.0.zip",
"sha256": "d028a4bcc1b2189bedc395bf67dcb07de9f19ee175a7443868385e082721b5ef",
"target": "geo"
},
{
"id": "de.add-ideas.helper-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/helper-tools/releases/download/v0.2.0/helper-tools-0.2.0.zip",
"sha256": "a6197310da3a4d471fe975e0ee18da3bc7f9b4c8264399cff6eb609cf9e6d12d",
"target": "helper"
},
{
"id": "de.add-ideas.rand-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/rand-tools/releases/download/v0.2.0/rand-tools-0.2.0.zip",
"sha256": "6d31426ae5d55b3cc2ee7a71684818e00cdbecc33c6dae1a9bdfadbcfeec188d",
"target": "rand"
},
{
"id": "de.add-ideas.data-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/data-tools/releases/download/v0.2.0/data-tools-0.2.0.zip",
"sha256": "bb3fe1e60b462ed82780cb806e030ab000cfc108998b86b7f247150ed7ba889f",
"target": "data"
},
{
"id": "de.add-ideas.diff-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/diff-tools/releases/download/v0.2.0/diff-tools-0.2.0.zip",
"sha256": "be2efe547c13521dc67f5101a7669ee3aa0c83bb6637300832f866da7bca6de1",
"target": "diff"
},
{
"id": "de.add-ideas.time-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/time-tools/releases/download/v0.2.0/time-tools-0.2.0.zip",
"sha256": "31ec1e460a1c1a566a73cbe04933df308908b013e973352b27b543e05050dc14",
"target": "time"
},
{
"id": "de.add-ideas.text-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/text-tools/releases/download/v0.2.0/text-tools-0.2.0.zip",
"sha256": "a1b635278da1baf844051fb0bbfc94022596bb674091c4c39ec164cf34bd5f62",
"target": "text"
},
{
"id": "de.add-ideas.unicode-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/unicode-tools/releases/download/v0.2.0/unicode-tools-0.2.0.zip",
"sha256": "35ca2c7dcbcc651fdd6910db67b72f2f440b8e5f0b6cdf434925a46efe1f10b6",
"target": "unicode"
},
{
"id": "de.add-ideas.flow-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/flow-tools/releases/download/v0.2.0/flow-tools-0.2.0.zip",
"sha256": "0172681d0d4361450a63981ac6b9cf3ccdb535695631874fb5d4ddf83e33e297",
"target": "flow"
},
{
"id": "de.add-ideas.subtitle-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/subtitle-tools/releases/download/v0.2.0/subtitle-tools-0.2.0.zip",
"sha256": "60a0367eb7d87bb5934d59020b6cf0eb71595efcf564e99248bdfd993ec465ca",
"target": "subtitle"
},
{
"id": "de.add-ideas.midi-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/midi-tools/releases/download/v0.2.0/midi-tools-0.2.0.zip",
"sha256": "2286ad471fd1e946e089797ef0bf56ddddfef833261ea52965c1a5bd6475fd81",
"target": "midi"
},
{
"id": "de.add-ideas.3d-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/3d-tools/releases/download/v0.2.0/3d-tools-0.2.0.zip",
"sha256": "912a2a398c5f88099638fba8ca2687b41eb5f4e5a66d1ee5bb5fa9a078c23012",
"target": "3d"
},
{
"id": "de.add-ideas.query-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/query-tools/releases/download/v0.2.0/query-tools-0.2.0.zip",
"sha256": "398e0954cded4f20200d8b0d9349b61b86d46b6f4080e13ae469c0352ad96a90",
"target": "query"
},
{
"id": "de.add-ideas.scan-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/scan-tools/releases/download/v0.2.0/scan-tools-0.2.0.zip",
"sha256": "836f93d248ceb052088826dde2fccaa31f17b8852039ac8ebdaf4e7d9c1927c0",
"target": "scan"
},
{
"id": "de.add-ideas.package-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/package-tools/releases/download/v0.2.0/package-tools-0.2.0.zip",
"sha256": "2f31ac3937901ab6a50d002cafbd294229cb5d6e1a18b9021b4ba345c28ee892",
"target": "package"
},
{
"id": "de.add-ideas.label-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/label-tools/releases/download/v0.2.0/label-tools-0.2.0.zip",
"sha256": "706d4bf3e4d802d06e5dcb089f67fdae56bbb250aedbe1b9f8e5b0c2fd997869",
"target": "label"
},
{
"id": "de.add-ideas.font-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/font-tools/releases/download/v0.2.0/font-tools-0.2.0.zip",
"sha256": "3257605518cbdfbe46b5ee4b8f3da6245ef97fc17b884cf97817f24ef0e765ea",
"target": "font"
},
{
"id": "de.add-ideas.fixture-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/fixture-tools/releases/download/v0.2.0/fixture-tools-0.2.0.zip",
"sha256": "918f322e2607bc1b5bcf4ddf33de88ef3cf1611d8aa3b218f2a70a7b967b3c00",
"target": "fixture"
},
{
"id": "de.add-ideas.minimize-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/minimize-tools/releases/download/v0.2.0/minimize-tools-0.2.0.zip",
"sha256": "b0fa1783acdb431ae56aeab9d5d8364492b833caa69ad557f48c26ee7e915c4f",
"target": "minimize"
},
{
"id": "de.add-ideas.format-lab",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/format-lab/releases/download/v0.2.0/format-lab-0.2.0.zip",
"sha256": "05a796584318a8bbfd651af80066136da46a533e19b37c18fb9f7fe3b00fe0f9",
"target": "format-lab"
},
{
"id": "de.add-ideas.repro-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/repro-tools/releases/download/v0.2.0/repro-tools-0.2.0.zip",
"sha256": "6d3062fbf9bd686f7b320239559b996f64ff0ad29740bfe37eaad02e307bbda8",
"target": "repro"
},
{
"id": "de.add-ideas.schema-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/schema-tools/releases/download/v0.2.0/schema-tools-0.2.0.zip",
"sha256": "ce0b72851d71e9b8b1ae451220f79a91c23c7c8ce621d021c6b7da50741b917a",
"target": "schema"
},
{
"id": "de.add-ideas.log-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/log-tools/releases/download/v0.2.0/log-tools-0.2.0.zip",
"sha256": "92e1e038efdfea5b605f69d84061489365d8e72f6a9cbe7800624325dc091d1d",
"target": "log"
},
{
"id": "de.add-ideas.binary-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/binary-tools/releases/download/v0.2.0/binary-tools-0.2.0.zip",
"sha256": "64b1c4c3ea8a05b3c193325d405180505b645b14ddb7e80d27af3cb8ef400711",
"target": "binary"
},
{
"id": "de.add-ideas.git-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/git-tools/releases/download/v0.2.0/git-tools-0.2.0.zip",
"sha256": "d5f2bd66f5aabdbbbdc853f460580ce276c3a51ef671297cbb6a88e3ad7d9035",
"target": "git"
},
{
"id": "de.add-ideas.api-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/api-tools/releases/download/v0.2.0/api-tools-0.2.0.zip",
"sha256": "81ad271a211fbaca3484b82b0a33aa145fd5863f6a0a53b544a6854016fbc114",
"target": "api"
},
{
"id": "de.add-ideas.mail-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/mail-tools/releases/download/v0.2.0/mail-tools-0.2.0.zip",
"sha256": "9701a3a1e55f0dd832fa78c808757fb1dd3ba9582a65c3692b376f15f3c62b7c",
"target": "mail"
},
{
"id": "de.add-ideas.calendar-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/calendar-tools/releases/download/v0.2.0/calendar-tools-0.2.0.zip",
