77 lines
3.6 KiB
XML
77 lines
3.6 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<component type="desktop-application">
|
|
<id>net.dcos.Vestibule</id>
|
|
<name>Vestibule</name>
|
|
<summary>Kiosk lockdown browser toolkit — provision a public terminal in one command</summary>
|
|
<developer id="net.dcos">
|
|
<name>Jeremy Anderson</name>
|
|
</developer>
|
|
<update_contact>info@dcos.net</update_contact>
|
|
<metadata_license>CC0-1.0</metadata_license>
|
|
<project_license>MIT</project_license>
|
|
<url type="homepage">https://dcos.net</url>
|
|
<url type="bugtracker">https://dcos.net</url>
|
|
<description>
|
|
<p>
|
|
Vestibule turns a Linux machine into a public-facing kiosk browser
|
|
built on LibreWolf ESR plus a small Rust native helper (usher). The
|
|
device is the kiosk, not an app pretending to be one: the cage
|
|
Wayland compositor runs LibreWolf as the only client on a VT, under
|
|
systemd supervision, with every session sanitized on idle timeout,
|
|
wake-from-sleep, and unlock.
|
|
</p>
|
|
<p>
|
|
This package is the deployment kit. It ships the usher binary, the
|
|
Vestibule WebExtension, enterprise policies, and the provisioning
|
|
scripts. Running it prints the exact host-side command that turns
|
|
the machine (or any machine with this Flatpak installed) into a
|
|
kiosk — no manual OS configuration required.
|
|
</p>
|
|
</description>
|
|
<launchable type="desktop-id">net.dcos.Vestibule.desktop</launchable>
|
|
<releases>
|
|
<release version="1.2.2" date="2026-08-24">
|
|
<description>
|
|
<p>Safe-by-default navigation.</p>
|
|
<ul>
|
|
<li>New safelist URL policy mode — the default: every domain is blocked until the operator lists it</li>
|
|
<li>Domain-based matching replaces substring matching for the safelist; subdomains covered, smuggle attempts blocked</li>
|
|
<li>Home-origin guarantee: the kiosk home page is always navigable, whatever the list says</li>
|
|
<li>Blocked top-level navigations land on an in-extension block page instead of a raw connection error</li>
|
|
<li>Admin wizard validates the home URL against the safelist live and at save time, with one-click domain add</li>
|
|
<li>62-assertion unit suite for the URL policy engine (scripts/test-url-policy.js), wired into CI</li>
|
|
<li>Relicensed MIT (was Apache 2.0)</li>
|
|
</ul>
|
|
</description>
|
|
</release>
|
|
<release version="1.2.0" date="2026-08-24">
|
|
<description>
|
|
<p>Production readiness pass.</p>
|
|
<ul>
|
|
<li>Constant-time admin password verification in the wizard</li>
|
|
<li>Table-driven smoke test; step-down browser/flavor resolution in the provisioning scripts</li>
|
|
<li>Launcher dispatch integration-tested across all browser/flavor permutations</li>
|
|
<li>Deprovision resets each policy directory to its pre-Vestibule baseline</li>
|
|
</ul>
|
|
</description>
|
|
</release>
|
|
<release version="1.1.0" date="2026-08-23">
|
|
<description>
|
|
<p>Phase 2 — deployability.</p>
|
|
<ul>
|
|
<li>cage systemd kiosk session provisioning (native + Flatpak LibreWolf)</li>
|
|
<li>Windows AssignedAccess / Shell Launcher provisioning wizard</li>
|
|
<li>Inno Setup installer + this Flatpak packaging</li>
|
|
<li>Full deprovision on both platforms</li>
|
|
</ul>
|
|
</description>
|
|
</release>
|
|
<release version="1.0.0" date="2026-08-23">
|
|
<description>
|
|
<p>Phase 1 — Argon2id unlock, dedicated unlock popup, Windows power events, per-origin cookie preservation, systemd supervision, CI matrix.</p>
|
|
</description>
|
|
</release>
|
|
</releases>
|
|
<content_rating type="oars-1.1" />
|
|
</component>
|