diff --git a/packaging/ota/publish-public.sh b/packaging/ota/publish-public.sh index 04892852a..55ffb3bcf 100755 --- a/packaging/ota/publish-public.sh +++ b/packaging/ota/publish-public.sh @@ -94,6 +94,10 @@ src, out, base = sys.argv[1:4] m = json.load(open(src)) for e in m.get("platforms", {}).values(): e["url"] = base + "/" + e["url"].rsplit("/", 1)[1] +# the interface entry is signed over its own URL in the token folder and the apps read it from the token manifest, +# never from here; the public copy is the site's download index, so the entry is left out (7 October 2026: the +# --public arm had refused every publish since interface 1.0.1 because the entry carried the token) +m.pop("ui", None) open(out, "w").write(json.dumps(m, sort_keys=True, separators=(",", ":"), ensure_ascii=False)) PY if grep -q "$TOKEN" "$tmp"; then rm -f "$tmp"; log "ERROR: the public $name would still carry the token" >&2; return 1; fi