"sha256": "89f9813ee2cbb9f89e9e6c60084cc497eb3211f76bb9d8bb4fd4bdfc85d118a9",
"target": "calendar"
},
{
"id": "de.add-ideas.contact-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/contact-tools/releases/download/v0.2.0/contact-tools-0.2.0.zip",
"sha256": "bacd7d0c18e3250226f7f171919a0de11860bca3a558fab73bb8790ee254ec0b",
"target": "contact"
},
{
"id": "de.add-ideas.diagram-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/diagram-tools/releases/download/v0.2.0/diagram-tools-0.2.0.zip",
"sha256": "971c530fca8f310ea0ebd06a9e10ecf6a194631c9a843df1c1f407f4d6213541",
"target": "diagram"
},
{
"id": "de.add-ideas.token-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/token-tools/releases/download/v0.2.0/token-tools-0.2.0.zip",
"sha256": "8c78980f2869fb2e7ac3f16f8a23694e526ae1649a14163e482636a364d45ab8",
"target": "token"
},
{
"id": "de.add-ideas.device-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/device-tools/releases/download/v0.2.0/device-tools-0.2.0.zip",
"sha256": "f1dbcbd51bdbc07b3d3860fb5a3dab081db87e74f21a1240d82584dbb70d101c",
"target": "device"
}
]
}
+316 -8
View File
@@ -1,8 +1,8 @@
{
"$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1,
"releaseVersion": "0.13.0",
"portalVersion": "0.2.15",
"releaseVersion": "0.20.3",
"portalVersion": "0.2.23",
"catalogue": {
"id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox",
@@ -50,17 +50,325 @@
},
{
"id": "de.add-ideas.svg-tools",
"version": "0.1.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.1.0/svg-tools-0.1.0.zip",
"sha256": "364f14c88c4934d9c847bf76de70b89dcf564a405afd58c6703363a95fbfb6ae",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.2.0/svg-tools-0.2.0.zip",
"sha256": "2e9ed259a784a474012fb2df558bf40e97fa76e02f4336ad62ba97e1d1d15ed3",
"target": "svg"
},
{
"id": "de.add-ideas.auth-tools",
"version": "0.3.0",
"artifact": "https://git.add-ideas.de/lotobo/auth-tools/releases/download/v0.3.0/auth-tools-0.3.0.zip",
"sha256": "ac80a711a0fc00d554505e6278aa3557eca4248b6da2ac9e2bae74bc0b26e58e",
"version": "0.3.1",
"artifact": "https://git.add-ideas.de/lotobo/auth-tools/releases/download/v0.3.1/auth-tools-0.3.1.zip",
"sha256": "60e90492fb50d2ce23298b3a3af84b1e3be02bbf5dea01d478f889d65eb66f3a",
"target": "auth"
},
{
"id": "de.add-ideas.sudoku-tools",
"version": "0.2.1",
"artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.2.1/sudoku-tools-0.2.1.zip",
"sha256": "3987813a3bcd24056b9ca9607ba5d74a094d54c15b0e8a7966df7373e87df67a",
"target": "sudoku"
},
{
"id": "de.add-ideas.colour-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/colour-tools/releases/download/v0.2.0/colour-tools-0.2.0.zip",
"sha256": "4eca3968f6b93b20dbd8878addb916bd7acf0f5941e168c012ee2a87d3e16e03",
"target": "colour"
},
{
"id": "de.add-ideas.office-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/office-tools/releases/download/v0.2.0/office-tools-0.2.0.zip",
"sha256": "95f288b9b1aebdf446a358aa0e72035a2c9bd344b012bdc0facd62bb41c6df72",
"target": "office"
},
{
"id": "de.add-ideas.image-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/image-tools/releases/download/v0.2.0/image-tools-0.2.0.zip",
"sha256": "997922a0ea9151f3f9de13f6f1b1f5abd2b2b0bf47faf411573d915d28a066b8",
"target": "image"
},
{
"id": "de.add-ideas.file-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/file-tools/releases/download/v0.2.0/file-tools-0.2.0.zip",
"sha256": "c6b90e14fe8c37e799ee461eb28489f91e01e116d28fdb323fa3616b834915c4",
"target": "file"
},
{
"id": "de.add-ideas.epub-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/epub-tools/releases/download/v0.2.0/epub-tools-0.2.0.zip",
"sha256": "ac3f3758b11f243dc0b785d25e6b839a12f0d9f90ec6abdfb1ad5de1730cbd27",
"target": "epub"
},
{
"id": "de.add-ideas.archive-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/archive-tools/releases/download/v0.2.0/archive-tools-0.2.0.zip",
"sha256": "dd9016c550c01fa07591636dadfa8be02f4dba8e6592e02a0941e70f73fc10b7",
"target": "archive"
},
{
"id": "de.add-ideas.privacy-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/privacy-tools/releases/download/v0.2.0/privacy-tools-0.2.0.zip",
"sha256": "88af2ae6172651de0be4bf45d90e7fddbaac51c55ef34dfeaa66f5913ca43c85",
"target": "privacy"
},
{
"id": "de.add-ideas.crypto-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/crypto-tools/releases/download/v0.2.0/crypto-tools-0.2.0.zip",
"sha256": "8611dec2937765b0fe59a9f457ed81231856484c7c0a06da34b1f24b66f0b53a",
"target": "crypto"
},
{
"id": "de.add-ideas.barcode-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/barcode-tools/releases/download/v0.2.0/barcode-tools-0.2.0.zip",
"sha256": "9180f6a9a38786018ef27db70301e7e8b92f5ad2132601297e4e98e291a977d7",
"target": "barcode"
},
{
"id": "de.add-ideas.network-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/network-tools/releases/download/v0.2.0/network-tools-0.2.0.zip",
"sha256": "9b00eac98c2263a1fc6b34291c1d00bee0b5ac172f449da4bf44de395b754608",
"target": "network"
},
{
"id": "de.add-ideas.geo-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/geo-tools/releases/download/v0.2.0/geo-tools-0.2.0.zip",
"sha256": "d028a4bcc1b2189bedc395bf67dcb07de9f19ee175a7443868385e082721b5ef",
"target": "geo"
},
{
"id": "de.add-ideas.helper-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/helper-tools/releases/download/v0.2.0/helper-tools-0.2.0.zip",
"sha256": "a6197310da3a4d471fe975e0ee18da3bc7f9b4c8264399cff6eb609cf9e6d12d",
"target": "helper"
},
{
"id": "de.add-ideas.rand-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/rand-tools/releases/download/v0.2.0/rand-tools-0.2.0.zip",
"sha256": "6d31426ae5d55b3cc2ee7a71684818e00cdbecc33c6dae1a9bdfadbcfeec188d",
"target": "rand"
},
{
"id": "de.add-ideas.data-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/data-tools/releases/download/v0.2.0/data-tools-0.2.0.zip",
"sha256": "bb3fe1e60b462ed82780cb806e030ab000cfc108998b86b7f247150ed7ba889f",
"target": "data"
},
{
"id": "de.add-ideas.diff-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/diff-tools/releases/download/v0.2.0/diff-tools-0.2.0.zip",
"sha256": "be2efe547c13521dc67f5101a7669ee3aa0c83bb6637300832f866da7bca6de1",
"target": "diff"
},
{
"id": "de.add-ideas.time-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/time-tools/releases/download/v0.2.0/time-tools-0.2.0.zip",
"sha256": "31ec1e460a1c1a566a73cbe04933df308908b013e973352b27b543e05050dc14",
"target": "time"
},
{
"id": "de.add-ideas.text-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/text-tools/releases/download/v0.2.0/text-tools-0.2.0.zip",
