Compare commits

...

8 Commits

Author SHA1 Message Date
996a7cc03e feat(installer): v0.4.0 — 파일제거기, 커스텀 폴더명, 포트포워딩 개편, 이름/개발자용 표기
- 음악퀴즈 파일제거 도구 신규 추가: 동의 → 휴지통/완전삭제 선택 → 커스텀 폴더
  (현재값 + 기본 .mc_custom) 전체, 데스크톱 바로가기, gameDir 가 해당 폴더인
  마인크래프트 런처 프로필 정리.
- MC_CUSTOM_DIR .env 로 커스텀 게임 폴더 이름 유동화(.mc_custom 기본). 렌더러
  사전에도 실제 폴더명 반영.
- 간편포트포워딩: 실행 중 UPnP 매핑 유지, 창 닫힘/종료 시 자동 제거(activePort 추적).
- 개발자용 빌드는 창/헤더 제목 앞에 (개발자용) 표기, exe 이름에도 반영.
- exe 이름 변경: 음악퀴즈 간편설치기 / 음악퀴즈 리소스팩설치기 / 간편포트포워딩.
- README 및 .env 템플릿 갱신, 버전 0.3.23 → 0.4.0.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-15 23:21:46 +09:00
00aa47ed17 feat(installer): record EULA acceptance timestamp in eula.txt
Write an ISO 8601 "# EULA accepted at: <time>" comment when the user
accepts the EULA, so the agreement time is captured alongside eula=true.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-15 22:29:07 +09:00
9c2a92c101 docs: align account section with account.local.json + scrypt reality
The 계정 section still described account.json as the account store and
scrypt hashing as future work; both are now implemented. Point it at the
gitignored account.local.json (0600) seed/scrypt flow, consistent with the
migration section below.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-12 01:06:05 +09:00
662c3c7b23 docs+comment: pin account.json untrack-after-redeploy TODO
추적 해제는 코드 작업이 아니라 사용자의 1회 재배포에 게이트된 운영 절차이므로,
잊히지 않도록 명시적 TODO 를 코드(paths.ts) + 운영 문서(admin-site.md)에 고정.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-11 13:31:50 +09:00
face70b3e9 security: env-gate trust proxy, 0600 account file, seed+template for account.json untrack
리뷰 지적 추가 반영(서버 전용).
- trust proxy 를 항상 켜던 것을 TRUST_PROXY=true 일 때만 켜도록 변경. 직접 노출
  시 X-Forwarded-For 조작으로 로그인 rate limit 을 우회하던 문제 차단(프록시 뒤면
  TRUST_PROXY=true 설정).
- account.local.json 을 0o600(소유자 전용)으로 저장.
- 서버 시작 시 account.local.json 이 없으면 account.json 에서 시드(0o600). 이렇게
  하면 재배포 직후(로그인 전에도) 로컬 계정 파일이 항상 존재해, 이후 account.json
  을 안전하게 추적 해제할 수 있다.
- account.example.json 템플릿 추가.

account.json 자체의 git 추적 해제는 서버가 한 번 재배포되어 account.local.json 이
생성된 뒤 후속 커밋에서 처리(그 전에 지우면 pull 시 삭제되어 로그인이 막힘).

Co-Authored-By: Claude Opus 4 <noreply@anthropic.com>
2026-07-11 13:27:32 +09:00
651c63faa6 security: revert auto-upgrade failure logging (keep silent per request)
사용자 요청으로 평문→해시 자동 업그레이드 저장 실패 시 console.error 로그를
원래대로 조용한 catch 로 되돌림. 나머지 보안 개선(로그인 rate-limit,
account.local.json 분리, secure 쿠키 옵션)은 유지.

Co-Authored-By: Claude Opus 4 <noreply@anthropic.com>
2026-07-11 13:23:17 +09:00
f392842d7f security: login rate-limit, gitignored account store, secure cookie opt, upgrade-fail log
리뷰 지적 4건 반영(서버 전용, exe 영향 없음).
- 로그인 IP 기준 실패 제한(15분 창 10회 → 15분 차단). 브루트포스 + scrypt CPU
  남용 방지. 인메모리, 무한 성장 가드 포함.
- 운영 계정을 gitignore 된 account.local.json 으로 이전. readAccounts 는 local
  우선, 없으면 추적되는 account.json 을 시드로 읽음. writeAccounts 는 local 에만
  기록 → 첫 로그인 자동 해시 업그레이드부터는 추적 평문 파일을 더 쓰지 않음.
  (account.json 을 git rm --cached 하면 서버 pull 시 삭제되는 위험이 있어 추적 자체는
  건드리지 않고, 실질 사용 파일만 분리.)
- 세션 쿠키 secure 를 SESSION_COOKIE_SECURE=true 로 켤 수 있게(HTTPS 배포용).
- 평문→해시 자동 업그레이드 저장 실패를 조용히 무시하지 않고 console.error 로 기록.

Co-Authored-By: Claude Opus 4 <noreply@anthropic.com>
2026-07-11 12:31:34 +09:00
00344084c7 security: hash operator passwords (scrypt) + persistent session secret
- 운영자 로그인 비밀번호를 평문 비교(===)에서 Node 내장 scrypt 해시 + 상수시간
  비교(verifyPassword)로 전환. 새 파일 src/server/password.ts. 기존 account.json
  의 평문 비밀번호는 그대로 검증되며, 로그인 성공 시 scrypt 해시로 자동 업그레이드
  후 저장(writeAccounts 추가). 외부 의존성 없음.
- 세션 시크릿을 하드코딩 폴백('...dev-secret') 대신, 환경변수 우선 → 없으면
  .session-secret 파일에 영구 랜덤값 생성/보관하도록 변경(세션 위조 방지, 재시작
  후에도 세션 유지). .session-secret 은 .gitignore 에 추가.

서버(사이트) 전용 변경이라 설치기 exe 는 영향 없음(재빌드 불필요).

Co-Authored-By: Claude Opus 4 <noreply@anthropic.com>
2026-07-11 12:24:42 +09:00
29 changed files with 986 additions and 45 deletions

View File

@@ -31,6 +31,14 @@ SITE_BASE_URL=https://mq.example.com
# 특별히 다른 경로를 쓰고 싶을 때만 아래를 풀어서 우선 적용시키세요.
# MANIFEST_URL=https://mq.example.com/manifest.json
# ----- 커스텀 게임 폴더 이름 -----
# 음악퀴즈 전용 게임/캐시 폴더의 이름. %APPDATA% 바로 아래에 이 이름으로 생성됩니다.
# 비워두면 기본값 `.mc_custom` 을 사용합니다. 경로 구분자(/ \)와 `..` 는 무시됩니다.
# 설치기·리소스팩설치기·파일제거기가 모두 이 값을 공유하므로, 값을 바꾸면
# 세 exe 를 같은 값으로 다시 빌드해야 서로 같은 폴더를 가리킵니다.
# MC_CUSTOM_DIR=.mc_custom
# ----- 리소스팩 설치기 -----
# yt-dlp 동시 다운로드 수(1~8). 비워두면 CPU 코어 수로 자동 결정.

View File

@@ -27,6 +27,12 @@ SITE_BASE_URL=http://127.0.0.1:3000
# 특별히 다른 경로를 쓰고 싶을 때만 아래를 풀어서 우선 적용시키세요.
# MANIFEST_URL=http://127.0.0.1:3000/manifest.json
# ----- 커스텀 게임 폴더 이름 -----
# 음악퀴즈 전용 게임/캐시 폴더의 이름. %APPDATA% 바로 아래에 이 이름으로 생성됩니다.
# 비워두면 기본값 `.mc_custom` 을 사용합니다. 경로 구분자(/ \)와 `..` 는 무시됩니다.
# MC_CUSTOM_DIR=.mc_custom
# ----- 리소스팩 설치기 -----
# yt-dlp 동시 다운로드 수(1~8). 비워두면 CPU 코어 수로 자동 결정.

