Metadata-Version: 2.5
Name: fahimtalking
Version: 0.1.3
Summary: Bootstrap installer/launcher for Fahim Talking. Downloads and verifies the real runtime on first run; ships no proprietary code, models, or heavy dependencies.
Project-URL: Homepage, https://huggingface.co/sallout/fahimtalkingfiles
Author: Tayseer
License: Proprietary
Requires-Python: >=3.10
Provides-Extra: dev
Requires-Dist: build>=1.2; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: twine>=5.0; extra == 'dev'
Description-Content-Type: text/markdown

# fahimtalking

Lightweight bootstrap/launcher for **Fahim Talking**, published by Tayseer.

```
py -3.12 -m pip install fahimtalking
```

This package is intentionally tiny: it contains no proprietary source code,
no models, and no heavy dependencies (no PyTorch, no CUDA libraries). It
only knows how to:

1. Securely store a Hugging Face read token (`fahimtalking auth`).
2. On first `fahimtalking run`, download the checksum-verified main and TTS
   runtime archives from
   [`sallout/fahimtalkingfiles`](https://huggingface.co/sallout/fahimtalkingfiles)
   using that token, atomically extract them, download any missing Hugging
   Face models into the standard user cache, and start the Admin and
   WebSocket services.
3. On every later run, validate the token and private-repository access,
   then reuse the already-verified runtimes and models without downloading
   them again.

## Commands

```
fahimtalking help
fahimtalking auth      Securely store your Hugging Face read token
fahimtalking doctor    Check this machine and report runtime status
fahimtalking ports      Show/change the Admin and WebSocket ports
fahimtalking run        Install missing runtimes/models, then run
fahimtalking stop       Stop the running services
```

## Where things live

All writable application data (downloaded runtimes, the encrypted token,
config, run-state) lives under:

```
C:\Users\<user>\AppData\Local\Tayseer\FahimTalking
```

Nothing is written to this package's own install location (site-packages);
uninstalling with `pip uninstall fahimtalking` never touches that data
directory - remove it by hand if you want a fully clean slate.

## Security notes

* The Hugging Face token is only ever stored encrypted at rest via the
  Windows Data Protection API (DPAPI), scoped to your Windows user account
  on this machine. It is never written to a config file, log, or the
  package itself, and never accepted as a command-line argument (so it
  never lands in shell history).
* The two runtime archives are downloaded from a *fixed* URL
  (`https://huggingface.co/sallout/fahimtalkingfiles/resolve/main`) baked
  into this package at release time, authenticated with your token via an
  `Authorization: Bearer` header, and verified against a bundled SHA-256
  manifest before anything is extracted.
* The proprietary application code inside the downloaded runtimes is
  compiled (not shipped as plain `.py`) - see this repository's
  `scripts/protect_source.ps1`. Obfuscation/compilation of *code* is not,
  and is never treated as, protection for the token above; that's what
  DPAPI is for.
* Release 0.1.3 validates both the Hugging Face identity and read access to
  the private publisher repository before every `run`. The same check is
  repeated inside the compiled runtime to prevent directly launching the
  managed interpreter as an easy bypass.
* This build expires at `2026-10-18T00:00:00+04:00`. The authorization
  response's HTTPS server time is used when available, so changing the local
  Windows clock does not extend the deadline.
* A definitive denial (missing/revoked token, lost repository access, or
  expiry) stops the services and removes only `runtime-main` and
  `runtime-tts`. Configuration, models, caches, logs, voices, and customer
  data are preserved. A timeout or temporary Hugging Face failure blocks
  startup but never removes files.

## For maintainers: building this package

See `../../scripts/build_pypi_wheel.ps1` in this repository and the
packaging runbook for the full release process (rebuilding the protected
runtime archives, publishing them to Hugging Face, syncing this package's
bundled manifest, building the wheel, and testing it in a clean virtual
environment).
