From a6fa6db17373eefaa2cffbfc4b882b145a733f9f Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Wed, 19 Aug 2026 00:44:20 +0530 Subject: feat: removed the auto-update checking from the chromium extensions --- modules/web/chromium/extensions/lib.nix | 140 -------------------------------- 1 file changed, 140 deletions(-) (limited to 'modules/web/chromium/extensions/lib.nix') diff --git a/modules/web/chromium/extensions/lib.nix b/modules/web/chromium/extensions/lib.nix index 2fdd3a8..6123b63 100644 --- a/modules/web/chromium/extensions/lib.nix +++ b/modules/web/chromium/extensions/lib.nix @@ -2,148 +2,8 @@ lib, pkgs, config, - checkForUpdates ? true, }: -let - # Fetch using the Releases API (Finds the latest official GitHub Release) - fetchLatestGithubReleaseTag = - { owner, repo }: - let - raw = builtins.fetchurl { - url = "https://api.github.com/repos/${owner}/${repo}/releases/latest"; - name = "${repo}-latest-release.json"; - }; - json = builtins.fromJSON (builtins.readFile raw); - in - json.tag_name; - - # Fetch using the Tags API (Finds the newest tag matching a prefix/regex) - fetchLatestGithubTag = - { - owner, - repo, - tagPrefix ? "", - tagRegex ? null, - }: - let - raw = builtins.fetchurl { - url = "https://api.github.com/repos/${owner}/${repo}/tags"; - name = "${repo}-tags.json"; - }; - tags = builtins.fromJSON (builtins.readFile raw); - - isValidTag = - t: - let - matchesPrefix = tagPrefix == "" || lib.hasPrefix tagPrefix t.name; - matchesRegex = tagRegex == null || builtins.match tagRegex t.name != null; - in - matchesPrefix && matchesRegex; - - matchingTags = builtins.filter isValidTag tags; - in - if builtins.length matchingTags > 0 then - (builtins.head matchingTags).name - else - throw "No tags found for ${owner}/${repo} matching prefix '${tagPrefix}' and regex '${toString tagRegex}'"; - - # Internal helper to handle the version comparison and error message - verifyAndThrow = - { - pname, - version, - latestTag, - tagPrefix, - urlTemplate, - updateType, - }: - let - latestVersion = - if lib.hasPrefix tagPrefix latestTag then lib.removePrefix tagPrefix latestTag else latestTag; - in - if latestVersion != version then - throw '' - [${pname}] A newer ${updateType} is available upstream — refusing to build a stale extension. - - pinned version : ${version} - latest version : ${latestVersion} (tag: ${latestTag}) - - To upgrade, edit extensions/${pname}.nix: - 1. Set version = "${latestVersion}"; - 2. Point the url at the new release asset: - ${urlTemplate} - 3. Set hash = lib.fakeHash; - then re-run your switch — it'll fail with a hash mismatch showing - the real sha256. Paste that in as the final hash. - 4. Re-run once more. This check passes once pinned == latest. - - To skip this check for now (e.g. offline / pure eval), set: - web.chromium.checkForUpdates = false; - '' - else - version; -in { - checkExtensionVersion = - { - pname, - owner, - repo, - version, - urlTemplate, - tagPrefix ? "", - }: - if !checkForUpdates then - version - else - let - latestTag = fetchLatestGithubReleaseTag { inherit owner repo; }; - in - verifyAndThrow { - inherit - pname - version - latestTag - tagPrefix - urlTemplate - ; - updateType = "release"; - }; - - checkExtensionVersionByTag = - { - pname, - owner, - repo, - version, - urlTemplate, - tagPrefix ? "", - tagRegex ? null, - }: - if !checkForUpdates then - version - else - let - latestTag = fetchLatestGithubTag { - inherit - owner - repo - tagPrefix - tagRegex - ; - }; - in - verifyAndThrow { - inherit - pname - version - latestTag - tagPrefix - urlTemplate - ; - updateType = "tag"; - }; - # EXTENSION BUILDERS # Download and unpack a zip or crx file into an unpacked extension directory fetchUnpackedExtension = -- cgit v1.2.3