#!/usr/bin/env sh
#
# DDIPE CLI installer.
#
#   curl -fsSL https://get.reysecurity.ai | sh
#
# Downloads the standalone `ddipe` binary for this OS/arch, verifies its
# checksum, and installs it onto your PATH. No Python required.
#
# Env overrides:
#   DDIPE_INSTALL_BASE   base URL (default: https://get.reysecurity.ai)
#   DDIPE_CHANNEL        latest | a version like v0.5.0 (default: latest)
#   DDIPE_BIN_DIR        install dir (default: /usr/local/bin, else ~/.local/bin)
#
set -eu

BASE="${DDIPE_INSTALL_BASE:-https://d10ijtp0dio7mb.cloudfront.net}"
CHANNEL="${DDIPE_CHANNEL:-latest}"
BIN_DIR="${DDIPE_BIN_DIR:-/usr/local/bin}"
LICENSE=""

# Accept the license inline so a gated install is one command, not two:
#   curl -fsSL https://get.reysecurity.ai | sh -s -- --license=<token>
for arg in "$@"; do
  case "$arg" in
    --license=*) LICENSE="${arg#--license=}" ;;
    *) echo "ddipe: unknown option: $arg" >&2; exit 2 ;;
  esac
done

os="$(uname -s | tr '[:upper:]' '[:lower:]')"
arch="$(uname -m)"
case "$arch" in
  x86_64 | amd64) arch="x64" ;;
  arm64 | aarch64) arch="arm64" ;;
  *) echo "ddipe: unsupported architecture: $arch" >&2; exit 1 ;;
esac
case "$os" in
  darwin | linux) ;;
  *) echo "ddipe: unsupported OS: $os (macOS and Linux only)" >&2; exit 1 ;;
esac

target="ddipe-${os}-${arch}"
url="${BASE}/ddipe/${CHANNEL}/${target}"

tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT

# Intel macOS is not currently built (see build-cli.yml). Saying so beats a 404
# on the binary, which reads like an outage rather than an unsupported platform.
if [ "$target" = "ddipe-darwin-x64" ]; then
  echo "ddipe: Intel macOS is not currently supported." >&2
  echo "       Apple Silicon and Linux x64 are. Contact Rey Security if you need this." >&2
  exit 1
fi

echo "ddipe: downloading ${target} (${CHANNEL})…"
curl -fsSL "$url" -o "$tmp/ddipe"

# Verify the checksum — REQUIRED (fail closed). The published .sha256 is the only
# client-side integrity control on the curl|sh path, so a missing, unreachable, or
# mismatching checksum aborts the install rather than running an unverified binary.
if ! curl -fsSL "${url}.sha256" -o "$tmp/ddipe.sha256"; then
  echo "ddipe: could not fetch ${target}.sha256 — aborting (integrity cannot be verified)." >&2
  exit 1
fi
expected="$(awk '{print $1}' "$tmp/ddipe.sha256")"
if command -v sha256sum >/dev/null 2>&1; then
  actual="$(sha256sum "$tmp/ddipe" | awk '{print $1}')"
else
  actual="$(shasum -a 256 "$tmp/ddipe" | awk '{print $1}')"
fi
if [ -z "$expected" ] || [ "$expected" != "$actual" ]; then
  echo "ddipe: checksum verification failed — aborting." >&2
  exit 1
fi
echo "ddipe: checksum verified."

chmod +x "$tmp/ddipe"
# We do NOT strip com.apple.quarantine: that would defeat Gatekeeper on an
# as-yet-unsigned binary. The proper fix is codesigning + notarization (planned).

# Install, falling back to a user-writable dir when BIN_DIR needs root.
if mkdir -p "$BIN_DIR" 2>/dev/null && [ -w "$BIN_DIR" ]; then
  dest="$BIN_DIR"
else
  dest="$HOME/.local/bin"
  mkdir -p "$dest"
fi
mv "$tmp/ddipe" "$dest/ddipe"

echo ""
echo "  ✓ ddipe installed to $dest/ddipe"
case ":$PATH:" in
  *":$dest:"*) ;;
  *) echo "  → add it to your PATH:  export PATH=\"$dest:\$PATH\"" ;;
esac

# The binary is free to download and does nothing without a license. That is the
# protection: not who holds the bytes, but who holds a token.
if [ -n "$LICENSE" ]; then
  if "$dest/ddipe" activate "$LICENSE" >/dev/null 2>&1; then
    echo "  ✓ license activated"
  else
    echo "" >&2
    echo "  ddipe: license activation failed — installed but not usable." >&2
    echo "  retry with:  ddipe activate <your-license-key>" >&2
    exit 1
  fi
else
  echo "  → next: ddipe activate <your-license-key>"
fi

# Installing the binary protects nothing on its own. Saying so here is the
# difference between a customer who is covered and one who believes they are.
echo ""
echo "  then install the runtime gate into your agent:"
echo "      ddipe moat-install --platform codex  --scope user --apply"
echo "      ddipe moat-install --platform claude --scope user --apply"
echo ""
echo "  on Codex, hooks do not run until you approve them in the agent. the"
echo "  installer reports whether MOAT is active or still awaiting approval."
echo ""