"sha256": "a1b635278da1baf844051fb0bbfc94022596bb674091c4c39ec164cf34bd5f62",
"target": "text"
},
{
"id": "de.add-ideas.translator-tools",
"version": "0.1.2",
"artifact": "https://git.add-ideas.de/lotobo/translator-tools/releases/download/v0.1.2/translator-tools-0.1.2.zip",
"sha256": "2ff24f97e0c3893c4d31dc347bd760d91a0d4a565fb392ec1a1b22ba9835c34f",
"target": "translator"
},
{
"id": "de.add-ideas.unicode-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/unicode-tools/releases/download/v0.2.0/unicode-tools-0.2.0.zip",
"sha256": "35ca2c7dcbcc651fdd6910db67b72f2f440b8e5f0b6cdf434925a46efe1f10b6",
"target": "unicode"
},
{
"id": "de.add-ideas.flow-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/flow-tools/releases/download/v0.2.0/flow-tools-0.2.0.zip",
"sha256": "0172681d0d4361450a63981ac6b9cf3ccdb535695631874fb5d4ddf83e33e297",
"target": "flow"
},
{
"id": "de.add-ideas.subtitle-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/subtitle-tools/releases/download/v0.2.0/subtitle-tools-0.2.0.zip",
"sha256": "60a0367eb7d87bb5934d59020b6cf0eb71595efcf564e99248bdfd993ec465ca",
"target": "subtitle"
},
{
"id": "de.add-ideas.midi-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/midi-tools/releases/download/v0.2.0/midi-tools-0.2.0.zip",
"sha256": "2286ad471fd1e946e089797ef0bf56ddddfef833261ea52965c1a5bd6475fd81",
"target": "midi"
},
{
"id": "de.add-ideas.3d-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/3d-tools/releases/download/v0.2.0/3d-tools-0.2.0.zip",
"sha256": "912a2a398c5f88099638fba8ca2687b41eb5f4e5a66d1ee5bb5fa9a078c23012",
"target": "3d"
},
{
"id": "de.add-ideas.query-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/query-tools/releases/download/v0.2.0/query-tools-0.2.0.zip",
"sha256": "398e0954cded4f20200d8b0d9349b61b86d46b6f4080e13ae469c0352ad96a90",
"target": "query"
},
{
"id": "de.add-ideas.scan-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/scan-tools/releases/download/v0.2.0/scan-tools-0.2.0.zip",
"sha256": "836f93d248ceb052088826dde2fccaa31f17b8852039ac8ebdaf4e7d9c1927c0",
"target": "scan"
},
{
"id": "de.add-ideas.package-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/package-tools/releases/download/v0.2.0/package-tools-0.2.0.zip",
"sha256": "2f31ac3937901ab6a50d002cafbd294229cb5d6e1a18b9021b4ba345c28ee892",
"target": "package"
},
{
"id": "de.add-ideas.label-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/label-tools/releases/download/v0.2.0/label-tools-0.2.0.zip",
"sha256": "706d4bf3e4d802d06e5dcb089f67fdae56bbb250aedbe1b9f8e5b0c2fd997869",
"target": "label"
},
{
"id": "de.add-ideas.font-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/font-tools/releases/download/v0.2.0/font-tools-0.2.0.zip",
"sha256": "3257605518cbdfbe46b5ee4b8f3da6245ef97fc17b884cf97817f24ef0e765ea",
"target": "font"
},
{
"id": "de.add-ideas.fixture-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/fixture-tools/releases/download/v0.2.0/fixture-tools-0.2.0.zip",
"sha256": "918f322e2607bc1b5bcf4ddf33de88ef3cf1611d8aa3b218f2a70a7b967b3c00",
"target": "fixture"
},
{
"id": "de.add-ideas.minimize-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/minimize-tools/releases/download/v0.2.0/minimize-tools-0.2.0.zip",
"sha256": "b0fa1783acdb431ae56aeab9d5d8364492b833caa69ad557f48c26ee7e915c4f",
"target": "minimize"
},
{
"id": "de.add-ideas.format-lab",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/format-lab/releases/download/v0.2.0/format-lab-0.2.0.zip",
"sha256": "05a796584318a8bbfd651af80066136da46a533e19b37c18fb9f7fe3b00fe0f9",
"target": "format-lab"
},
{
"id": "de.add-ideas.repro-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/repro-tools/releases/download/v0.2.0/repro-tools-0.2.0.zip",
"sha256": "6d3062fbf9bd686f7b320239559b996f64ff0ad29740bfe37eaad02e307bbda8",
"target": "repro"
},
{
"id": "de.add-ideas.schema-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/schema-tools/releases/download/v0.2.0/schema-tools-0.2.0.zip",
"sha256": "ce0b72851d71e9b8b1ae451220f79a91c23c7c8ce621d021c6b7da50741b917a",
"target": "schema"
},
{
"id": "de.add-ideas.log-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/log-tools/releases/download/v0.2.0/log-tools-0.2.0.zip",
"sha256": "92e1e038efdfea5b605f69d84061489365d8e72f6a9cbe7800624325dc091d1d",
"target": "log"
},
{
"id": "de.add-ideas.binary-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/binary-tools/releases/download/v0.2.0/binary-tools-0.2.0.zip",
"sha256": "64b1c4c3ea8a05b3c193325d405180505b645b14ddb7e80d27af3cb8ef400711",
"target": "binary"
},
{
"id": "de.add-ideas.git-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/git-tools/releases/download/v0.2.0/git-tools-0.2.0.zip",
"sha256": "d5f2bd66f5aabdbbbdc853f460580ce276c3a51ef671297cbb6a88e3ad7d9035",
"target": "git"
},
{
"id": "de.add-ideas.api-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/api-tools/releases/download/v0.2.0/api-tools-0.2.0.zip",
"sha256": "81ad271a211fbaca3484b82b0a33aa145fd5863f6a0a53b544a6854016fbc114",
"target": "api"
},
{
"id": "de.add-ideas.mail-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/mail-tools/releases/download/v0.2.0/mail-tools-0.2.0.zip",
"sha256": "9701a3a1e55f0dd832fa78c808757fb1dd3ba9582a65c3692b376f15f3c62b7c",
"target": "mail"
},
{
"id": "de.add-ideas.calendar-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/calendar-tools/releases/download/v0.2.0/calendar-tools-0.2.0.zip",
"sha256": "89f9813ee2cbb9f89e9e6c60084cc497eb3211f76bb9d8bb4fd4bdfc85d118a9",
"target": "calendar"
},
{
"id": "de.add-ideas.contact-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/contact-tools/releases/download/v0.2.0/contact-tools-0.2.0.zip",
"sha256": "bacd7d0c18e3250226f7f171919a0de11860bca3a558fab73bb8790ee254ec0b",
"target": "contact"
},
{
"id": "de.add-ideas.diagram-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/diagram-tools/releases/download/v0.2.0/diagram-tools-0.2.0.zip",
"sha256": "971c530fca8f310ea0ebd06a9e10ecf6a194631c9a843df1c1f407f4d6213541",
"target": "diagram"
},
{
"id": "de.add-ideas.token-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/token-tools/releases/download/v0.2.0/token-tools-0.2.0.zip",
"sha256": "8c78980f2869fb2e7ac3f16f8a23694e526ae1649a14163e482636a364d45ab8",
"target": "token"
},
{
"id": "de.add-ideas.device-tools",
"version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/device-tools/releases/download/v0.2.0/device-tools-0.2.0.zip",
"sha256": "f1dbcbd51bdbc07b3d3860fb5a3dab081db87e74f21a1240d82584dbb70d101c",
