fix(gui): fix UAC SmartScreen and scrolling UI layout

This commit is contained in:
ospab 2026-07-08 22:45:03 +03:00
parent b2ee9eb010
commit fbc37e9d39
3 changed files with 41 additions and 18 deletions

View File

@ -766,10 +766,34 @@ fn launch_as_admin(exe: &std::path::PathBuf, token: &str, port: u16) -> anyhow::
// Use the GUI executable's directory as the working directory so dependencies are found
let cwd_path = std::env::current_exe().unwrap_or_else(|_| std::path::PathBuf::from("."));
let dir_wstr: Vec<u16> = cwd_path.parent().unwrap_or(std::path::Path::new(".")).as_os_str().encode_wide().chain(Some(0)).collect();
let ret = unsafe { ShellExecuteW(null_mut(), verb_wstr.as_ptr(), exe_wstr.as_ptr(), params_wstr.as_ptr(), dir_wstr.as_ptr(), 0) };
if ret <= 32 { anyhow::bail!("UAC denied or helper missing."); }
// Remove Mark of the Web (Zone.Identifier) so SmartScreen doesn't block UAC
let zone_id = format!("{}:Zone.Identifier", exe.display());
let _ = std::fs::remove_file(zone_id);
// Use SW_SHOWNORMAL (1) instead of SW_HIDE (0) because runas with SW_HIDE is automatically blocked by UAC
let ret = unsafe { ShellExecuteW(null_mut(), verb_wstr.as_ptr(), exe_wstr.as_ptr(), params_wstr.as_ptr(), dir_wstr.as_ptr(), 1) };
// ShellExecuteW's return is a pseudo-HINSTANCE: > 32 means the call itself
// "succeeded" — but that range INCLUDES ERROR_CANCELLED (1223), which is
// exactly what Windows returns when the user clicks "No" on the UAC prompt.
// The old `ret <= 32` check alone treated a user-denied prompt as success,
// silently starting nothing and reporting a single opaque "denied or
// missing" message that could not distinguish "no prompt ever shown"
// (missing exe, ret<=32) from "prompt shown and declined" (ret==1223) from
// any other Win32 failure — exactly the ambiguity blocking diagnosis here.
if ret == 1223 {
anyhow::bail!("UAC elevation was denied. TUN mode requires administrator privileges.");
}
if ret <= 32 {
let win_err = unsafe { GetLastError() };
anyhow::bail!(
"Failed to request UAC elevation for the TUN helper (ShellExecuteW ret={}, \
GetLastError={}, path={}). If this keeps happening with no prompt ever appearing, \
an unsigned binary can be silently blocked by SmartScreen/antivirus during \
elevation try running ostp-gui.exe as Administrator manually.",
ret, win_err, exe.display()
);
}
Ok(())
}

View File

@ -280,10 +280,11 @@
</label>
</div>
</div>
</div> <!-- client-settings-card -->
<div class="app-version" id="app-version">OSTP GUI</div>
</div>
</div>
</div> <!-- settings-body -->
</div> <!-- settings-screen -->
<!-- ── ADD PROFILE DROPDOWN ─────────────────────────────── -->
<div id="add-menu" class="add-menu hidden">

View File

@ -84,7 +84,7 @@
/* ── Reset ───────────────────────────────────────────────────────────── */
*, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; }
html, body { width: 100%; height: 100%; background: var(--c-bg); overflow: hidden; user-select: none; }
html, body { width: 100%; height: 100%; background: var(--c-bg); user-select: none; }
button { cursor: pointer; font-family: inherit; border: none; background: none; }
input, textarea, select { font-family: inherit; }
a { text-decoration: none; }
@ -356,8 +356,12 @@ a { text-decoration: none; }
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
gap: 2px;
padding: 10px 18px;
padding: 10px 4px;
flex: 1;
min-width: 80px;
white-space: nowrap;
}
.live-stat-label {
font-size: 0.6rem;
@ -408,19 +412,13 @@ a { text-decoration: none; }
.settings-body {
flex: 1;
min-height: 0;
display: flex;
flex-direction: column;
gap: 0;
overflow-y: auto;
overflow-x: hidden;
scrollbar-width: thin;
scrollbar-color: rgba(255,255,255,0.07) transparent;
overflow-y: scroll;
scrollbar-width: none;
padding-bottom: 20px;
position: relative;
z-index: 1;
}
.settings-body::-webkit-scrollbar { width: 3px; }
.settings-body::-webkit-scrollbar-thumb { background: rgba(255,255,255,0.07); border-radius: 10px; }
.settings-body::-webkit-scrollbar { display: none; }
/* ── Profile list ────────────────────────────────────────────────────── */
.profile-list {