fix(docker): harden frontend runtime config

This commit is contained in:
2026-07-11 22:03:24 +02:00
parent 3d939426b1
commit 715de6649b
9 changed files with 75 additions and 11 deletions
+8 -3
View File
@@ -2,8 +2,13 @@
set -eu
backend_base_url=${BACKEND_BASE_URL:-/api}
escaped_backend_base_url=$(printf '%s' "$backend_base_url" | sed 's/[&|\\]/\\&/g')
sed "s|__BACKEND_BASE_URL__|${escaped_backend_base_url}|g" \
/usr/share/nginx/html/config.template.js > /usr/share/nginx/html/config.js
runtime_config=$(jq -cn --arg backend_base_url "$backend_base_url" \
'{backendBaseUrl: $backend_base_url}')
printf 'window.__THOTHII_CONFIG__ = %s;\n' "$runtime_config" \
> /usr/share/nginx/html/config.js
if [ "$#" -gt 0 ]; then
exec "$@"
fi
exec nginx -g 'daemon off;'
+3 -3
View File
@@ -8,12 +8,12 @@ RUN npm run build
FROM nginxinc/nginx-unprivileged:1.27-alpine
USER root
RUN apk add --no-cache jq
COPY --from=build /src/frontend/dist /usr/share/nginx/html
COPY docker/nginx.conf.template /etc/nginx/conf.d/default.conf
COPY docker/frontend-entrypoint.sh /usr/local/bin/frontend-entrypoint
RUN mv /usr/share/nginx/html/config.js /usr/share/nginx/html/config.template.js \
&& sed -i 's|{}|{ backendBaseUrl: "__BACKEND_BASE_URL__" }|' /usr/share/nginx/html/config.template.js \
&& chmod 0555 /usr/local/bin/frontend-entrypoint \
COPY docker/smoke/frontend-smoke.sh /usr/local/bin/frontend-config-smoke
RUN chmod 0555 /usr/local/bin/frontend-entrypoint /usr/local/bin/frontend-config-smoke \
&& chown -R 101:101 /usr/share/nginx/html
EXPOSE 8080
+14
View File
@@ -0,0 +1,14 @@
#!/bin/sh
set -eu
assignment=$(sed \
-e 's/^window\.__THOTHII_CONFIG__ = //' \
-e 's/;$//' \
/usr/share/nginx/html/config.js)
printf '%s\n' "$assignment" \
| jq -e --arg expected "${BACKEND_BASE_URL:-/api}" \
'type == "object" and keys == ["backendBaseUrl"] and .backendBaseUrl == $expected' \
>/dev/null
printf '%s\n' "frontend runtime config smoke: ok"