"target": "device"
}
]
}
+2 -2
View File
@@ -83,7 +83,7 @@ function makeLock(artifact: string, sha256: string) {
return {
schemaVersion: 1,
releaseVersion: '0.1.0',
portalVersion: '0.2.15',
portalVersion: '0.2.23',
catalogue: {
id: 'de.add-ideas.toolbox',
name: 'Test Toolbox',
@@ -290,7 +290,7 @@ describe('release assembly integrity', () => {
expect(await sha256File(utcArchive)).toBe(
await sha256File(honoluluArchive)
);
});
}, 30_000);
it('rejects a valid archive whose manifest identity is not the lock identity', async () => {
const directory = await temporaryDirectory();
+23
View File
@@ -0,0 +1,23 @@
#!/usr/bin/env bash
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
PROJECT_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)"
cd "${PROJECT_DIR}"
git fetch origin --tags
git pull --ff-only origin main
if ! TAG="$(git describe --tags --exact-match 2>/dev/null)"; then
TAG="$(git describe --tags --abbrev=0 2>/dev/null || true)"
if [ -z "${TAG}" ]; then
echo "warning: current commit is untagged and no tagged ancestor was found"
else
echo "warning: current commit is untagged; nearest tag is ${TAG}"
fi
else
echo "tagged: ${TAG}"
fi
docker compose up -d --build
docker compose ps
+104 -13
View File
@@ -22,7 +22,64 @@ const nginxConfig = readFileSync(
);
const releaseLock = JSON.parse(
readFileSync(path.join(projectRoot, 'release', 'toolbox.lock.json'), 'utf8')
) as { releaseVersion: string };
) as { releaseVersion: string; apps: Array<{ target: string }> };
const developmentCatalogue = JSON.parse(
readFileSync(path.join(projectRoot, 'public', 'toolbox.catalog.json'), 'utf8')
) as { apps: Array<{ manifest: string; enabled: boolean }> };
const expectedAppTargets = [
'pdf',
'xslt',
'onenote',
'av',
'regex',
'svg',
'auth',
'sudoku',
'colour',
'office',
'image',
'file',
'epub',
'archive',
'privacy',
'crypto',
'barcode',
'network',
'geo',
'helper',
'rand',
'data',
'diff',
'time',
'text',
'translator',
'unicode',
'flow',
'subtitle',
'midi',
'3d',
'query',
'scan',
'package',
'label',
'font',
'fixture',
'minimize',
'format-lab',
'repro',
'schema',
'log',
'binary',
'git',
'api',
'mail',
'calendar',
'contact',
'diagram',
'token',
'device',
] as const;
const immutableCacheControl = 'public, max-age=31536000, immutable';
const immutableUriPatterns = Array.from(
@@ -85,15 +142,7 @@ describe('production deployment', () => {
expect(containerfile).toContain(
'COPY --from=release --chown=101:101 /tmp/toolbox/'
);
for (const app of [
'pdf',
'xslt',
'onenote',
'av',
'regex',
'svg',
'auth',
]) {
for (const app of expectedAppTargets) {
expect(containerfile).toContain(
`test -f /tmp/toolbox/apps/${app}/toolbox-app.json`
);
@@ -101,6 +150,18 @@ describe('production deployment', () => {
expect(containerfile).toMatch(/\nUSER 101:101\nEXPOSE 8080\n/u);
});
it('keeps the development catalogue aligned with all release targets', () => {
expect(releaseLock.apps.map(({ target }) => target)).toEqual(
expectedAppTargets
);
expect(developmentCatalogue.apps).toEqual(
expectedAppTargets.map((target) => ({
manifest: `./apps/${target}/toolbox-app.json`,
enabled: true,
}))
);
});
it('uses only the requested external Traefik network and redirects HTTP to HTTPS', () => {
expect(compose).toContain('dockerfile: Containerfile.release');
expect(compose).toContain('traefik.enable: "true"');
@@ -166,9 +227,21 @@ describe('production deployment', () => {
expect(compose).not.toContain('addideas-auth-stripprefix');
});
it('grants camera capture only to the isolated authentication hostname', () => {
expect(nginxConfig).toMatch(
/map \$host \$toolbox_permissions_policy\s*\{\s*default "camera=\(\), microphone=\(\), geolocation=\(\), payment=\(\), usb=\(\)";\s*"auth\.toolbox\.add-ideas\.de" "camera=\(self\), microphone=\(\), geolocation=\(\), payment=\(\), usb=\(\)";\s*\}/mu
it('scopes camera and device probes while denying sensitive features by default', () => {
expect(nginxConfig).toContain(
'default "camera=(), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";'
);
expect(nginxConfig).toContain(
'"~^auth\\.toolbox\\.add-ideas\\.de:" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";'
);
expect(nginxConfig).toContain(
'"~^[^:]+:/apps/barcode(?:/|$)" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";'
);
expect(nginxConfig).toContain(
'"~^[^:]+:/apps/scan(?:/|$)" "camera=(self), microphone=(), display-capture=(), geolocation=(), payment=(), usb=()";'
);
expect(nginxConfig).toContain(
'"~^[^:]+:/apps/device(?:/|$)" "camera=(self), microphone=(self), display-capture=(self), geolocation=(), payment=(), usb=()";'
);
expect(nginxConfig).toContain(
'add_header Permissions-Policy $toolbox_permissions_policy always;'
@@ -178,6 +251,14 @@ describe('production deployment', () => {
).toHaveLength(1);
});
it('keeps application network connections same-origin', () => {
expect(nginxConfig).toMatch(
/^\s*add_header Content-Security-Policy "[^"]*connect-src 'self';[^"]*" always;$/mu
);
expect(nginxConfig).not.toContain('$toolbox_connect_sources');
expect(nginxConfig).not.toMatch(/https?:\/\//u);
});
it('quotes nginx regular expressions that contain brace quantifiers', () => {
expect(nginxConfig).toContain(
'"~^/(?:.*/)?assets/.*-[A-Za-z0-9_-]{8,}\\.[^/]+$"'
@@ -253,10 +334,20 @@ describe('production deployment', () => {
expect(staticLocationIndex).toBeGreaterThan(moduleLocationIndex);
});
it('serves bundled Scan OCR language data as gzip without widening the static route', () => {
const languageLocation =
/location ~\* \^\/apps\/scan\/ocr\/lang\/\[a-z0-9_-\]\+\\\.traineddata\\\.gz\$\s*\{\s*types\s*\{\s*application\/gzip gz;\s*\}\s*try_files \$uri =404;\s*\}/mu;
expect(nginxConfig).toMatch(languageLocation);
expect(nginxConfig).not.toMatch(
/location ~\* \\.\(\?:[^\n)]*\bgz\b[^\n)]*\)/u
);
});
it('allows same-origin WebAssembly workers and local blob media previews', () => {
expect(nginxConfig).toContain("script-src 'self' 'wasm-unsafe-eval'");
expect(nginxConfig).toContain("worker-src 'self' blob:");
expect(nginxConfig).toContain("media-src 'self' blob:");
expect(nginxConfig).toContain("font-src 'self' data: blob:");
expect(nginxConfig).not.toContain("'unsafe-eval'");
});
+290
View File
@@ -0,0 +1,290 @@
#!/usr/bin/env node
import path from 'node:path';
import { readFile, access } from 'node:fs/promises';
import { createHash } from 'node:crypto';
const SEMVER = /^\d+\.\d+\.\d+(?:-[0-9A-Za-z.-]+)?(?:\+[0-9A-Za-z.-]+)?$/;
function usage() {
return `Usage: node scripts/publish-release.mjs [options]
Uploads prepared release artifacts to a Gitea release.