4
.gitignore vendored
View File

@@ -7,3 +7,7 @@ conversations/
.env
.env.local
.env.*.local
# 세션 서명용 자동 생성 시크릿. 절대 커밋 금지.
.session-secret
# 운영 계정(해시 비밀번호) 파일. 추적되는 account.json 대신 이 파일을 사용. 커밋 금지.
account.local.json

View File

@@ -5,6 +5,8 @@
- **관리 사이트** — 음악퀴즈 정보(JSON)와 음악·사진 목록, 데이터팩 출력을 한 곳에서 운영.
- **음악퀴즈 간편설치기 (`.exe`)** — `manifest.json` 기반으로 사용자가 마인크래프트 본체·서버·모드를 자동 설치.
- **리소스팩 간편설치기 (`.exe`)** — 음악퀴즈 음악·표지를 yt-dlp 로 받아 painting variant 텍스처 리소스팩으로 패키징.
- **간편포트포워딩 (`.exe`)** — 원하는 포트를 입력해 UPnP 로 개방. 프로그램을 켜 두는 동안만 열려 있고 창을 닫으면 자동으로 닫힙니다.
- **음악퀴즈 파일제거 (`.exe`)** — 설치기들이 만든 게임 폴더·캐시와 런처 프로필을 휴지통 이동 또는 완전 삭제로 한 번에 정리.
---
@@ -15,7 +17,9 @@
| `src/server/` | 음악퀴즈 관리 웹사이트 (Express + EJS) | `bun start` 또는 `npm start` |
| `src/installer/` | 음악퀴즈 간편설치기 (Electron) | `npm run installer` |
| `src/installer-rp/` | 리소스팩 간편설치기 (Electron) | `npm run installer:rp` |
| `src/shared/` | 두 설치기와 서버가 공유하는 타입·스토어 | — |
| `src/installer-pf/` | 간편포트포워딩 도구 (Electron) | `npm run installer:pf` |
| `src/installer-uninstall/` | 음악퀴즈 파일제거 도구 (Electron) | `npm run installer:uninstall` |
| `src/shared/` | 설치기들과 서버가 공유하는 타입·스토어 | — |
| `views/` | EJS 템플릿 (관리 사이트) | — |
| `manifest/` | 음악퀴즈별 정의 JSON | — |
| `file/list/` | 음악퀴즈별 음악·사진 목록 JSON | — |
@@ -43,6 +47,8 @@
이렇게 분리해 두면 사용자가 평소 쓰던 마인크래프트와 음악퀴즈 설정이 섞이지 않고, 음악퀴즈만 삭제해도 본체에는 영향이 없습니다.
> **폴더 이름 바꾸기.** 기본값은 `.mc_custom` 이지만 `.env` / `.env.build` 의 `MC_CUSTOM_DIR` 로 다른 이름을 지정할 수 있습니다. 설치기·리소스팩설치기·파일제거기가 모두 이 값을 공유하므로, 값을 바꾸면 세 exe 를 같은 값으로 다시 빌드해야 서로 같은 폴더를 가리킵니다. (경로 구분자 `/ \` 와 `..` 는 무시되어 항상 `%APPDATA%` 바로 아래 단일 폴더가 됩니다.)
---
## 빠른 시작
@@ -65,8 +71,17 @@ npm run installer
# 3) 리소스팩 간편설치기를 Electron 으로 실행해 보기
npm run installer:rp
# 4) 음악퀴즈 간편설치기 윈도우 .exe 빌드
npm run dist:win
# 4) 간편포트포워딩 / 파일제거 도구 실행해 보기
npm run installer:pf
npm run installer:uninstall
# 5) 윈도우 .exe 빌드 (개별)
npm run dist:win # 음악퀴즈 간편설치기
npm run dist:win:rp # 음악퀴즈 리소스팩설치기
npm run dist:win:pf # 간편포트포워딩
npm run dist:win:uninstall # 음악퀴즈 파일제거
npm run dist:win:dev # (개발자용) 음악퀴즈 간편설치기
npm run dist:win:rp:dev # (개발자용) 음악퀴즈 리소스팩설치기
```
리소스팩 설치기는 `yt-dlp` 가 필요합니다. 자동 다운로드되지만, 막혀 있는 환경이라면 [`docs/yt-dlp-setup.md`](docs/yt-dlp-setup.md) 참고.
@@ -155,9 +170,13 @@ minecraft_launcher/
│ ├─ server/ Express + EJS 관리 사이트
│ ├─ installer/ 음악퀴즈 간편설치기 (Electron 메인 + preload)
│ ├─ installer-rp/ 리소스팩 간편설치기 (Electron 메인 + 음악/이미지 파이프라인)
│ ├─ installer-pf/ 간편포트포워딩 도구 (Electron 메인 + preload)
│ ├─ installer-uninstall/ 음악퀴즈 파일제거 도구 (Electron 메인 + preload)
│ └─ shared/ 공용 타입, 매니페스트 스토어, mojang/upnp 유틸
├─ installer/ 음악퀴즈 설치기 렌더러(HTML/CSS/JS)
├─ installer-rp/ 리소스팩 설치기 렌더러(HTML/CSS/JS)
├─ installer-pf/ 간편포트포워딩 렌더러(HTML/JS)
├─ installer-uninstall/ 파일제거 렌더러(HTML/JS)
├─ views/ 관리 사이트 EJS 템플릿
├─ public/ 관리 사이트 정적 파일(styles.css 등)
├─ manifest/ 음악퀴즈 JSON 정의 (운영자가 편집)
@@ -172,18 +191,24 @@ minecraft_launcher/
├─ manifest.json 사이트 루트 매니페스트 (자동 관리)
├─ account.json 관리자 계정 (절대 외부 노출 금지)
├─ package.json
└─ tsconfig.{,server,installer,installer-rp}.json
└─ tsconfig.{,server,installer,installer-rp,installer-pf,installer-uninstall}.json
```
---
## 빌드 산출물 / 배포
| 산출물 | 빌드 명령 | 비고 |
| 산출물(파일명) | 빌드 명령 | 비고 |
| --- | --- | --- |
| 관리 사이트 (Node 실행) | `npm start` | systemd 등으로 띄우기. 외부 도메인이 manifest 의 base URL 이 됩니다. |
| 음악퀴즈 간편설치기 `.exe` | `npm run dist:win` | `electron-builder.yml` 설정 사용. |
| 리소스팩 간편설치기 `.exe` | `tsconfig.installer-rp.json` 빌드 후 `electron-builder` 수동 패키징 | |
| `음악퀴즈 간편설치기-<버전>.exe` | `npm run dist:win` | `electron-builder.yml`. |
| `음악퀴즈 리소스팩설치기-<버전>.exe` | `npm run dist:win:rp` | `electron-builder-rp.yml`. |
| `간편포트포워딩-<버전>.exe` | `npm run dist:win:pf` | `electron-builder-pf.yml`. |
| `음악퀴즈 파일제거-<버전>.exe` | `npm run dist:win:uninstall` | `electron-builder-uninstall.yml`. |
| `(개발자용) 음악퀴즈 간편설치기-<버전>.exe` | `npm run dist:win:dev` | 비공개(public=false) 팩만 노출. 제목 앞에 `(개발자용)` 표시. |
| `(개발자용) 음악퀴즈 리소스팩설치기-<버전>.exe` | `npm run dist:win:rp:dev` | 상동. |
빌드 결과물은 `release/` 폴더에 생성됩니다(포터블 exe).
---

3
account.example.json Normal file
View File

@@ -0,0 +1,3 @@
[
{ "id": "admin", "password": "여기에-비밀번호를-넣으세요" }
]

View File

@@ -50,7 +50,9 @@ npm start # 기본 포트 3000.
## 계정
`account.json` 에 정의합니다(루트 디렉터리). **외부 HTTP 로 절대 노출되지 않도록 라우팅에서 제외돼 있습니다.**
운영 계정은 **gitignore 된 `account.local.json`**(루트 디렉터리, 0600, scrypt 해시)에 저장됩니다. 추적되는 `account.json` 은 서버에 `account.local.json` 이 없을 때만 읽는 **시드 소스**로, 서버 시작 시 자동으로 `account.local.json`(0600) 으로 복사됩니다. 두 파일 모두 **외부 HTTP 로 절대 노출되지 않도록 라우팅에서 제외돼 있습니다.**
시드 포맷(`account.json`):
```json
[
@@ -58,7 +60,7 @@ npm start # 기본 포트 3000.
]
```
> 운영 환경에서는 평문 비밀번호 대신 해시를 쓰도록 추후 보강할 여지가 있습니다.
평문 비밀번호로 시드해도 로그인 성공 시 자동으로 scrypt 해시(`scrypt$<salt>$<hash>`)로 업그레이드되어 `account.local.json` 에만 저장됩니다. 자세한 마이그레이션 절차는 아래 "운영 계정 파일 마이그레이션" 을 참고하세요.
## 대시보드 (`/op/dashboard`)
@@ -138,4 +140,14 @@ say [musicquiz] 데이터팩 초기화
- `account.json` 은 라우팅에서 차단되어 있으나, 디스크 권한도 운영자만 접근 가능하게 두는 것이 안전합니다.
- 관리자 비밀번호는 충분히 강하게 설정.
### 운영 계정 파일 마이그레이션 (미완결 — 재배포 게이트)
운영 계정은 이제 gitignore 된 `account.local.json`(0o600, scrypt 해시)에만 저장됩니다. 추적되는 `account.json` 은 서버에 `account.local.json` 이 없을 때만 읽는 **시드 소스**로 남겨 둔 상태입니다. 남은 위생 작업이 하나 있습니다:
1. **[운영] 최신 main 재배포** → 서버가 `account.local.json`(0o600) 을 자동 생성하는지 확인.
2. **[운영] 비밀번호 로테이션** — git 히스토리에 평문 비밀번호가 남아 있어 추적 해제로는 지워지지 않으므로, 이것이 실질적 최우선 보안 조치입니다.
3. **[후속 커밋] `account.json` 추적 해제** — 위 1번(서버에 `account.local.json` 존재) 확인 **후에만** `git rm --cached account.json` 를 별도 커밋으로 진행. 같은 커밋에서 하면 시드 소스가 사라져 로그인이 막힙니다.
> 코드 상 앵커: `src/shared/paths.ts` 의 `TODO(untrack-after-redeploy)` 주석.
- 모든 `/op/*` 라우트는 세션 기반 인증 미들웨어를 거칩니다. 세션 만료 시 자동으로 로그인 페이지로 리다이렉트.

