Aditya Vikram Singh
252ea92d3b
fix(menubar): keep Keychain failure paths from leaving plaintext
...
A valid Keychain item plus a leftover JSON used to skip chmod, so a
failed unlink could leave 0644 secrets on disk. Failed Disconnect also
cleared bootstrap and hid the retry. Repair leftover files to 0600,
keep bootstrap when Keychain delete fails, revalidate the opened fd,
and loop the secure read.
2026-08-19 20:02:44 +05:30
Resham Joshi
495a254338
feat(mac): native Swift menubar app + one-command install
...
Introduces mac/ with a native SwiftUI menubar app that replaces the
previous SwiftBar plugin entirely. Install via `npx codeburn menubar`,
which downloads the .app from GitHub Releases, strips Gatekeeper
quarantine, and drops it into ~/Applications.
Highlights
- mac/ SwiftUI app: agent tabs, Today/7/30/Month/All period switcher,
Trend/Forecast/Pulse/Stats/Plan insights, activity + model
breakdowns, optimize findings, CSV/JSON export, Star-on-GitHub
banner, live 60s refresh, instant currency switching with offline FX
cache.
- Security: CodeburnCLI argv-based spawn (no shell interpretation),
SafeFile symlink guards + O_NOFOLLOW writes, FX rate clamping to
[0.0001, 1_000_000], keychain filtered to account == "default",
removed byte-window credential log, in-flight refresh guard, POSIX
flock on config.json writes, TerminalLauncher validates argv before
AppleScript interpolation.
- Performance: shared static NumberFormatter (thousands of allocations
per popover redraw eliminated), concurrent pipe drain with 20 MB cap
+ 60s timeout in DataClient, Observation-tracked reactive UI, 5-min
payload cache keyed on (period, provider).
- CLI: new `codeburn menubar` subcommand that downloads + installs +
launches the .app (no clone, no build). New `status --format
menubar-json` payload builder. `export` rewritten to produce a
folder of one-table-per-file CSVs with a `.codeburn-export` marker
so arbitrary -o paths cannot be silently deleted.
- Removed: src/menubar.ts (SwiftBar plugin generator),
install-menubar / uninstall-menubar subcommands, `status --format
menubar` directive output, tests/menubar.test.ts,
tests/security/menubar-injection.test.ts.
- Release: .github/workflows/release-menubar.yml builds universal
binary, assembles .app, ad-hoc signs, zips, uploads on mac-v* tag
push. Runs on the free macos-latest runner.
Tests
- 230 TypeScript tests pass
- 10 Swift CapacityEstimator tests pass
- TypeScript typecheck clean
- Swift release build clean
2026-04-17 16:55:56 -07:00