Options:
--api-base URL Gitea API base (default: https://git.add-ideas.de/api/v1)
--owner OWNER Gitea repository owner (default: lotobo)
--repo REPO Gitea repository (default: toolbox-portal)
--tag TAG Release tag, e.g. v0.20.3 (default: from --lock-file)
--target HASH Target commit SHA for release creation
--name NAME Release name
--body BODY Optional release body
--archive PATH Release ZIP path
--checksum PATH SHA256 file path
--lock-file PATH Release lock file (default: release/toolbox.lock.json)
--token TOKEN Gitea API token; defaults to GITEA_TOKEN env
--dry-run Print actions without contacting Gitea
--help Show this help
`;
}
function parseArguments(argv) {
if (argv.includes('--help')) {
console.log(usage());
process.exit(0);
}
const args = new Map();
for (let index = 0; index < argv.length; index += 1) {
const arg = argv[index];
if (!arg.startsWith('--')) throw new Error(`Unknown argument ${arg}`);
if (arg === '--dry-run') {
args.set(arg, true);
continue;
}
const value = argv[index + 1];
if (value === undefined) throw new Error(`Missing value for ${arg}`);
args.set(arg, value);
index += 1;
}
return {
apiBase: args.get('--api-base') ?? 'https://git.add-ideas.de/api/v1',
owner: args.get('--owner') ?? 'lotobo',
repo: args.get('--repo') ?? 'toolbox-portal',
tag: args.get('--tag'),
target: args.get('--target'),
name: args.get('--name') ?? 'add-ideas Toolbox release',
body: args.get('--body'),
archive: args.get('--archive'),
checksum: args.get('--checksum'),
lockFile: args.get('--lock-file') ?? 'release/toolbox.lock.json',
token: args.get('--token') ?? process.env.GITEA_TOKEN,
dryRun: args.get('--dry-run') === true,
};
}
async function readTokenFromEnvFile() {
const xdgConfig = process.env.XDG_CONFIG_HOME;
const homeConfig = process.env.HOME
? `${process.env.HOME}/.config/gitea/gitea.env`
: null;
const candidates = [];
if (xdgConfig) candidates.push(`${xdgConfig}/gitea/gitea.env`);
if (homeConfig) candidates.push(homeConfig);
for (const candidate of candidates) {
try {
await access(candidate);
} catch {
continue;
}
const fileContent = await readFile(candidate, 'utf8');
const tokenLine = fileContent
.split('\n')
.map((line) => line.trim())
.find((line) => line.startsWith('GITEA_TOKEN='));
if (!tokenLine) continue;
const token = tokenLine.split('=', 2)[1]?.trim();
if (token) return token;
}
return null;
}
async function giteaRequest(url, options, { allowNotFound = false } = {}) {
const response = await fetch(url, {
...options,
headers: {
Accept: 'application/json',
...(options.headers ?? {}),
},
});
if (allowNotFound && response.status === 404) {
return { notFound: true, status: 404 };
}
const text = await response.text();
const payload = text ? (() => {
try {
return JSON.parse(text);
} catch {
return { raw: text };
}
})() : null;
if (!response.ok) {
const detail = payload && typeof payload === 'object' && payload.error
? payload.error
: payload?.raw ?? text ?? '';
throw new Error(`Gitea API request failed (${response.status} ${response.statusText}): ${detail}`);
}
return payload;
}
function sha256Digest(content) {
return createHash('sha256').update(content).digest('hex');
}
function parseChecksumFile(raw) {
const [first] = String(raw).trim().split(/\s+/);
return first?.toLowerCase() ?? '';
}
function parseReleaseVersionFromLock(lockJson) {
return lockJson.releaseVersion;
}
async function run() {
const options = parseArguments(process.argv.slice(2));
const lock = await readFile(options.lockFile, 'utf8');
const lockJson = JSON.parse(lock);
if (!SEMVER.test(lockJson.releaseVersion)) {
throw new Error(`Invalid releaseVersion in lock: ${lockJson.releaseVersion}`);
}
const releaseVersion = parseReleaseVersionFromLock(lockJson);
const releaseTag = options.tag ?? `v${releaseVersion}`;
const dryRun = options.dryRun === true;
let token = options.token;
if (!token && !dryRun) token = await readTokenFromEnvFile();
if (!token && !dryRun) {
throw new Error('GITEA_TOKEN is required. Set env or provide --token.');
}
if (!token && dryRun) token = 'dry-run-token';
if (!options.archive) {
throw new Error('Missing --archive');
}
if (!options.checksum) {
throw new Error('Missing --checksum');
}
const archive = path.resolve(options.archive);
const checksumFile = path.resolve(options.checksum);
const [archiveData, checksumRaw] = await Promise.all([
readFile(archive),
readFile(checksumFile, 'utf8'),
]);
const expectedChecksum = parseChecksumFile(checksumRaw);
const computedChecksum = sha256Digest(archiveData);
if (!expectedChecksum) {
throw new Error(`Checksum file is empty: ${checksumFile}`);
}
if (!/^[a-f0-9]{64}$/i.test(expectedChecksum)) {
throw new Error(`Invalid checksum format in ${checksumFile}`);
}
if (expectedChecksum.toLowerCase() !== computedChecksum.toLowerCase()) {
throw new Error(
`Checksum mismatch for ${options.archive}. computed=${computedChecksum} file=${expectedChecksum}`
);
}
if (dryRun) {
console.log(`DRY-RUN: would ensure or create release ${releaseTag} on ${options.owner}/${options.repo}.`);
console.log(`DRY-RUN: would upload assets ${path.basename(archive)} and ${path.basename(checksumFile)}.`);
return;
}
const apiBase = options.apiBase.replace(/\/+$/, '');
const releasePrefix = `${apiBase}/repos/${options.owner}/${options.repo}`;
const auth = `token ${token}`;
const headers = { Authorization: auth };
const tagUrl = `${releasePrefix}/releases/tags/${encodeURIComponent(releaseTag)}`;
const tagLookup = await giteaRequest(
tagUrl,
{ method: 'GET', headers },
{ allowNotFound: true }
);
let release;
if (tagLookup?.notFound) {
const body = {
tag_name: releaseTag,
target_commitish: options.target || 'main',
name: options.name,
body:
options.body
|| `Automated release of add-ideas toolbox ${releaseTag} from lock release ${releaseVersion}.`,
draft: false,
prerelease: false,
};
if (dryRun) {
console.log(`DRY-RUN: would create release ${releaseTag} on ${options.owner}/${options.repo}`);
release = { id: '<dry-run>', assets: [] };
} else {
release = await giteaRequest(`${releasePrefix}/releases`, {
method: 'POST',
headers: {
...headers,
'Content-Type': 'application/json',
},
body: JSON.stringify(body),
});
console.log(`Created release ${releaseTag} (${release.id})`);
}
} else {
release = tagLookup;
if (dryRun) {
console.log(`DRY-RUN: would reuse existing release ${releaseTag} (${release?.id ?? 'unknown'})`);
} else {
console.log(`Using existing release ${releaseTag} (${release.id})`);
}
}
if (dryRun) {
console.log('DRY-RUN: would upload assets:', options.archive, options.checksum);
return;
}
const existingAssets = release.assets ?? [];
const candidateAssets = [
{ path: archive, name: path.basename(archive) },
{ path: checksumFile, name: path.basename(checksumFile) },
];
for (const asset of candidateAssets) {
const duplicate = existingAssets.find((entry) => entry.name === asset.name);
if (duplicate) {
console.log(`Deleting existing asset ${asset.name} from release ${releaseTag}`);
await giteaRequest(
`${releasePrefix}/releases/assets/${duplicate.id}`,
{ method: 'DELETE', headers },
{ allowNotFound: true }
);
}
const payload = await readFile(asset.path);
const form = new FormData();
form.set('attachment', new Blob([payload]), asset.name);
console.log(`Uploading ${asset.name}`);
await giteaRequest(
`${releasePrefix}/releases/${release.id}/assets?name=${encodeURIComponent(asset.name)}`,
{
method: 'POST',
headers,
body: form,
}
);
}
console.log(`Release ${releaseTag} published on ${options.owner}/${options.repo}`);
}
run().catch((error) => {
console.error(error instanceof Error ? error.message : String(error));
process.exit(1);
});
+258
View File
@@ -0,0 +1,258 @@
#!/usr/bin/env bash
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
PROJECT_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)"
cd "${PROJECT_DIR}"
usage() {
cat <<'USAGE'
Usage: scripts/release.sh [options]
Bundles the current lockfile into a portal archive and publishes the release to Gitea.