View File

@@ -29,7 +29,7 @@ extraResources:
- "**/*"
win:
target: portable
artifactName: MusicQuizInstaller-Dev-${version}-Portable.${ext}
artifactName: (개발자용) 음악퀴즈 간편설치기-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: MusicQuizInstaller-Dev-${version}-Portable.${ext}
artifactName: (개발자용) 음악퀴즈 간편설치기-${version}.${ext}

View File

@@ -27,7 +27,7 @@ extraResources:
- "**/*"
win:
target: portable
artifactName: 마인크래프트간편포트포워딩-${version}-Portable.${ext}
artifactName: 간편포트포워딩-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: 마인크래프트간편포트포워딩-${version}-Portable.${ext}
artifactName: 간편포트포워딩-${version}.${ext}

View File

@@ -29,7 +29,7 @@ extraResources:
- "**/*"
win:
target: portable
artifactName: MusicQuizResourcepackInstaller-Dev-${version}-Portable.${ext}
artifactName: (개발자용) 음악퀴즈 리소스팩설치기-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: MusicQuizResourcepackInstaller-Dev-${version}-Portable.${ext}
artifactName: (개발자용) 음악퀴즈 리소스팩설치기-${version}.${ext}

View File

@@ -35,7 +35,7 @@ extraResources:
- "**/*"
win:
target: portable
artifactName: ${productName}-${version}-Portable.${ext}
artifactName: 음악퀴즈 리소스팩설치기-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: ${productName}-${version}-Portable.${ext}
artifactName: 음악퀴즈 리소스팩설치기-${version}.${ext}

View File

@@ -0,0 +1,38 @@
appId: kr.tkrmagid.musicquiz.uninstall
productName: 음악퀴즈 파일제거
# 루트 package.json 의 "main" 은 메인 설치기를 가리키므로, 패키지된 앱이
# 파일제거 도구를 진입점으로 쓰도록 빌드 시 main 을 덮어쓴다.
extraMetadata:
main: dist/installer-uninstall/main.js
directories:
output: release
buildResources: build
files:
- dist/installer-uninstall/**
- dist/shared/**
- installer-uninstall/**
# index.html 은 메인 설치기와 동일한 styles.css 를 공유함
# (`<link href="../installer/styles.css">`). 그 한 파일만 명시적으로 포함.
- installer/styles.css
- build/icon.*
- package.json
# 이 도구는 sharp(이미지 처리)를 쓰지 않으므로 통째로 제외해 exe 크기를 줄인다.
- "!node_modules/sharp/**"
- "!node_modules/@img/**"
# MC_CUSTOM_DIR 을 커스텀으로 빌드했다면 파일제거기도 같은 폴더를 가리켜야 하므로
# `.env.build` 를 함께 배포한다. i18n 사전(locales/installer-uninstall/ko-kr.json)도 함께.
extraResources:
- from: .
to: .
filter:
- .env.build
- from: locales
to: locales
filter:
- "**/*"
win:
target: portable
artifactName: 음악퀴즈 파일제거-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: 음악퀴즈 파일제거-${version}.${ext}

View File

@@ -32,7 +32,7 @@ extraResources:
- "**/*"
win:
target: portable
artifactName: ${productName}-${version}-Portable.${ext}
artifactName: 음악퀴즈 간편설치기-${version}.${ext}
icon: build/icon.ico
portable:
artifactName: ${productName}-${version}-Portable.${ext}
artifactName: 음악퀴즈 간편설치기-${version}.${ext}

View File

@@ -0,0 +1,22 @@
<!doctype html>
<html lang="ko">
<head>
<meta charset="utf-8" />
<title>음악퀴즈 파일제거</title>
<link rel="stylesheet" href="../installer/styles.css" />
</head>
<body>
<header class="appHeader">
<h1>음악퀴즈 파일제거</h1>
</header>
<main id="pageHost"></main>
<aside class="logViewer" id="logViewer" hidden>
<header><h2>로그</h2><button type="button" id="logToggle">접기</button></header>
<pre id="logBody"></pre>
</aside>
<script src="./renderer.js"></script>
</body>
</html>

