119 lines
5.7 KiB
Plaintext
119 lines
5.7 KiB
Plaintext
; vestibule.iss — Inno Setup script for the Vestibule Windows installer.
|
|
;
|
|
; Builds Vestibule-Setup-<version>.exe: stages usher.exe, the extension,
|
|
; configs, and provisioning scripts to C:\Program Files\Vestibule, adds
|
|
; Start Menu shortcuts for provisioning, and offers to launch the
|
|
; AssignedAccess provisioning wizard at the end.
|
|
;
|
|
; The installer STAGES files only — it never touches OS lockdown state.
|
|
; All OS-level configuration (kiosk account, AssignedAccess, autologon,
|
|
; policies) is done by scripts\provision-kiosk.ps1, which is fully
|
|
; parameterized for unattended deployment. See DEPLOYMENT.md.
|
|
;
|
|
; Build (local):
|
|
; cd helper && cargo build --release && cd ..
|
|
; packaging\build-installer.ps1
|
|
; Build (CI): .github/workflows/ci.yml, "package-windows" job.
|
|
;
|
|
; Inno Setup 6.x required.
|
|
|
|
#define MyAppName "Vestibule"
|
|
#define MyAppVersion "1.2.2"
|
|
#define MyAppPublisher "Jeremy Anderson"
|
|
#define MyAppURL "https://dcos.net"
|
|
#define MyAppExeVersion "1.2.2"
|
|
|
|
; Compile-time guard: fail with a clear message instead of shipping an
|
|
; installer without the helper binary.
|
|
#if !FileExists("..\helper\target\release\usher.exe")
|
|
#error usher.exe not found under helper\target\release. Build it first: cd helper; cargo build --release
|
|
#endif
|
|
|
|
[Setup]
|
|
AppId={{1DE48322-DE9E-43B3-B86B-41ABCD8EB585}
|
|
AppName={#MyAppName}
|
|
AppVersion={#MyAppVersion}
|
|
AppVerName={#MyAppName} {#MyAppVersion}
|
|
AppPublisher={#MyAppPublisher}
|
|
AppPublisherURL={#MyAppURL}
|
|
AppSupportURL={#MyAppURL}
|
|
DefaultDirName={autopf}\{#MyAppName}
|
|
DefaultGroupName={#MyAppName}
|
|
DisableProgramGroupPage=yes
|
|
LicenseFile=..\LICENSE
|
|
; Vestibule is a system-level kiosk product: install per-machine, elevated.
|
|
PrivilegesRequired=admin
|
|
ArchitecturesInstallIn64BitMode=x64compatible
|
|
OutputDir=Output
|
|
OutputBaseFilename=Vestibule-Setup-{#MyAppVersion}
|
|
SetupIconFile=icons\vestibule.ico
|
|
UninstallDisplayIcon={app}\bin\usher.exe
|
|
UninstallDisplayName={#MyAppName} {#MyAppVersion}
|
|
Compression=lzma2/max
|
|
SolidCompression=yes
|
|
WizardStyle=modern
|
|
; The installer is unsigned until a code-signing budget exists (see
|
|
; README "Honest limitations"). SmartScreen will warn; operators verify
|
|
; the hash from the release notes.