Options:
--lock PATH Lock file to use (default: release/toolbox.lock.json)
--tag TAG Release tag to create/push (default: v<releaseVersion>)
--owner OWNER Gitea owner/org (default: lotobo)
--repo REPO Gitea repository (default: toolbox-portal)
--api-base URL Gitea API base URL (default: https://git.add-ideas.de/api/v1)
--remote REMOTE Git remote used to push the tag (default: origin)
--build-dir DIR Build directory (default: build)
--output-subdir DIR Assembled output directory under build-dir (default: toolbox)
--skip-tests Skip npm test
--skip-assemble Skip npm run assemble
--skip-build Skip npm run build
--skip-tag Skip tagging/push of the release tag
--skip-git-push Skip pushing git branch and tag
--skip-publish Skip Gitea release publish/upload
--force Force overwrite of build outputs
--dry-run Print commands without running remote publishing operations
--help Show this help
Environment:
GITEA_TOKEN Personal token for Gitea API calls
GITEA_API_BASE Optional override for API base URL
Examples:
scripts/release.sh
scripts/release.sh --tag v0.20.4 --skip-tests
USAGE
}
LOCK_FILE="release/toolbox.lock.json"
OWNER="lotobo"
REPO="toolbox-portal"
API_BASE="${GITEA_API_BASE:-https://git.add-ideas.de/api/v1}"
REMOTE="origin"
BUILD_DIR="build"
OUTPUT_SUBDIR="toolbox"
SKIP_TESTS=0
SKIP_ASSEMBLE=0
SKIP_BUILD=0
SKIP_TAG=0
SKIP_GIT_PUSH=0
SKIP_PUBLISH=0
FORCE=0
DRY_RUN=0
while [ "$#" -gt 0 ]; do
case "$1" in
--lock)
LOCK_FILE="$2"
shift 2
;;
--tag)
TAG_OVERRIDE="$2"
shift 2
;;
--owner)
OWNER="$2"
shift 2
;;
--repo)
REPO="$2"
shift 2
;;
--api-base)
API_BASE="$2"
shift 2
;;
--remote)
REMOTE="$2"
shift 2
;;
--build-dir)
BUILD_DIR="$2"
shift 2
;;
--output-subdir)
OUTPUT_SUBDIR="$2"
shift 2
;;
--skip-tests)
SKIP_TESTS=1
shift
;;
--skip-assemble)
SKIP_ASSEMBLE=1
shift
;;
--skip-build)
SKIP_BUILD=1
shift
;;
--skip-tag)
SKIP_TAG=1
shift
;;
--skip-git-push)
SKIP_GIT_PUSH=1
shift
;;
--skip-publish)
SKIP_PUBLISH=1
shift
;;
--force)
FORCE=1
shift
;;
--dry-run)
DRY_RUN=1
shift
;;
--help|-h)
usage
exit 0
;;
*)
echo "Unknown argument: $1" >&2
usage
exit 1
;;
esac
done
run() {
if [ "$DRY_RUN" -eq 1 ]; then
echo "DRY-RUN: $*"
return 0
fi
"$@"
}
RELEASE_VERSION="$(node -e "const fs=require('fs');const path=process.argv[1];const lock=JSON.parse(fs.readFileSync(path,'utf8'));if(!lock?.releaseVersion){process.exit(1);}console.log(lock.releaseVersion);" "$LOCK_FILE")"
if [ -z "$RELEASE_VERSION" ]; then
echo "releaseVersion could not be read from ${LOCK_FILE}" >&2
exit 1
fi
if [ -n "${TAG_OVERRIDE:-}" ]; then
RELEASE_TAG="$TAG_OVERRIDE"
else
RELEASE_TAG="v${RELEASE_VERSION}"
fi
ZIP_FILE="${BUILD_DIR}/add-ideas-toolbox-${RELEASE_VERSION}.zip"
CHECKSUM_FILE="${ZIP_FILE}.sha256"
TARGET_DIR="${BUILD_DIR}/${OUTPUT_SUBDIR}"
if [ "$SKIP_TESTS" -eq 0 ]; then
run npm test
fi
if [ "$SKIP_BUILD" -eq 0 ]; then
run npm run build
fi
if [ "$SKIP_ASSEMBLE" -eq 0 ]; then
ASSEMBLE_ARGS=(
npm
run
assemble
--
--lock
"$LOCK_FILE"
--portal-dist
dist
--output
"$TARGET_DIR"
--archive
"$ZIP_FILE"
)
if [ "$FORCE" -eq 1 ]; then
ASSEMBLE_ARGS+=(--force)
fi
run "${ASSEMBLE_ARGS[@]}"
fi
if [ ! -s "$ZIP_FILE" ]; then
echo "Release archive missing: $ZIP_FILE" >&2
exit 1
fi
if [ ! -s "$CHECKSUM_FILE" ]; then
if [ "$DRY_RUN" -eq 1 ]; then
echo "DRY-RUN: would create ${CHECKSUM_FILE}"
else
sha256sum "$ZIP_FILE" > "$CHECKSUM_FILE"
fi
fi
if [ "$SKIP_TAG" -eq 0 ]; then
if git rev-parse -q --verify "refs/tags/${RELEASE_TAG}" >/dev/null; then
CURRENT_COMMIT="$(git rev-parse "${RELEASE_TAG}^{commit}")"
HEAD_COMMIT="$(git rev-parse HEAD)"
if [ "$CURRENT_COMMIT" != "$HEAD_COMMIT" ]; then
echo "Tag ${RELEASE_TAG} already exists at ${CURRENT_COMMIT}, but HEAD is ${HEAD_COMMIT}." >&2
exit 1
fi
echo "Tag exists at HEAD: ${RELEASE_TAG}"
else
echo "Creating tag ${RELEASE_TAG}"
run git tag -a "$RELEASE_TAG" -m "toolbox ${RELEASE_TAG}"
fi
if [ "$SKIP_GIT_PUSH" -eq 0 ]; then
run git push "$REMOTE" HEAD
run git push "$REMOTE" "$RELEASE_TAG"
fi
fi
if [ "$SKIP_PUBLISH" -eq 0 ]; then
TOKEN="${GITEA_TOKEN:-}"
if [ -z "$TOKEN" ]; then
if [ -f "${HOME}/.config/gitea/gitea.env" ]; then
# shellcheck disable=SC1091
. "${HOME}/.config/gitea/gitea.env"
TOKEN="${GITEA_TOKEN:-}"
fi
fi
if [ -z "$TOKEN" ]; then
echo "GITEA_TOKEN is required for publishing (or use --skip-publish)." >&2
exit 1
fi
run node scripts/publish-release.mjs \
--api-base "$API_BASE" \
--owner "$OWNER" \
--repo "$REPO" \
--tag "$RELEASE_TAG" \
--target "$(git rev-parse HEAD)" \
--name "Toolbox ${RELEASE_TAG}" \
--archive "$ZIP_FILE" \
--checksum "$CHECKSUM_FILE" \
--lock-file "$LOCK_FILE" \
--token "$TOKEN"
if [ "$DRY_RUN" -eq 1 ]; then
echo "Dry run complete. No assets were uploaded."
else
echo "Published ${RELEASE_TAG} to Gitea."