View File

@@ -0,0 +1,209 @@
'use strict'
const api = window.uninstaller
let I18N = {}
function tt(key, params) {
var parts = String(key).split('.')
var cur = I18N
for (var i = 0; i < parts.length; i++) {
if (cur && typeof cur === 'object' && parts[i] in cur) {
cur = cur[parts[i]]
} else {
return key
}
}
if (typeof cur !== 'string') return key
if (!params) return cur
return cur.replace(/\{\{\s*(\w+)\s*\}\}/g, function (_m, name) {
return name in params ? String(params[name]) : '{{' + name + '}}'
})
}
function escapeHtml(s) {
return String(s).replace(/[&<>"']/g, function (c) {
return c === '&' ? '&amp;' : c === '<' ? '&lt;' : c === '>' ? '&gt;' : c === '"' ? '&quot;' : '&#39;'
})
}
const pageHost = document.getElementById('pageHost')
const logViewer = document.getElementById('logViewer')
const logBody = document.getElementById('logBody')
const logToggle = document.getElementById('logToggle')
logToggle.addEventListener('click', function () {
logViewer.classList.toggle('collapsed')
if (logViewer.classList.contains('collapsed')) {
logViewer.style.height = '36px'
logToggle.textContent = tt('logViewer.expand')
} else {
logViewer.style.height = ''
logToggle.textContent = tt('logViewer.collapse')
}
})
api.onLog(function (line) {
logViewer.hidden = false
logBody.textContent += line + '\n'
logBody.scrollTop = logBody.scrollHeight
})
function applyStaticI18n() {
document.title = tt('app.title')
var h1 = document.querySelector('.appHeader h1')
if (h1) h1.textContent = tt('app.title')
var logH2 = logViewer.querySelector('header h2')
if (logH2) logH2.textContent = tt('logViewer.heading')
logToggle.textContent = tt('logViewer.collapse')
}
// ── 1단계: 삭제 동의 ──────────────────────────────
function renderConfirm() {
pageHost.innerHTML =
'<section class="page">' +
' <h2>' + escapeHtml(tt('confirm.heading')) + '</h2>' +
' <p class="formMessage" style="margin-top:8px;font-size:15px;">' + escapeHtml(tt('confirm.question')) + '</p>' +
' <p class="formMessage" style="margin-top:8px;">' + escapeHtml(tt('confirm.detail')) + '</p>' +
' <div id="previewBox" class="progressCard" style="margin-top:14px;"><p class="formMessage">' +
escapeHtml(tt('confirm.loadingPreview')) + '</p></div>' +
' <div class="actionRow" style="margin-top:16px;">' +
' <button class="primaryBtn" id="agreeBtn" disabled>' + escapeHtml(tt('confirm.agreeBtn')) + '</button>' +
' <button class="secondaryBtn" id="cancelBtn">' + escapeHtml(tt('confirm.cancelBtn')) + '</button>' +
' </div>' +
'</section>'
var agreeBtn = document.getElementById('agreeBtn')
var cancelBtn = document.getElementById('cancelBtn')
var previewBox = document.getElementById('previewBox')
cancelBtn.addEventListener('click', function () { api.quit() })
api.preview().then(function (p) {
var existingDirs = p.existingDirs || []
var items = []
if (existingDirs.length) {
for (var d = 0; d < existingDirs.length; d++) {
items.push(tt('confirm.itemCustomDir', { path: existingDirs[d] }))
}
} else {
var first = (p.allTargetDirs && p.allTargetDirs[0]) || ''
items.push(tt('confirm.itemCustomDirMissing', { path: first }))
}
if (p.shortcutExists) items.push(tt('confirm.itemShortcut'))
if (p.launcherProfiles && p.launcherProfiles.length) {
items.push(tt('confirm.itemProfiles', { names: p.launcherProfiles.join(', ') }))
}
var nothing = !existingDirs.length && !p.shortcutExists && (!p.launcherProfiles || !p.launcherProfiles.length)
var html = '<p class="formMessage"><strong>' + escapeHtml(tt('confirm.previewTitle')) + '</strong></p><ul>'
for (var i = 0; i < items.length; i++) html += '<li>' + escapeHtml(items[i]) + '</li>'
html += '</ul>'
if (nothing) html += '<p class="formMessage">' + escapeHtml(tt('confirm.nothingFound')) + '</p>'
previewBox.innerHTML = html
agreeBtn.disabled = false
agreeBtn.addEventListener('click', function () { renderChoose(p) })
}).catch(function (err) {
previewBox.innerHTML = '<p class="formMessage error">' +
escapeHtml(tt('confirm.previewFail', { message: (err && err.message) || String(err) })) + '</p>'
agreeBtn.disabled = false
agreeBtn.addEventListener('click', function () { renderChoose({ existingDirs: [], allTargetDirs: [], shortcutExists: false, launcherProfiles: [] }) })
})
}
// ── 2단계: 삭제 방식 선택 ─────────────────────────
function renderChoose(preview) {
pageHost.innerHTML =
'<section class="page">' +
' <h2>' + escapeHtml(tt('choose.heading')) + '</h2>' +
' <p class="formMessage" style="margin-top:8px;">' + escapeHtml(tt('choose.intro')) + '</p>' +
' <div class="actionRow" style="margin-top:18px;flex-direction:column;gap:12px;align-items:stretch;">' +
' <button class="secondaryBtn" id="trashBtn" style="padding:16px;text-align:left;">' +
' <strong>' + escapeHtml(tt('choose.trashTitle')) + '</strong><br/>' +
' <span class="formMessage">' + escapeHtml(tt('choose.trashDesc')) + '</span></button>' +
' <button class="secondaryBtn" id="permBtn" style="padding:16px;text-align:left;">' +
' <strong>' + escapeHtml(tt('choose.permTitle')) + '</strong><br/>' +
' <span class="formMessage">' + escapeHtml(tt('choose.permDesc')) + '</span></button>' +
' </div>' +
' <div class="actionRow" style="margin-top:16px;">' +
' <button class="secondaryBtn" id="backBtn">' + escapeHtml(tt('choose.backBtn')) + '</button>' +
' </div>' +
' <div id="runState"></div>' +
'</section>'
var trashBtn = document.getElementById('trashBtn')
var permBtn = document.getElementById('permBtn')
var backBtn = document.getElementById('backBtn')
var runState = document.getElementById('runState')
backBtn.addEventListener('click', function () { renderConfirm() })
function runMode(mode) {
var warn = mode === 'permanent' ? tt('choose.confirmPermanent') : tt('choose.confirmTrash')
if (!window.confirm(warn)) return
trashBtn.disabled = true
permBtn.disabled = true
backBtn.disabled = true
runState.innerHTML = '<p class="formMessage" style="margin-top:14px;">' + escapeHtml(tt('choose.running')) + '</p>'
api.run(mode).then(function (result) {
renderResult(result, mode)
}).catch(function (err) {
runState.innerHTML = '<p class="formMessage error" style="margin-top:14px;">' +
escapeHtml(tt('choose.error', { message: (err && err.message) || String(err) })) + '</p>'
trashBtn.disabled = false
permBtn.disabled = false
backBtn.disabled = false
})
}
trashBtn.addEventListener('click', function () { runMode('trash') })
permBtn.addEventListener('click', function () { runMode('permanent') })
}
// ── 3단계: 결과 ──────────────────────────────────
function renderResult(result, mode) {
var total = (result.removed ? result.removed.length : 0) + (result.profilesRemoved ? result.profilesRemoved.length : 0)
var hasErr = result.errors && result.errors.length
var cls = hasErr ? 'error' : 'done'
var badge = hasErr ? tt('result.badgePartial') : tt('result.badgeOk')
var lines = ''
if (result.removed && result.removed.length) {
lines += '<p class="formMessage"><strong>' + escapeHtml(tt('result.removedTitle')) + '</strong></p><ul>'
for (var i = 0; i < result.removed.length; i++) lines += '<li>' + escapeHtml(result.removed[i]) + '</li>'
lines += '</ul>'
}
if (result.profilesRemoved && result.profilesRemoved.length) {
lines += '<p class="formMessage"><strong>' + escapeHtml(tt('result.profilesTitle')) + '</strong></p><ul>'
for (var j = 0; j < result.profilesRemoved.length; j++) lines += '<li>' + escapeHtml(result.profilesRemoved[j]) + '</li>'
lines += '</ul>'
}
if (hasErr) {
lines += '<p class="formMessage error"><strong>' + escapeHtml(tt('result.errorsTitle')) + '</strong></p><ul>'
for (var k = 0; k < result.errors.length; k++) lines += '<li>' + escapeHtml(result.errors[k]) + '</li>'
lines += '</ul>'
}
if (total === 0 && !hasErr) {
lines += '<p class="formMessage">' + escapeHtml(tt('result.nothing')) + '</p>'
}
pageHost.innerHTML =
'<section class="page">' +
' <div class="progressCard ' + cls + '" style="margin-top:6px;">' +
' <div class="cardTop"><span class="statusBadge ' + (hasErr ? 'fail' : 'ok') + '">' + escapeHtml(badge) + '</span> ' +
' <span class="label">' + escapeHtml(tt(mode === 'permanent' ? 'mode.permanent' : 'mode.trash')) + '</span></div>' +
lines +
' <p class="formMessage" style="margin-top:10px;"><small>' + escapeHtml(tt('result.note')) + '</small></p>' +
' </div>' +
' <div class="actionRow" style="margin-top:16px;">' +
' <button class="primaryBtn" id="quitBtn">' + escapeHtml(tt('result.quitBtn')) + '</button>' +
' </div>' +
'</section>'
document.getElementById('quitBtn').addEventListener('click', function () { api.quit() })
}
;(async function () {
try { I18N = (await api.loadLocale()) || {} } catch (_) { I18N = {} }
applyStaticI18n()
renderConfirm()
})()

View File

@@ -0,0 +1,63 @@
{
"app": {
"title": "음악퀴즈 파일제거"
},
"logViewer": {
"heading": "로그",
"collapse": "접기",
"expand": "펼치기"
},
"mode": {
"trash": "휴지통으로 이동",
"permanent": "컴퓨터에서 완전 삭제"
},
"confirm": {
"heading": "음악퀴즈 파일제거",
"question": "음악퀴즈 간편설치기로 설치한 내용들과, 음악퀴즈 관련된 내용을 전부 삭제하시겠습니까?",
"detail": "음악퀴즈 간편설치기·리소스팩설치기가 만든 게임 폴더와 캐시, 마인크래프트 런처의 음악퀴즈 프로필을 정리합니다. 평소 쓰던 .minecraft 본체는 건드리지 않습니다.",
"loadingPreview": "삭제 대상을 확인하는 중…",
"previewTitle": "삭제 대상",
"itemCustomDir": "음악퀴즈 전용 폴더: {{path}}",
"itemCustomDirMissing": "음악퀴즈 전용 폴더가 없음(이미 삭제됨): {{path}}",
"itemShortcut": "바탕화면의 'MusicQuiz Server' 바로가기",
"itemProfiles": "마인크래프트 런처 프로필: {{names}}",
"nothingFound": "삭제할 음악퀴즈 관련 항목을 찾지 못했습니다. 이미 정리된 상태일 수 있습니다.",
"previewFail": "삭제 대상 확인 실패: {{message}}",
"agreeBtn": "동의하고 계속",
"cancelBtn": "취소(종료)"
},
"choose": {
"heading": "삭제 방식 선택",
"intro": "삭제 방식을 선택하세요.",
"trashTitle": "휴지통으로 이동",
"trashDesc": "휴지통으로 옮깁니다. 실수했을 때 되돌릴 수 있습니다.",
"permTitle": "컴퓨터에서 완전 삭제",
"permDesc": "휴지통을 거치지 않고 즉시 완전히 지웁니다. 되돌릴 수 없습니다.",
"backBtn": "뒤로",
"confirmTrash": "선택한 음악퀴즈 관련 항목을 휴지통으로 이동합니다. 계속하시겠습니까?",
"confirmPermanent": "선택한 음악퀴즈 관련 항목을 컴퓨터에서 완전히 삭제합니다. 되돌릴 수 없습니다. 계속하시겠습니까?",
"running": "삭제하는 중…",
"error": "삭제 중 오류: {{message}}"
},
"result": {
"badgeOk": "완료",
"badgePartial": "일부 실패",
"removedTitle": "삭제한 항목",
"profilesTitle": "제거한 런처 프로필",
"errorsTitle": "삭제하지 못한 항목",
"nothing": "삭제할 항목이 없었습니다.",
"note": "직접 지정한 위치에 서버를 설치했다면 그 폴더는 위치를 알 수 없어 자동 삭제되지 않습니다. 필요하면 직접 삭제하세요.",
"quitBtn": "종료"
},
"log": {
"start": "삭제 시작 ({{mode}})",
"removedDir": "폴더 제거: {{path}}",
"removedShortcut": "바로가기 제거: {{path}}",
"removedProfile": "런처 프로필 제거: {{name}}",
"removeFail": "제거 실패: {{path}} — {{message}}",
"customDirMissing": "음악퀴즈 폴더가 이미 없음: {{path}}",
"launcherParseFail": "launcher_profiles.json 을 읽지 못함: {{path}}",
"launcherWriteFail": "launcher_profiles.json 갱신 실패: {{message}}",
"done": "정리 완료 — 총 {{count}}개 항목 처리"
}
}

View File

@@ -30,7 +30,8 @@
"title": "관리자 로그인",
"password": "비밀번호",
"submit": "로그인",
"wrongPassword": "비밀번호가 올바르지 않습니다."
"wrongPassword": "비밀번호가 올바르지 않습니다.",
"tooManyAttempts": "로그인 시도가 너무 많습니다. 약 {{minutes}}분 후 다시 시도해 주세요."
},
"dashboard": {
"title": "음악퀴즈 목록",

