codepush_protocol 0.1.0
codepush_protocol: ^0.1.0 copied to clipboard
The CodePush wire protocol: patch manifest shape and Ed25519 signing, shared verbatim between the in-app runtime and the publishing CLI.
codepush_protocol #
The CodePush wire protocol: what a patch manifest contains, and what a signature covers.
Shared verbatim by the in-app runtime and the publishing CLI. That is the point — before this they were two hand-written copies, one per side, which is the most reliable way to ship a signature scheme that verifies on the machine that wrote it and nowhere else.
Pure Dart, no Flutter.
What the signature covers #
The whole manifest, not just the artifact:
codepush.manifest.v1
<platform> <appId> <releaseId> <engineVersion> <versionCode> <versionName>
<sha256> <sizeBytes> <rolloutPercent> <artifactUrl> <patchNumber>
Signing only the patch file would leave every decision around it unsigned. An
attacker who could write to the bucket could keep a genuinely signed patch and
retarget its releaseId, raise rolloutPercent from 5 to 100, or repoint
artifactUrl at a different object. So the signature covers the manifest, and
the manifest carries the artifact's hash.
A line-oriented payload rather than canonical JSON, because the two sides are different programs. Canonical JSON means agreeing on key order, number formatting, unicode escaping and whitespace — and any disagreement shows up as "signature invalid" on a user's device, at launch, with the cause invisible. A fixed field list joined by newlines has exactly one encoding and is covered by a golden vector asserted on both sides.
Field order is frozen. Adding a field means a new version and keeping the old builder, because a device running an older build must still be able to verify manifests signed for it.
Use #
You do not depend on this directly. codepush re-exports what an app needs.