|
|
|
|
[Languages]
|
|
Name: "english"; MessagesFile: "compiler:Default.isl"
|
|
|
|
[Tasks]
|
|
Name: "provision"; Description: "Run the kiosk provisioning wizard after setup (configure AssignedAccess, kiosk account, autologon)"; Flags: unchecked
|
|
Name: "stagenativehost"; Description: "Also register usher as Native Messaging host for THIS user (developer mode; kiosk users get it automatically at logon)"
|
|
|
|
[Files]
|
|
Source: "..\helper\target\release\usher.exe"; DestDir: "{app}\bin"; Flags: ignoreversion
|
|
Source: "..\extension\*"; DestDir: "{app}\extension"; Flags: recursesubdirs createallsubdirs ignoreversion
|
|
Source: "..\config\*"; DestDir: "{app}\config"; Flags: ignoreversion
|
|
Source: "..\scripts\*.ps1"; DestDir: "{app}\scripts"; Flags: ignoreversion
|
|
Source: "..\scripts\*.py"; DestDir: "{app}\scripts"; Flags: ignoreversion
|
|
Source: "..\scripts\vestibule-kiosk.service.in"; DestDir: "{app}\scripts"; Flags: ignoreversion
|
|
Source: "..\docs\*"; DestDir: "{app}\docs"; Flags: recursesubdirs ignoreversion
|
|
Source: "..\DEPLOYMENT.md"; DestDir: "{app}"; Flags: ignoreversion
|
|
Source: "..\README.md"; DestDir: "{app}"; Flags: ignoreversion
|
|
Source: "..\QUICKSTART.md"; DestDir: "{app}"; Flags: ignoreversion
|
|
Source: "..\LICENSE"; DestDir: "{app}"; Flags: ignoreversion
|
|
|
|
[Icons]
|
|
Name: "{group}\Provision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1"""
|
|
Name: "{group}\Deprovision kiosk (run as admin)"; Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\deprovision-kiosk.ps1"""
|
|
Name: "{group}\Deployment guide"; Filename: "{app}\DEPLOYMENT.md"
|
|
Name: "{group}\README"; Filename: "{app}\README.md"
|
|
Name: "{group}\{cm:UninstallProgram,{#MyAppName}}"; Filename: "{uninstallexe}"
|
|
|
|
[Run]
|
|
; Developer-mode native host registration for the installing user
|
|
; (mirrors scripts/install-native-host.ps1 but from the staged binary).
|
|
Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -Command ""if (-not (Test-Path \"$env:LOCALAPPDATA\Vestibule\usher.exe\")) { New-Item -ItemType Directory -Force -Path \"$env:LOCALAPPDATA\Vestibule\" | Out-Null; Copy-Item \"{app}\bin\usher.exe\" \"$env:LOCALAPPDATA\Vestibule\usher.exe\" }"""; Tasks: stagenativehost; Flags: runhidden; Description: "Register usher for this user"
|
|
; Provisioning wizard (elevated — the installer process is elevated).
|
|
Filename: "powershell.exe"; Parameters: "-NoProfile -ExecutionPolicy Bypass -File ""{app}\scripts\provision-kiosk.ps1"""; Tasks: provision; Flags: postinstall nowait skipifsilent; Description: "Run the kiosk provisioning wizard"
|
|
|
|
[UninstallDelete]
|
|
; The XPI is generated by provision-kiosk.ps1 after install.
|
|
Type: files; Name: "{app}\extension\vestibule.xpi"
|
|
Type: filesandordirs; Name: "{app}\Output"
|
|
|
|
[Code]
|
|
procedure CurUninstallStepChanged(CurUninstallStep: TUninstallStep);
|
|
var
|
|
ResultCode: Integer;
|
|
begin
|
|
if CurUninstallStep = usUninstall then
|
|
begin
|
|
if MsgBox('Also remove kiosk lockdown configuration?' + #13#10 + #13#10 +
|
|
'This runs deprovision-kiosk.ps1: removes AssignedAccess/' +
|
|
'Shell Launcher config, autologon, the kiosk shortcut, and ' +
|
|
'Vestibule policies. Choose Yes on kiosk machines, No to ' +
|
|
'keep OS configuration (e.g. shared dev boxes).',
|
|
mbConfirmation, MB_YESNO) = IDYES then
|
|
begin
|
|
Exec(ExpandConstant('{cmd}'),
|
|
'/C powershell.exe -NoProfile -ExecutionPolicy Bypass -File "' +
|
|
ExpandConstant('{app}') + '\scripts\deprovision-kiosk.ps1" -Quiet -RemoveKioskAccount',
|
|
'', SW_SHOW, ewWaitUntilTerminated, ResultCode);
|
|
end;
|
|
end;
|
|
end;
|