View File

@@ -1,6 +1,6 @@
{
"name": "minecraft-music-quiz-installer",
"version": "0.3.23",
"version": "0.4.0",
"description": "마인크래프트 음악퀴즈 간편설치기 + 관리 사이트",
"main": "dist/installer/main.js",
"scripts": {
@@ -10,13 +10,15 @@
"installer": "tsc -p tsconfig.installer.json && electron .",
"installer:rp": "tsc -p tsconfig.installer-rp.json && electron dist/installer-rp/main.js",
"installer:pf": "tsc -p tsconfig.installer-pf.json && electron dist/installer-pf/main.js",
"installer:uninstall": "tsc -p tsconfig.installer-uninstall.json && electron dist/installer-uninstall/main.js",
"preinstall:sharp-win32": "npm install --no-save --force @img/sharp-win32-x64@0.34.5",
"build:launcher-icon": "node scripts/build-launcher-icon.cjs",
"dist:win": "npm run preinstall:sharp-win32 && npm run build:launcher-icon && tsc -p tsconfig.installer.json && electron-builder --win --config electron-builder.yml",
"dist:win:rp": "npm run preinstall:sharp-win32 && tsc -p tsconfig.installer-rp.json && electron-builder --win --config electron-builder-rp.yml",
"dist:win:pf": "tsc -p tsconfig.installer-pf.json && electron-builder --win --config electron-builder-pf.yml",
"dist:win:dev": "npm run preinstall:sharp-win32 && npm run build:launcher-icon && tsc -p tsconfig.installer.json && electron-builder --win --config electron-builder-dev.yml",
"dist:win:rp:dev": "npm run preinstall:sharp-win32 && tsc -p tsconfig.installer-rp.json && electron-builder --win --config electron-builder-rp-dev.yml"
"dist:win:rp:dev": "npm run preinstall:sharp-win32 && tsc -p tsconfig.installer-rp.json && electron-builder --win --config electron-builder-rp-dev.yml",
"dist:win:uninstall": "tsc -p tsconfig.installer-uninstall.json && electron-builder --win --config electron-builder-uninstall.yml"
},
"dependencies": {
"@types/archiver": "^7.0.0",

View File

@@ -16,6 +16,13 @@ const localeDict = i18n.dict
let mainWindow: BrowserWindow | null = null
// 이 도구가 UPnP 로 직접 열어둔 포트. 앱이 살아 있는 동안 매핑을 유지하고,
// 창을 닫거나 종료할 때 이 포트의 매핑을 제거한다(사용자가 라우터에 직접 만든
// 영구 규칙으로 이미 열려 있던 preForwarded 포트는 우리 것이 아니므로 추적하지 않음).
let activePort: number | null = null
// before-quit 재진입 가드. 매핑 정리를 마친 뒤에만 실제 종료로 넘어가게 한다.
let cleanupDone = false
function createMainWindow(): void {
const iconPath = path.join(__dirname, '..', '..', 'build', process.platform === 'win32' ? 'icon.ico' : 'icon.png')
mainWindow = new BrowserWindow({
@@ -355,6 +362,13 @@ ipcMain.handle('pf:open', async (_event, portInput: number): Promise<PortForward
const localIp = detectLocalIpv4()
if (localIp) sendLog(t('log.localIp', { ip: localIp }))
// 다른 포트를 이미 우리가 열어둔 상태에서 새 포트를 열면, 이전 포트 매핑을 먼저 닫아
// 매핑이 새는 것을 막는다.
if (activePort !== null && activePort !== port) {
await removeUpnpMapping(activePort)
activePort = null
}
// 이전에 남은 매핑을 먼저 제거해 "사용자 라우터 규칙으로 이미 열린 상태" 와 구별.
sendLog(t('log.cleanup'))
await removeUpnpMapping(port)
@@ -387,6 +401,8 @@ ipcMain.handle('pf:open', async (_event, portInput: number): Promise<PortForward
sendLog(t('log.upnpTry', { port }))
try {
await openPortViaUpnp(port)
// 우리가 연 포트로 기록 → 앱 종료/창 닫힘 시 자동으로 매핑 제거.
activePort = port
sendLog(t('log.upnpReqOk'))
} catch (error) {
const msg = (error as Error).message
@@ -415,6 +431,7 @@ ipcMain.handle('pf:close', async (_event, portInput: number): Promise<void> => {
const port = Number.isFinite(portInput) && portInput > 0 && portInput < 65536 ? Math.floor(portInput) : 25565
sendLog(t('log.closeTry', { port }))
await removeUpnpMapping(port)
if (activePort === port) activePort = null
})
ipcMain.handle('pf:quit', async () => {
@@ -432,6 +449,20 @@ app.whenReady().then(() => {
})
})
// 창을 닫거나 종료할 때, 이 도구가 열어둔 UPnP 매핑을 제거한 뒤 실제 종료로 넘어간다.
// removeUpnpMapping 은 비동기라 before-quit 을 한 번 막고(cleanup) 끝나면 다시 quit 한다.
app.on('before-quit', (event) => {
if (cleanupDone || activePort === null) return
event.preventDefault()
const port = activePort
activePort = null
sendLog(t('log.closeTry', { port }))
void removeUpnpMapping(port).finally(() => {
cleanupDone = true
app.quit()
})
})
app.on('window-all-closed', () => {
app.quit()
})

View File

@@ -9,7 +9,7 @@ import { URL } from 'node:url'
import type { ChildProcess } from 'node:child_process'
import type { Manifest, PackDefinition, PackList } from '../shared/types.js'
import { normalizePackDefinition } from '../shared/store.js'
import { getAppDataDir, getMcCustomDir } from '../shared/paths.js'
import { getAppDataDir, getMcCustomDir, withCustomDirName } from '../shared/paths.js'
import { loadEnv, getManifestUrl } from '../shared/env.js'
import { loadComponentI18n } from '../shared/i18n.js'
import { resolveAudience, isPackVisibleForAudience, type Audience } from '../shared/audience.js'
@@ -273,7 +273,25 @@ ipcMain.handle('rp:packs:select', async (_event, packKey: string) => {
sendLog(t('log.selectedPack', { key: packKey }))
})
ipcMain.handle('rp:i18n:dict', () => localeDict)
// 개발자용 빌드(musicQuizAudience=developer)면 렌더러에 넘기는 사전의 제목 앞에
// "(개발자용) " 을 붙여, 창 제목/헤더에 개발자용임을 표시한다.
function dictForRenderer(): Record<string, unknown> {
// 커스텀 폴더명을 UI 문구에 반영.
const base = withCustomDirName(localeDict)
if (getAudience() !== 'developer') return base
const prefix = '(개발자용) '
const appBlock = (base.app ?? {}) as Record<string, unknown>
const title = appBlock.title
return {
...base,
app: {
...appBlock,
title: typeof title === 'string' && !title.startsWith(prefix) ? prefix + title : title
}
}
}
ipcMain.handle('rp:i18n:dict', () => dictForRenderer())
// ── IPC: 약관 다운로드 ──────────────────────────────
// v0.3.4~ : 사이트에서 임의 kind 가 만들어질 수 있으니 5종 화이트리스트 대신

