Files
electron/script/codesign/gen-trust.ts
Samuel Attard 2c94aac330 build: add oxfmt for JS/TS formatting and import sorting (#50692)
* build: add oxfmt for code formatting and import sorting

Adds oxfmt as a devDependency alongside oxlint and wires it into the
lint pipeline. The .oxfmtrc.json config matches Electron's current JS
style (single quotes, semicolons, 2-space indent, trailing commas off,
printWidth 100) and configures sortImports with custom groups that
mirror the import/order pathGroups previously enforced by ESLint:
@electron/internal, @electron/*, and {electron,electron/**} each get
their own ordered group ahead of external modules.

- `yarn lint:fmt` runs `oxfmt --check` over JS/TS sources and is
  chained into `yarn lint` so CI enforces it automatically.
- `yarn format` runs `oxfmt --write` for local fix-up.
- lint-staged invokes `oxfmt --write` on staged .js/.ts/.mjs/.cjs
  files before oxlint, so formatting is applied at commit time.

The next commit applies the formatter to the existing codebase so the
check actually passes.

* chore: apply oxfmt formatting to JS and TS sources

Runs `yarn format` across lib/, spec/, script/, build/, default_app/,
and npm/ to bring the codebase in line with the .oxfmtrc.json settings
added in the previous commit. This is a pure formatting pass: import
statements are sorted into the groups defined by the config, method
chains longer than printWidth are broken, single-quoted strings
containing apostrophes are switched to double quotes, and a handful of
single-statement `if` bodies are re-wrapped and get braces added by
`oxlint --fix` to satisfy the `curly: multi-line` rule.

No behavior changes.
2026-04-12 02:03:04 -07:00

44 lines
1.3 KiB
TypeScript

import * as cp from 'node:child_process';
import * as fs from 'node:fs';
import * as path from 'node:path';
const certificatePath = process.argv[2];
const outPath = process.argv[3];
const templatePath = path.resolve(__dirname, 'trust.xml');
const template = fs.readFileSync(templatePath, 'utf8');
const fingerprintResult = cp.spawnSync('openssl', ['x509', '-noout', '-fingerprint', '-sha1', '-in', certificatePath]);
if (fingerprintResult.status !== 0) {
console.error(fingerprintResult.stderr.toString());
process.exit(1);
}
const fingerprint = fingerprintResult.stdout
.toString()
.replace(/^SHA1 Fingerprint=/, '')
.replace(/:/g, '')
.trim();
const serialResult = cp.spawnSync('openssl', ['x509', '-serial', '-noout', '-in', certificatePath]);
if (serialResult.status !== 0) {
console.error(serialResult.stderr.toString());
process.exit(1);
}
let serialHex = serialResult.stdout
.toString()
.replace(/^serial=/, '')
.trim();
// Pad the serial number out to 18 hex chars
while (serialHex.length < 18) {
serialHex = `0${serialHex}`;
}
const serialB64 = Buffer.from(serialHex, 'hex').toString('base64');
const trust = template.replace(/{{FINGERPRINT}}/g, fingerprint).replace(/{{SERIAL_BASE64}}/g, serialB64);
fs.writeFileSync(outPath, trust);
console.log('Generated Trust Settings');