v6.8.15: the Android app is out for testing
CodeQL Analysis / Analyze CodeQL (push) Canceled after 0s
Deploy Application / deploy (push) Canceled after 0s
Mirror to Codeberg / mirror (push) Canceled after 0s
Mirror to PrivacyGuides / mirror (push) Canceled after 0s

- Android APK download, served from securebit.chat (/downloads/, never
  committed): a "Download Android APK" badge next to the Snap Store one, drawn
  for both themes, and an Android entry in the download menu (recommended on
  Android devices). nginx serves .apk as an attachment; the service worker
  leaves /downloads/ alone. The APK version is one constant in three places,
  checked by tests/desktop-download-links.test.mjs.
- Roadmap versions follow the real releases: Group Communications v6.0
  shipped, Mobile Edition v6.8 is current, Quantum-Resistant v7.0 is in
  development (2027), then v8.0 and v9.0.
- "Download desktop app" is now "Download the app"; the "You're on Web" pill
  in the download menu is gone.
This commit is contained in:
lockbitchat
2026-09-28 01:23:50 -04:00
parent 02b007af3e
commit bf5d43b2f1
59 changed files with 663 additions and 529 deletions
+10
View File
@@ -28,6 +28,7 @@ http {
font/woff2 woff2;
font/woff woff;
image/svg+xml svg;
application/vnd.android.package-archive apk;
}
sendfile on;
@@ -46,6 +47,14 @@ http {
# Decide Cache-Control from the request path. Keeping all add_header calls at
# one level avoids nginx's header-inheritance reset between blocks.
# The Android APK is downloaded, never displayed: a browser that is handed
# an APK without this may render it as text or refuse it. Empty everywhere
# else, which nginx omits.
map $uri $sb_disposition {
default "";
"~^/downloads/.+\.apk$" "attachment";
}
map $uri $sb_cache {
default "public, max-age=31536000, immutable";
# Quoted because nginx reads a bare { as the start of a block: an unquoted
@@ -142,6 +151,7 @@ http {
# Edge-cache directive for Cloudflare/CDNs (empty value → header is omitted).
add_header CDN-Cache-Control $sb_cdn_cache always;
add_header Service-Worker-Allowed "/" always;
add_header Content-Disposition $sb_disposition always;
# Short-lived TURN relay credentials. See deploy/turn-credentials.js.
location = /api/turn-credentials {