View File

@@ -0,0 +1,224 @@
import { app, BrowserWindow, ipcMain, shell } from 'electron'
import path from 'node:path'
import fs from 'node:fs'
import fsp from 'node:fs/promises'
import { loadEnv } from '../shared/env.js'
import { getAppDataDir, getMcCustomDir } from '../shared/paths.js'
import { loadComponentI18n } from '../shared/i18n.js'
// 음악퀴즈 파일제거 도구. 음악퀴즈 간편설치기 / 리소스팩설치기가 만든 데이터를
// 한 번에 정리한다. (설치기 exe 자체는 사용자가 임의 위치에 둔 포터블이라
// 위치를 알 수 없어 삭제 대상에서 제외)
loadEnv()
const i18n = loadComponentI18n('installer-uninstall')
const t = i18n.t
const localeDict = i18n.dict
let mainWindow: BrowserWindow | null = null
function createMainWindow(): void {
const iconPath = path.join(__dirname, '..', '..', 'build', process.platform === 'win32' ? 'icon.ico' : 'icon.png')
mainWindow = new BrowserWindow({
width: 720,
height: 620,
icon: iconPath,
webPreferences: {
preload: path.join(__dirname, 'preload.js'),
contextIsolation: true,
nodeIntegration: false
}
})
mainWindow.removeMenu()
void mainWindow.loadFile(path.join(__dirname, '..', '..', 'installer-uninstall', 'index.html'))
}
function sendLog(line: string): void {
if (!mainWindow || mainWindow.isDestroyed()) return
const stamped = `[${new Date().toLocaleTimeString('ko-KR', { hour12: false })}] ${line}`
mainWindow.webContents.send('log', stamped)
}
/** 마인크래프트 런처 프로필 파일 경로. */
function launcherProfilesPath(): string {
return path.join(getAppDataDir(), '.minecraft', 'launcher_profiles.json')
}
/** 데스크톱에 설치기가 만든 서버 실행 바로가기 경로. */
function serverShortcutPath(): string {
return path.join(app.getPath('desktop'), 'MusicQuiz Server.lnk')
}
/** 기본 폴더 이름(.mc_custom) 경로. MC_CUSTOM_DIR 을 바꿔 빌드해도, 예전 기본 폴더가 남아 있을 수 있으므로 함께 지운다. */
function defaultCustomDir(): string {
return path.join(getAppDataDir(), '.mc_custom')
}
/** 삭제 대상 커스텀 폴더 후보(현재 설정값 + 기본 .mc_custom)를 대소문자 무시로 중복 제거. */
function targetCustomDirs(): string[] {
const seen = new Set<string>()
const out: string[] = []
for (const dir of [getMcCustomDir(), defaultCustomDir()]) {
const key = path.resolve(dir).toLowerCase()
if (!seen.has(key)) {
seen.add(key)
out.push(dir)
}
}
return out
}
/** 두 경로가 같은 폴더거나, a 가 b 하위인지(대소문자 무시 — Windows 파일계). */
function isSameOrInside(child: string, parent: string): boolean {
const c = path.resolve(child).replace(/[\\/]+$/, '').toLowerCase()
const p = path.resolve(parent).replace(/[\\/]+$/, '').toLowerCase()
return c === p || c.startsWith(p + path.sep.toLowerCase()) || c.startsWith(p + '/')
}
interface UninstallPreview {
existingDirs: string[]
allTargetDirs: string[]
shortcutExists: boolean
launcherProfiles: string[]
}
/** 삭제 전 미리보기: 실제로 존재하는 대상만 추려 렌더러에 보여준다. */
ipcMain.handle('uninstall:preview', async (): Promise<UninstallPreview> => {
const allTargetDirs = targetCustomDirs()
const existingDirs = allTargetDirs.filter((d) => fs.existsSync(d))
const shortcutExists = fs.existsSync(serverShortcutPath())
const launcherProfiles = findMusicQuizProfiles(allTargetDirs)
return { existingDirs, allTargetDirs, shortcutExists, launcherProfiles }
})
/** launcher_profiles.json 에서 gameDir 가 커스텀 폴더(또는 그 하위)인 프로필 이름 목록. */
function findMusicQuizProfiles(customDirs: string[]): string[] {
const file = launcherProfilesPath()
if (!fs.existsSync(file)) return []
try {
const json = JSON.parse(fs.readFileSync(file, 'utf8')) as {
profiles?: Record<string, { name?: string; gameDir?: string }>
}
const profiles = json.profiles ?? {}
const names: string[] = []
for (const [key, prof] of Object.entries(profiles)) {
const gameDir = typeof prof?.gameDir === 'string' ? prof.gameDir : ''
if (gameDir && customDirs.some((d) => isSameOrInside(gameDir, d))) {
names.push(typeof prof?.name === 'string' && prof.name ? prof.name : key)
}
}
return names
} catch {
return []
}
}
interface UninstallResult {
removed: string[]
profilesRemoved: string[]
errors: string[]
}
/** 하나의 파일/폴더를 mode 에 따라 휴지통 이동 또는 완전 삭제. */
async function removeOne(target: string, mode: 'trash' | 'permanent'): Promise<void> {
if (mode === 'trash') {
await shell.trashItem(target)
} else {
await fsp.rm(target, { recursive: true, force: true })
}
}
/** launcher_profiles.json 에서 음악퀴즈 프로필만 제거하고 나머지는 보존. */
async function cleanLauncherProfiles(customDirs: string[]): Promise<string[]> {
const file = launcherProfilesPath()
if (!fs.existsSync(file)) return []
let json: { profiles?: Record<string, { name?: string; gameDir?: string }> }
try {
json = JSON.parse(await fsp.readFile(file, 'utf8'))
} catch {
sendLog(t('log.launcherParseFail', { path: file }))
return []
}
const profiles = json.profiles ?? {}
const removed: string[] = []
for (const [key, prof] of Object.entries(profiles)) {
const gameDir = typeof prof?.gameDir === 'string' ? prof.gameDir : ''
if (gameDir && customDirs.some((d) => isSameOrInside(gameDir, d))) {
removed.push(typeof prof?.name === 'string' && prof.name ? prof.name : key)
delete profiles[key]
}
}
if (removed.length > 0) {
json.profiles = profiles
await fsp.writeFile(file, `${JSON.stringify(json, null, 2)}\n`, 'utf8')
}
return removed
}
ipcMain.handle('uninstall:run', async (_event, modeInput: unknown): Promise<UninstallResult> => {
const mode: 'trash' | 'permanent' = modeInput === 'permanent' ? 'permanent' : 'trash'
const customDirs = targetCustomDirs()
const removed: string[] = []
const errors: string[] = []
sendLog(t('log.start', { mode: t(mode === 'trash' ? 'mode.trash' : 'mode.permanent') }))
// 1) 커스텀 게임/캐시 폴더 통째로(현재 설정값 + 기본 .mc_custom).
for (const customDir of customDirs) {
if (fs.existsSync(customDir)) {
try {
await removeOne(customDir, mode)
removed.push(customDir)
sendLog(t('log.removedDir', { path: customDir }))
} catch (err) {
const msg = (err as Error).message
errors.push(`${customDir}: ${msg}`)
sendLog(t('log.removeFail', { path: customDir, message: msg }))
}
} else {
sendLog(t('log.customDirMissing', { path: customDir }))
}
}
// 2) 데스크톱 서버 실행 바로가기.
const shortcut = serverShortcutPath()
if (fs.existsSync(shortcut)) {
try {
await removeOne(shortcut, mode)
removed.push(shortcut)
sendLog(t('log.removedShortcut', { path: shortcut }))
} catch (err) {
const msg = (err as Error).message
errors.push(`${shortcut}: ${msg}`)
sendLog(t('log.removeFail', { path: shortcut, message: msg }))
}
}
// 3) 마인크래프트 런처 프로필에서 음악퀴즈 설정 제거.
let profilesRemoved: string[] = []
try {
profilesRemoved = await cleanLauncherProfiles(customDirs)
for (const name of profilesRemoved) sendLog(t('log.removedProfile', { name }))
} catch (err) {
const msg = (err as Error).message
errors.push(`launcher_profiles.json: ${msg}`)
sendLog(t('log.launcherWriteFail', { message: msg }))
}
sendLog(t('log.done', { count: removed.length + profilesRemoved.length }))
return { removed, profilesRemoved, errors }
})
ipcMain.handle('uninstall:i18n:dict', () => localeDict)
ipcMain.handle('uninstall:quit', () => app.quit())
app.whenReady().then(() => {
createMainWindow()
app.on('activate', () => {
if (BrowserWindow.getAllWindows().length === 0) createMainWindow()
})
})
app.on('window-all-closed', () => {
app.quit()
})

View File

@@ -0,0 +1,43 @@
import { contextBridge, ipcRenderer } from 'electron'
interface UninstallPreview {
customDir: string
customDirExists: boolean
shortcutExists: boolean
launcherProfiles: string[]
}
interface UninstallResult {
removed: string[]
profilesRemoved: string[]
errors: string[]
}
const api = {
/** i18n 사전을 렌더러에 전달. */
loadLocale: (): Promise<Record<string, unknown>> => ipcRenderer.invoke('uninstall:i18n:dict'),
/** 삭제 전, 실제로 존재하는 대상 미리보기. */
preview: (): Promise<UninstallPreview> => ipcRenderer.invoke('uninstall:preview'),
/** 삭제 실행. mode: 'trash'(휴지통) | 'permanent'(완전 삭제). */
run: (mode: 'trash' | 'permanent'): Promise<UninstallResult> => ipcRenderer.invoke('uninstall:run', mode),
/** 프로그램 종료. */
quit: (): Promise<void> => ipcRenderer.invoke('uninstall:quit'),
/** 로그 스트림 구독. */
onLog: (handler: (line: string) => void): (() => void) => {
const listener = (_event: unknown, line: string) => handler(line)
ipcRenderer.on('log', listener)
return () => ipcRenderer.removeListener('log', listener)
}
}
contextBridge.exposeInMainWorld('uninstaller', api)
declare global {
interface Window {
uninstaller: typeof api
}
}