fi
fi
echo "Release wrapper finished for ${RELEASE_TAG}"
+241
View File
@@ -0,0 +1,241 @@
#!/usr/bin/env node
import { createHash } from 'node:crypto';
import { createReadStream } from 'node:fs';
import { access, readFile, writeFile } from 'node:fs/promises';
import path from 'node:path';
import { spawn } from 'node:child_process';
import { parseReleaseLock } from './release-lock.mjs';
const SEMVER = /^\d+\.\d+\.\d+(?:-[0-9A-Za-z.-]+)?(?:\+[0-9A-Za-z.-]+)?$/;
const HEX_HASH = /^[a-f0-9]{64}$/;
function usage() {
return `Usage: node scripts/update-release-lock.mjs --app-id ID --app-version VERSION --artifact URL --sha256 HEX --release-version SEMVER [options]
Options:
--lock PATH Path to release lock (default: release/toolbox.lock.json)
--portal-version SEMVER Optional portal package override
--app-id ID App id in lock (for example de.add-ideas.translator-tools)
--app-version VERSION App semantic version
--artifact URL Artifact URL/path/file: URL
--sha256 HEX Optional artifact checksum; required for remote artifacts
--release-version VERSION New toolbox release version
--assemble Run npm run build and npm run assemble after patching
--force Pass --force to assemble command
--help Show this message
`;
}
function parseArguments(argv) {
if (argv.includes('--help')) {
console.log(usage());
process.exit(0);
}
const args = new Map();
for (let index = 0; index < argv.length; index += 1) {
const option = argv[index];
if (!option.startsWith('--')) {
throw new Error(`Unknown argument: ${option}`);
}
if (option === '--assemble' || option === '--force') {
args.set(option, true);
continue;
}
const value = argv[index + 1];
if (value === undefined) {
throw new Error(`${option} requires a value.`);
}
args.set(option, value);
index += 1;
}
return {
lockFile: args.get('--lock') ?? 'release/toolbox.lock.json',
appId: args.get('--app-id'),
appVersion: args.get('--app-version'),
artifact: args.get('--artifact'),
sha256: args.get('--sha256'),
releaseVersion: args.get('--release-version'),
portalVersion: args.get('--portal-version'),
assemble: args.get('--assemble') === true,
forceAssemble: args.get('--force') === true,
};
}
function bumpPatch(version) {
const [major, minor, patchAndSuffix] = version.split('.');
const [patch] = patchAndSuffix.split('-');
const nextPatch = Number.parseInt(patch, 10) + 1;
return `${major}.${minor}.${nextPatch}`;
}
async function sha256ForPath(filePath) {
await access(filePath);
const hash = createHash('sha256');
const input = createReadStream(filePath);
await new Promise((resolve, reject) => {
input.on('data', (chunk) => hash.update(chunk));
input.on('error', reject);
input.on('end', resolve);
});
return hash.digest('hex');
}
async function computeRemoteSha256(url) {
const response = await fetch(url);
if (!response.ok) {
throw new Error(`Unable to download artifact (${response.status} ${response.statusText}).`);
}
if (!response.body) {
throw new Error('Artifact download did not provide a response body.');
}
const hash = createHash('sha256');
const reader = response.body.getReader();
for (;;) {
const { done, value } = await reader.read();
if (done) break;
hash.update(Buffer.from(value));
}
return hash.digest('hex');
}
function resolveArtifactPath(artifact, lockDirectory) {
if (/^file:/i.test(artifact)) return new URL(artifact).pathname;
if (/^https?:/i.test(artifact)) return null;
return path.resolve(lockDirectory, artifact);
}
function toShaIfNeeded(hash) {
if (!hash) return null;
const normalized = hash.toLowerCase();
if (!HEX_HASH.test(normalized)) {
throw new Error('Provided --sha256 is not a valid 64 hex hash.');
}
return normalized;
}
function command(cwd) {
return (name, args) =>
new Promise((resolve, reject) => {
const child = spawn(name, args, {
cwd,
stdio: 'inherit',
shell: true,
});
child.on('error', reject);
child.on('exit', (code) =>
code === 0
? resolve(undefined)
: reject(new Error(`${name} ${args.join(' ')} failed with code ${code}`))
);
});
}
async function run() {
const options = parseArguments(process.argv.slice(2));
if (
!options.appId ||
!options.appVersion ||
!options.artifact ||
!options.releaseVersion
) {
throw new Error(`Missing required options.
${usage()}`);
}
if (!SEMVER.test(options.releaseVersion)) {
throw new Error(`--release-version must be semver: ${options.releaseVersion}`);
}
if (!SEMVER.test(options.appVersion)) {
throw new Error(`--app-version must be semver: ${options.appVersion}`);
}
const lockPath = path.resolve(options.lockFile);
const lockDir = path.dirname(lockPath);
const lockJson = JSON.parse(await readFile(lockPath, 'utf8'));
const lock = parseReleaseLock(lockJson);
const nextReleaseVersion = options.releaseVersion ?? bumpPatch(lock.releaseVersion);
if (!SEMVER.test(nextReleaseVersion)) {
throw new Error(`Invalid release version: ${nextReleaseVersion}`);
}
const appIndex = lock.apps.findIndex((app) => app.id === options.appId);
if (appIndex < 0) {
throw new Error(`App id not found in lock: ${options.appId}`);
}
const artifactPath = resolveArtifactPath(options.artifact, lockDir);
let sha256 = toShaIfNeeded(options.sha256);
if (!sha256) {
if (artifactPath) {
sha256 = await sha256ForPath(artifactPath);
} else {
sha256 = await computeRemoteSha256(options.artifact);
}
}
if (!HEX_HASH.test(sha256)) {
throw new Error('Computed checksum is malformed.');
}
const updatedApps = [...lock.apps];
const previous = updatedApps[appIndex];
updatedApps[appIndex] = {
...previous,
version: options.appVersion,
artifact: options.artifact,
sha256,
};
const nextLock = {
...lock,
releaseVersion: nextReleaseVersion,
apps: updatedApps,
};
if (options.portalVersion) {
if (!SEMVER.test(options.portalVersion))
throw new Error(`--portal-version must be semver: ${options.portalVersion}`);
nextLock.portalVersion = options.portalVersion;
}
parseReleaseLock(nextLock);
await writeFile(lockPath, `${JSON.stringify(nextLock, null, 2)}\n`, 'utf8');
console.log(`Updated ${path.relative(process.cwd(), lockPath)} (${options.appId})`);
if (!options.assemble) return;
const runCommand = command(process.cwd());
await runCommand('npm', ['run', 'build']);
const archive = `build/add-ideas-toolbox-${nextReleaseVersion}.zip`;
const assembleArgs = [
'run',
'assemble',
'--',
'--lock',
options.lockFile,
'--portal-dist',
'dist',
'--output',
'build/toolbox',
'--archive',
archive,
];
if (options.forceAssemble) assembleArgs.push('--force');
await runCommand('npm', assembleArgs);
console.log(`Assembled release -> ${archive}`);
const releaseChecksum = path.join(
path.dirname(archive),
`${path.basename(archive)}.sha256`
);
const releaseSha256 = await sha256ForPath(releaseChecksum === undefined ? '' : releaseChecksum);
console.log(`Release checksum: ${releaseSha256}`);
}
run().catch((error) => {
console.error(error instanceof Error ? error.message : String(error));
process.exit(1);
});
+27 -3
View File
@@ -48,6 +48,12 @@ describe('portal UI', () => {
expect(
screen.getByTestId('app-card-de.add-ideas.auth-tools')
).toHaveTextContent('OTP & Passkeys');
expect(
screen.getByTestId('app-card-de.add-ideas.colour-tools')
).toHaveTextContent('Colour');
expect(
screen.getByTestId('app-card-de.add-ideas.office-tools')
).toHaveTextContent('Office');
expect(
screen.queryByText(
'Page-level PDF operations performed locally in the browser.'
