caspian-native
Optional Tauri packaging for applications built with the Caspian framework and
PulsePoint. Version 0.0.1 packages the existing application in a system
WebView; it does not translate HTML into operating-system widgets.
Support in 0.0.1
| Target | Backend | Status |
|---|---|---|
| Windows | Embedded Python sidecar | Initial support |
| Windows | Remote Caspian server | Initial support |
| Android | Remote Caspian server | Initial support |
| Android | Embedded Python | Not supported yet |
Android embedded Python is deliberately refused. A Caspian application may
depend on native Python wheels such as asyncpg, cryptography, or Pillow;
shipping an APK without proving every wheel for every ABI would produce a
package that builds unreliably or fails on launch.
Install for development
python -m pip install -e ".[test,build]"
Tauri's CLI is installed separately so it can match the version selected by
the generated application's native/Cargo.toml:
cargo install tauri-cli --version "^2" --locked
Add native packaging to a Caspian project
From a directory containing caspian.config.json:
caspian-native init --identifier com.example.myapp --windows
caspian-native doctor --target windows
caspian-native backend build
caspian-native dev --target windows
caspian-native build --target windows
For an Android thin client backed by a deployed Caspian server:
caspian-native init \
--identifier com.example.myapp \
--windows --android \
--remote-url https://app.example.com
caspian-native doctor --target android
caspian-native build --target android
When Android is enabled, init also runs Tauri's non-interactive Android
project initializer. dev and build repeat this check and automatically
initialize native/gen/android for projects created by an earlier version.
The generated tauri.android.conf.json removes the desktop-only Python
sidecar from Android builds; Android always loads the configured remote server.
The generated files live under native/. Re-running init never overwrites a
changed generated file unless --force is supplied.
Configuration
caspian.native.json is the source of truth:
{
"$schema": "./caspian.native.schema.json",
"schema": 1,
"productName": "My App",
"identifier": "com.example.myapp",
"version": "0.0.1",
"targets": ["windows"],
"window": {
"title": "My App",
"width": 1200,
"height": 800,
"resizable": true
},
"backend": {
"desktopMode": "embedded",
"remoteUrl": null
},
"security": {
"loopbackToken": true
}
}
Runtime model
Embedded desktop mode builds main.py, the Caspian runtime, project modules,
route index, and public/ into a one-file sidecar. The sidecar:
- restores a per-installation
AUTH_SECRETfrom application data; - imports the project's
main.appin production mode; - binds
127.0.0.1on an operating-system-assigned port; - prints the protected launch URL to the Tauri host;
- serves the normal Caspian ASGI application with Uvicorn.
The WebView receives a per-launch token once. The native middleware exchanges
it for an HttpOnly; SameSite=Strict cookie and refuses documents, assets,
RPCs, uploads, streams, and WebSocket handshakes without that cookie.
Caspian's production session cookie normally has the Secure flag. A packaged
loopback server intentionally uses http://127.0.0.1, so the adapter changes
only that middleware option before Starlette constructs the stack. The app
otherwise remains in production mode.
Native bridge
Pages may capability-check window.caspianNative:
const native = window.caspianNative;
if (native?.has("open-external")) {
await native.invoke("open_external", { url: "https://example.com" });
}
The bridge allowlist is intentionally short: platform, application version, application data directory, external HTTP/HTTPS/mail links, and a user-driven file picker. An XSS can reach every bridge command, so commands must remain safe even when the calling page is compromised.
Current limitations
- The first embedded-backend implementation uses PyInstaller and has only been designed for Windows packaging.
- Dynamic route discovery requires project Python sources and
settings/files-list.jsonto be bundled. - Secrets from
.envare never embedded. Remote database credentials and third-party credentials must be provisioned outside the package. - Android remote mode requires connectivity and a deployed Caspian server.
- Installer signing and Android store signing are not automated in
0.0.1.
Release files for caspian-native 0.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| caspian_native-0.0.3.tar.gz | 25.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| caspian_native-0.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:48.3 kB
Release files / caspian_native-0.0.3.tar.gz
| Download URL | caspian_native-0.0.3.tar.gz |
|---|---|
| Size | 25.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
467db9075265980becc64824bef62cb2f1bbeb750ddd0a9b8f4fe1eb70370897
|
|
BLAKE2b-256 checksum How to use checksums |
4e5e1bab01799246843b1a9f916f690177a0d501c18f686e07c49a3f6d08cfad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.6 {"installer":{"name":"uv","version":"0.11.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / caspian_native-0.0.3-py3-none-any.whl
| Download URL | caspian_native-0.0.3-py3-none-any.whl |
|---|---|
| Size | 23.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fc37d1a21daac295e4176407a8be1f05382dcf160f70c6462a9af31caed13557
|
|
BLAKE2b-256 checksum How to use checksums |
0c824623f688c7b57b64f971b6617ae1b360b26d386ed7533da560ce7215c61f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.6 {"installer":{"name":"uv","version":"0.11.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|