View File

@@ -20,6 +20,7 @@ import type {
} from './types.js'
import type { Manifest, PackDefinition } from '../shared/types.js'
import { normalizePackDefinition } from '../shared/store.js'
import { getMcCustomDirName, withCustomDirName } from '../shared/paths.js'
import { loadEnv, getManifestUrl } from '../shared/env.js'
import { loadComponentI18n } from '../shared/i18n.js'
import { resolveAudience, isPackVisibleForAudience, type Audience } from '../shared/audience.js'
@@ -656,7 +657,12 @@ ipcMain.handle('server:fetchMinecraftEula', async (): Promise<{ url: string; htm
ipcMain.handle('server:acceptEula', async (_event, installPath: string) => {
const target = path.join(installPath, 'eula.txt')
await fsp.writeFile(target, `# Generated by music quiz installer\neula=true\n`, 'utf8')
const acceptedAt = new Date()
await fsp.writeFile(
target,
`# Generated by music quiz installer\n# EULA accepted at: ${acceptedAt.toISOString()}\neula=true\n`,
'utf8',
)
sendLog(t('log.eulaAccepted'))
})
@@ -1039,7 +1045,7 @@ function sleep(ms: number): Promise<void> {
ipcMain.handle('client:install', async (_event, payload: ClientInstallPayload) => {
const pack = state.packs.get(payload.packKey)
if (!pack) throw new Error(t('errors.packNotFound2'))
const customRoot = path.join(getAppDataDir(), '.mc_custom')
const customRoot = path.join(getAppDataDir(), getMcCustomDirName())
await fsp.mkdir(path.join(customRoot, 'mods'), { recursive: true })
await fsp.mkdir(path.join(customRoot, 'resourcepacks'), { recursive: true })
@@ -1582,7 +1588,27 @@ ipcMain.handle('finish:startLauncher', async () => {
sendLog(t('log.launcherAllFail'))
})
ipcMain.handle('i18n:dict', () => localeDict)
// 개발자용 빌드(musicQuizAudience=developer)면 렌더러에 넘기는 사전의 제목 앞에
// "(개발자용) " 을 붙여, 창 제목/헤더에 개발자용임을 표시한다.
function dictForRenderer(): Record<string, unknown> {
// 커스텀 폴더명을 UI 문구에 반영.
const base = withCustomDirName(localeDict)
if (getAudience() !== 'developer') return base
const prefix = '(개발자용) '
const appBlock = (base.app ?? {}) as Record<string, unknown>
const withPrefix = (v: unknown): unknown =>
typeof v === 'string' && !v.startsWith(prefix) ? prefix + v : v
return {
...base,
app: {
...appBlock,
browserTitle: withPrefix(appBlock.browserTitle),
headerTitle: withPrefix(appBlock.headerTitle)
}
}
}
ipcMain.handle('i18n:dict', () => dictForRenderer())
ipcMain.handle('app:quit', () => {
// 모든 창을 닫고 앱 종료. macOS에서도 종료(설치기는 한 번 쓰고 끝이니 잔류시키지 않음).

View File

@@ -1,10 +1,13 @@
import express from 'express'
import session from 'express-session'
import path from 'node:path'
import fs from 'node:fs'
import fsp from 'node:fs/promises'
import crypto from 'node:crypto'
import {
manifestRootPath, manifestDirPath, manifestTermsDirPath,
fileDirPath, viewsDirPath, publicDirPath
fileDirPath, viewsDirPath, publicDirPath, projectRoot,
accountFilePath, accountLocalFilePath
} from '../shared/paths.js'
import {
ensurePackTermsDir, isPublicTermsFile, listTermsWithLabels, loadPackDefinition
@@ -25,7 +28,24 @@ const app = express()
app.set('view engine', 'ejs')
app.set('views', viewsDirPath)
app.set('trust proxy', 1)
// 리버스 프록시 뒤일 때만 켠다. 항상 켜두면 직접 노출 시 X-Forwarded-For 조작으로
// req.ip 를 위조해 로그인 rate limit 을 우회할 수 있다. 프록시 뒤라면 TRUST_PROXY=true.
app.set('trust proxy', process.env.TRUST_PROXY === 'true' ? 1 : false)
// 추적되는 account.json(과거 평문 노출)을 gitignore 된 account.local.json 으로 시드한다.
// 로컬 파일이 이미 있으면 건드리지 않음. 이후 계정 쓰기/자동 해시 업그레이드는 로컬
// 파일에만 반영되어, 재배포로 account.json 을 추적 해제해도 로그인이 유지된다.
function seedLocalAccounts(): void {
try {
if (fs.existsSync(accountLocalFilePath)) return
if (!fs.existsSync(accountFilePath)) return
fs.copyFileSync(accountFilePath, accountLocalFilePath)
fs.chmodSync(accountLocalFilePath, 0o600)
} catch {
// 실패해도 readAccounts 가 account.json 으로 폴백하므로 치명적이지 않음.
}
}
seedLocalAccounts()
app.use(express.urlencoded({ extended: true }))
app.use(express.json())
@@ -38,13 +58,36 @@ app.use((_req, res, next) => {
next()
})
// 세션 시크릿: 환경변수 우선, 없으면 하드코딩(위조 위험) 대신 영구 랜덤 시크릿을
// 파일로 생성/보관한다(재시작해도 세션 유지). 파일 접근 불가 시엔 프로세스 수명 동안만
// 유효한 랜덤값으로 폴백(그래도 하드코딩보다 안전).
function resolveSessionSecret(): string {
const fromEnv = process.env.SESSION_SECRET
if (fromEnv && fromEnv.length >= 16) return fromEnv
const secretPath = path.join(projectRoot, '.session-secret')
try {
if (fs.existsSync(secretPath)) {
const existing = fs.readFileSync(secretPath, 'utf8').trim()
if (existing.length >= 16) return existing
}
const generated = crypto.randomBytes(32).toString('hex')
fs.writeFileSync(secretPath, generated, { mode: 0o600 })
return generated
} catch {
return crypto.randomBytes(32).toString('hex')
}
}
app.use(session({
secret: process.env.SESSION_SECRET ?? 'music-quiz-installer-dev-secret',
secret: resolveSessionSecret(),
resave: false,
saveUninitialized: false,
cookie: {
httpOnly: true,
sameSite: 'lax',
// HTTPS 전용 배포면 SESSION_COOKIE_SECURE=true 로 secure 쿠키 활성화.
// HTTP 접근이 섞이면 로그인 쿠키가 안 실리므로 기본값은 false.
secure: process.env.SESSION_COOKIE_SECURE === 'true',
maxAge: 1000 * 60 * 60 * 8
}
}))

48
src/server/password.ts Normal file
View File

@@ -0,0 +1,48 @@
import crypto from 'node:crypto'
// 운영자 비밀번호 저장/검증. 외부 의존성 없이 Node 내장 scrypt 사용.
// 저장 형식: `scrypt$<saltHex>$<hashHex>`. 검증은 항상 상수시간 비교.
// 기존 account.json 의 평문 비밀번호는 verifyPassword 가 그대로 검증할 수 있고,
// 로그인 성공 시 호출측에서 hashPassword 로 재저장(자동 업그레이드)한다.
const SCHEME = 'scrypt'
const KEY_LEN = 32
const SALT_LEN = 16
export function hashPassword(plain: string): string {
const salt = crypto.randomBytes(SALT_LEN)
const hash = crypto.scryptSync(plain, salt, KEY_LEN)
return `${SCHEME}$${salt.toString('hex')}$${hash.toString('hex')}`
}
export function isHashed(stored: string): boolean {
return typeof stored === 'string' && stored.startsWith(`${SCHEME}$`)
}
export function verifyPassword(plain: string, stored: string): boolean {
if (typeof stored !== 'string' || stored.length === 0) return false
if (isHashed(stored)) {
const parts = stored.split('$')
if (parts.length !== 3) return false
let salt: Buffer
let expected: Buffer
try {
salt = Buffer.from(parts[1], 'hex')
expected = Buffer.from(parts[2], 'hex')
} catch {
return false
}
if (expected.length === 0) return false
let derived: Buffer
try {
derived = crypto.scryptSync(plain, salt, expected.length)
} catch {
return false
}
return derived.length === expected.length && crypto.timingSafeEqual(derived, expected)
}
// 레거시 평문: 길이 노출을 피하려 양쪽을 sha256 으로 고정 길이화한 뒤 상수시간 비교.
const a = crypto.createHash('sha256').update(plain, 'utf8').digest()
const b = crypto.createHash('sha256').update(stored, 'utf8').digest()
return crypto.timingSafeEqual(a, b)
}