@@ -335,12 +341,12 @@ describe('portal UI', () => {
expect(
screen.getByRole('heading', {
level: 2,
name: 'Your document tools, in one calm place.',
name: 'Your local tools, in one calm place.',
})
).toBeInTheDocument();
expect(
screen.getAllByRole('heading', {
name: 'Your document tools, in one calm place.',
name: 'Your local tools, in one calm place.',
})
).toHaveLength(1);
@@ -415,6 +421,9 @@ describe('portal UI', () => {
'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
'de.add-ideas.auth-tools',
'de.add-ideas.sudoku-tools',
'de.add-ideas.colour-tools',
'de.add-ideas.office-tools',
],
hidden: [],
theme: 'light',
@@ -434,6 +443,9 @@ describe('portal UI', () => {
screen.getByTestId('app-card-de.add-ideas.onenote-tools'),
screen.getByTestId('app-card-de.add-ideas.svg-tools'),
screen.getByTestId('app-card-de.add-ideas.auth-tools'),
screen.getByTestId('app-card-de.add-ideas.sudoku-tools'),
screen.getByTestId('app-card-de.add-ideas.colour-tools'),
screen.getByTestId('app-card-de.add-ideas.office-tools'),
];
cards.forEach((card, index) => {
const rect = {
@@ -464,7 +476,16 @@ describe('portal UI', () => {
within(tools)
.getAllByRole('heading', { level: 3 })
.map((heading) => heading.textContent)
).toEqual(['XSLT', 'PDF', 'OneNote', 'SVG', 'OTP & Passkeys']);
).toEqual([
'XSLT',
'PDF',
'OneNote',
'SVG',
'OTP & Passkeys',
'Sudoku',
'Colour',
'Office',
]);
});
expect(
JSON.parse(localStorage.getItem(PREFERENCES_KEY) ?? '{}').order
@@ -474,6 +495,9 @@ describe('portal UI', () => {
'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
'de.add-ideas.auth-tools',
'de.add-ideas.sudoku-tools',
'de.add-ideas.colour-tools',
'de.add-ideas.office-tools',
]);
});
+3 -3
View File
@@ -297,7 +297,7 @@ export default function App() {
Privacy details up front · useful by default
</p>
<h2 id="page-title">
Your document tools,
Your local tools,
<br /> <span>in one calm place.</span>
</h2>
<p className="hero-copy">
@@ -489,9 +489,9 @@ export default function App() {
</span>
</p>
<span>
Portal v0.2.15 ·{' '}
Portal v0.2.23 ·{' '}
<a
href="https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.13.0"
href="https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.20.0"
target="_blank"
rel="noopener noreferrer"
>
+4 -1
View File
@@ -10,7 +10,7 @@ describe('catalogue loading', () => {
const loaded = await loadCatalogue('/toolbox.catalog.json');
expect(loaded.catalogue.name).toBe('add·ideas Toolbox');
expect(loaded.homeUrl).toBe('http://localhost:3000/');
expect(loaded.apps).toHaveLength(5);
expect(loaded.apps).toHaveLength(8);
expect(loaded.apps[0]).toMatchObject({
id: 'de.add-ideas.pdf-tools',
name: 'PDF Workbench',
@@ -42,6 +42,9 @@ describe('catalogue loading', () => {
'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
'de.add-ideas.auth-tools',
'de.add-ideas.sudoku-tools',
'de.add-ideas.colour-tools',
'de.add-ideas.office-tools',
]);
expect(loaded.unavailable).toHaveLength(1);
expect(loaded.unavailable[0]?.reason).toMatch(/HTTP 404/);
+121
View File
@@ -160,6 +160,118 @@ export const authManifest: ToolboxAppManifest = {
},
};
export const sudokuManifest: ToolboxAppManifest = {
schemaVersion: 1,
id: 'de.add-ideas.sudoku-tools',
name: 'Sudoku Tools',
version: '0.1.0',
description:
'Set, play, solve and analyse Sudoku puzzles locally in the browser.',
entry: './',
icon: './favicon.svg',
categories: ['games', 'puzzles', 'logic'],
tags: ['sudoku', 'killer', 'solver', 'setter', 'generator', 'candidates'],
integration: {
contextVersion: 1,
launchModes: ['navigate', 'new-tab'],
embedding: 'unsupported',
},
requirements: {
secureContext: false,
workers: true,
indexedDb: true,
crossOriginIsolated: false,
topLevelContext: false,
},
privacy: {
processing: 'local',
fileUploads: false,
telemetry: false,
label: 'Puzzles and progress stay in this browser; nothing is uploaded.',
},
source: {
repository: 'https://git.add-ideas.de/lotobo/sudoku-tools',
license: 'GPL-3.0-or-later',
},
actions: [
{
id: 'source',
label: 'Source',
url: 'https://git.add-ideas.de/lotobo/sudoku-tools',
},
],
};
export const colourManifest: ToolboxAppManifest = {
...sudokuManifest,
id: 'de.add-ideas.colour-tools',
name: 'Colour Tools',
version: '0.1.0',
description:
'Convert, composite, compare and build colours locally in the browser.',
categories: ['graphics', 'design', 'developer'],
tags: ['colour', 'rgba', 'oklch', 'palette', 'gradient', 'contrast'],
requirements: {
secureContext: false,
workers: true,
indexedDb: false,
crossOriginIsolated: false,
topLevelContext: false,
},
privacy: {
processing: 'local',
fileUploads: false,
telemetry: false,
label: 'Colours and images stay in this browser; nothing is uploaded.',
},
source: {
repository: 'https://git.add-ideas.de/lotobo/colour-tools',
license: 'GPL-3.0-or-later',
},
actions: [
{
id: 'source',
label: 'Source',
url: 'https://git.add-ideas.de/lotobo/colour-tools',
},
],
};
export const officeManifest: ToolboxAppManifest = {
...sudokuManifest,
id: 'de.add-ideas.office-tools',
name: 'Office Tools',
version: '0.1.0',
description:
'Open and inspect documents, spreadsheets and presentations locally in the browser.',
categories: ['documents', 'office', 'productivity'],
tags: ['document', 'spreadsheet', 'presentation', 'docx', 'xlsx', 'pptx'],
requirements: {
secureContext: false,
workers: true,
indexedDb: false,
crossOriginIsolated: false,
topLevelContext: false,
},
privacy: {
processing: 'local',
fileUploads: false,
telemetry: false,
label: 'Office files stay in this browser; nothing is uploaded.',
},
source: {
repository: 'https://git.add-ideas.de/lotobo/office-tools',
license: 'GPL-3.0-or-later',
},
actions: [
{
id: 'source',
label: 'Source',
url: 'https://git.add-ideas.de/lotobo/office-tools',
},
],
};
export const catalogue: ToolboxCatalog = {
schemaVersion: 1,
id: 'de.add-ideas.toolbox',
@@ -172,6 +284,9 @@ export const catalogue: ToolboxCatalog = {
{ manifest: './apps/onenote/toolbox-app.json', enabled: true },
{ manifest: './apps/svg/toolbox-app.json', enabled: true },
{ manifest: './apps/auth/toolbox-app.json', enabled: true },
{ manifest: './apps/sudoku/toolbox-app.json', enabled: true },
{ manifest: './apps/colour/toolbox-app.json', enabled: true },
{ manifest: './apps/office/toolbox-app.json', enabled: true },
],
};
@@ -197,6 +312,12 @@ export function catalogueFetch(overrides: Record<string, Response> = {}) {
return Response.json(svgManifest);
if (url.pathname.endsWith('/apps/auth/toolbox-app.json'))
return Response.json(authManifest);
if (url.pathname.endsWith('/apps/sudoku/toolbox-app.json'))
return Response.json(sudokuManifest);
if (url.pathname.endsWith('/apps/colour/toolbox-app.json'))
return Response.json(colourManifest);
if (url.pathname.endsWith('/apps/office/toolbox-app.json'))
return Response.json(officeManifest);
return new Response('Not found', { status: 404 });
};
}
+35
View File
@@ -52,4 +52,39 @@ describe('compact tool presentation', () => {
'Inspect and test authentication locally.'
);
});
it('uses the compact Sudoku tile copy', () => {
const sudoku = app(
'de.add-ideas.sudoku-tools',
'Sudoku Tools',
'Set, play, solve and analyse Sudoku puzzles locally in the browser.'
);
expect(shortToolTitle(sudoku)).toBe('Sudoku');
expect(shortToolDescription(sudoku)).toBe('Set, play and solve locally.');
});
it('uses the compact Colour tile copy', () => {
const colour = app(
'de.add-ideas.colour-tools',
'Colour Tools',
'Convert, composite, compare and build colours locally in the browser.'
);
expect(shortToolTitle(colour)).toBe('Colour');
expect(shortToolDescription(colour)).toBe(
'Convert and build colours locally.'
);
});
it('uses the compact Office tile copy', () => {
const office = app(
'de.add-ideas.office-tools',
'Office Tools',
'Open and inspect documents, spreadsheets and presentations locally in the browser.'
);
expect(shortToolTitle(office)).toBe('Office');
expect(shortToolDescription(office)).toBe('Open office files locally.');
});
});
+12
View File
@@ -29,6 +29,18 @@ const PRESENTATION: Record<string, { title: string; description: string }> = {
title: 'OTP & Passkeys',
description: 'Inspect and test authentication locally.',
},
'de.add-ideas.sudoku-tools': {
title: 'Sudoku',
description: 'Set, play and solve locally.',
},
'de.add-ideas.colour-tools': {
title: 'Colour',
description: 'Convert and build colours locally.',
},
'de.add-ideas.office-tools': {
title: 'Office',
description: 'Open office files locally.',
},
};
export function shortToolTitle(app: ResolvedApp): string {
+2
View File
@@ -10,5 +10,7 @@ export default defineConfig({
setupFiles: './src/test/setup.ts',
css: true,
restoreMocks: true,
pool: 'threads',
maxWorkers: 1,
},
});