View File

@@ -22,8 +22,10 @@ import {
saveTerm,
savePackList,
setPackPublic,
setTermVisibility
setTermVisibility,
writeAccounts
} from '../../shared/store.js'
import { hashPassword, isHashed, verifyPassword } from '../password.js'
import { fetchReleaseVersions } from '../../shared/mojang.js'
import { fetchPlaylistEntries, fetchVideoMeta, YtDlpUnavailableError } from '../youtube.js'
import { requireAuth } from '../middleware/auth.js'
@@ -33,6 +35,40 @@ import { buildSongsMcfunction } from '../datapack.js'
export const opRouter = Router()
// 로그인 브루트포스 + scrypt CPU 남용 방지용 IP 기준 인메모리 실패 제한.
const LOGIN_WINDOW_MS = 15 * 60 * 1000
const LOGIN_MAX_FAILS = 10
const loginFails = new Map<string, { count: number; first: number; blockedUntil: number }>()
function loginClientKey(req: { ip?: string; socket?: { remoteAddress?: string } }): string {
return req.ip || req.socket?.remoteAddress || 'unknown'
}
/** 차단 중이면 남은 ms, 아니면 0. 접근 시 만료된 항목은 정리. */
function loginBlockedMs(key: string): number {
const now = Date.now()
const entry = loginFails.get(key)
if (!entry) return 0
if (entry.blockedUntil > now) return entry.blockedUntil - now
if (now - entry.first > LOGIN_WINDOW_MS) loginFails.delete(key)
return 0
}
function recordLoginFail(key: string): void {
const now = Date.now()
let entry = loginFails.get(key)
if (!entry || now - entry.first > LOGIN_WINDOW_MS) entry = { count: 0, first: now, blockedUntil: 0 }
entry.count += 1
if (entry.count >= LOGIN_MAX_FAILS) entry.blockedUntil = now + LOGIN_WINDOW_MS
loginFails.set(key, entry)
// 맵 무한 성장 방지(분산 시도 대비): 상한 초과 시 만료 항목 정리.
if (loginFails.size > 5000) {
for (const [k, v] of loginFails) {
if (v.blockedUntil <= now && now - v.first > LOGIN_WINDOW_MS) loginFails.delete(k)
}
}
}
function pickFirstValue(value: unknown): string {
if (Array.isArray(value)) return typeof value[0] === 'string' ? value[0] : ''
return typeof value === 'string' ? value : ''
@@ -56,13 +92,32 @@ opRouter.get('/op', (req, res) => {
opRouter.post('/op', async (req, res, next) => {
try {
const clientKey = loginClientKey(req)
const blockedMs = loginBlockedMs(clientKey)
if (blockedMs > 0) {
res.status(429).render('op/login', {
error: t('login.tooManyAttempts', { minutes: Math.ceil(blockedMs / 60000) })
})
return
}
const password = pickFirstValue(req.body.password)
const accounts = await readAccounts()
const matched = accounts.find((entry) => entry.password === password)
const matched = accounts.find((entry) => verifyPassword(password, entry.password))
if (!matched) {
recordLoginFail(clientKey)
res.status(401).render('op/login', { error: t('login.wrongPassword') })
return
}
loginFails.delete(clientKey)
// 평문으로 저장돼 있던 비밀번호는 로그인 성공 시 scrypt 해시로 자동 업그레이드.
if (!isHashed(matched.password)) {
try {
matched.password = hashPassword(password)
await writeAccounts(accounts)
} catch {
// 업그레이드 실패는 로그인 자체에 영향 주지 않음.
}
}
req.session.userId = matched.id
res.redirect('/op/dashboard')
} catch (error) {

View File

@@ -73,7 +73,9 @@ export function createI18n(filePath: string): I18n {
* 1. 패키징된 Electron 앱이면 `process.resourcesPath/locales/<component>/ko-kr.json`
* 2. `<프로젝트 루트>/locales/<component>/ko-kr.json`
*/
export function loadComponentI18n(component: 'server' | 'installer' | 'installer-rp' | 'installer-pf'): I18n {
export function loadComponentI18n(
component: 'server' | 'installer' | 'installer-rp' | 'installer-pf' | 'installer-uninstall'
): I18n {
// 컴파일된 dist/shared/i18n.js 기준으로 프로젝트 루트는 2단계 위.
const projectRoot = path.resolve(__dirname, '..', '..')

View File

@@ -6,7 +6,17 @@ export const projectRoot = path.resolve(__dirname, '..', '..')
export const manifestRootPath = path.join(projectRoot, 'manifest.json')
export const manifestDirPath = path.join(projectRoot, 'manifest')
export const manifestTermsDirPath = path.join(manifestDirPath, 'terms')
// 추적되는 account.json(과거 평문 노출)을 대체할, gitignore 된 운영 계정 파일.
// readAccounts 는 이 파일을 우선 사용하고, 없을 때만 account.json 을 시드로 읽는다.
//
// TODO(untrack-after-redeploy): account.json 은 아직 git 추적 상태다. 절대 지금
// 같은 커밋에서 `git rm --cached account.json` 하지 말 것 — 서버에 account.local.json
// 이 아직 없을 때 시드 소스가 사라져 로그인이 막힌다(chicken-and-egg).
// 안전한 순서: (1) 이 커밋 배포 → 서버가 account.local.json(0o600) 자동 생성 확인 →
// (2) 그 다음 후속 커밋에서 account.json 추적 해제.
// 주의: 추적 해제는 위생일 뿐, 히스토리의 평문 비밀번호는 지워지지 않는다 → 비밀번호 로테이션이 실질 조치.
export const accountFilePath = path.join(projectRoot, 'account.json')
export const accountLocalFilePath = path.join(projectRoot, 'account.local.json')
export const fileDirPath = path.join(projectRoot, 'file')
export const fileListDirPath = path.join(fileDirPath, 'list')
export const fileDatapacksDirPath = path.join(fileDirPath, 'datapacks')
@@ -29,9 +39,43 @@ export function getAppDataDir(): string {
return process.env.XDG_CONFIG_HOME || path.join(os.homedir(), '.config')
}
/** %appdata%/.mc_custom — 음악퀴즈 관련 외부 도구/캐시 보관 디렉터리. */
/**
* 커스텀 게임 디렉터리의 폴더 이름. 기본은 `.mc_custom` 이지만 환경변수
* `MC_CUSTOM_DIR` 로 다른 이름을 지정할 수 있다(.env / .env.build 로 주입).
* 경로 구분자·상위경로 이스케이프(`/`, `\`, `..`)는 제거해 항상 %appdata%
* 바로 아래 단일 폴더로 강제한다.
*/
export function getMcCustomDirName(): string {
const raw = (process.env.MC_CUSTOM_DIR ?? '').trim()
if (!raw) return '.mc_custom'
const sanitized = raw.replace(/[\\/]+/g, '').replace(/\.\.+/g, '.')
return sanitized || '.mc_custom'
}
/** %appdata%/<MC_CUSTOM_DIR|.mc_custom> — 음악퀴즈 관련 게임 폴더/외부 도구/캐시 보관 디렉터리. */
export function getMcCustomDir(): string {
return path.join(getAppDataDir(), '.mc_custom')
return path.join(getAppDataDir(), getMcCustomDirName())
}
/**
* 사전/문자열 구조 안의 리터럴 `.mc_custom` 을 실제 폴더 이름으로 치환한 깊은
* 복사본을 돌려준다. 기본값(`.mc_custom`)이면 원본을 그대로 반환한다. 렌더러로
* 넘기는 i18n 사전에 적용해 UI 안내 문구가 실제 폴더 이름과 어긋나지 않게 한다.
*/
export function withCustomDirName<T>(value: T): T {
const name = getMcCustomDirName()
if (name === '.mc_custom') return value
const replace = (v: unknown): unknown => {
if (typeof v === 'string') return v.split('.mc_custom').join(name)
if (Array.isArray(v)) return v.map(replace)
if (v && typeof v === 'object') {
const out: Record<string, unknown> = {}
for (const [k, val] of Object.entries(v as Record<string, unknown>)) out[k] = replace(val)
return out
}
return v
}
return replace(value) as T
}
/**

View File

@@ -3,7 +3,7 @@ import fsp from 'node:fs/promises'
import path from 'node:path'
import {
manifestRootPath, manifestDirPath, manifestTermsDirPath,
accountFilePath, fileListDirPath
accountFilePath, accountLocalFilePath, fileListDirPath
} from './paths.js'
import type {
Manifest, ManifestEntry, PackDefinition, AccountEntry, LoaderType,
@@ -778,14 +778,24 @@ export function isPublicTermsFile(packKey: string, fileName: string): boolean {
}
export async function readAccounts(): Promise<AccountEntry[]> {
try {
const raw = await fsp.readFile(accountFilePath, 'utf8')
const parsed = JSON.parse(raw)
if (!Array.isArray(parsed)) return []
return parsed.filter((entry): entry is AccountEntry =>
typeof entry?.id === 'string' && typeof entry?.password === 'string')
} catch (error) {
if ((error as NodeJS.ErrnoException).code === 'ENOENT') return []
throw error
// gitignore 된 account.local.json 우선. 없으면(ENOENT) 추적되는 account.json 을 시드로.
for (const filePath of [accountLocalFilePath, accountFilePath]) {
try {
const raw = await fsp.readFile(filePath, 'utf8')
const parsed = JSON.parse(raw)
if (!Array.isArray(parsed)) return []
return parsed.filter((entry): entry is AccountEntry =>
typeof entry?.id === 'string' && typeof entry?.password === 'string')
} catch (error) {
if ((error as NodeJS.ErrnoException).code === 'ENOENT') continue
throw error
}
}
return []
}
// 운영 계정 저장은 항상 gitignore 된 account.local.json 에만 한다(추적 파일 오염 방지).
// 비밀번호(해시) 파일이므로 소유자만 읽기/쓰기(0o600).
export async function writeAccounts(accounts: AccountEntry[]): Promise<void> {
await fsp.writeFile(accountLocalFilePath, `${JSON.stringify(accounts, null, 2)}\n`, { mode: 0o600 })
}

View File

@@ -0,0 +1,4 @@
{
"extends": "./tsconfig.json",
"include": ["src/installer-uninstall/**/*.ts", "src/shared/**/*.ts"]
}