deploy: route frontend and core through one origin
This commit is contained in:
@@ -1,21 +1,34 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
corpus=/etc/thothii/backend-url-cases.json
|
||||
cd "$(dirname "$0")/../.."
|
||||
|
||||
jq -c '.[]' "$corpus" | while IFS= read -r case_json; do
|
||||
value=$(printf '%s' "$case_json" | jq -r '.value')
|
||||
valid=$(printf '%s' "$case_json" | jq -r '.valid')
|
||||
if BACKEND_BASE_URL="$value" /usr/local/bin/frontend-entrypoint true \
|
||||
>/dev/null 2>&1; then
|
||||
actual=true
|
||||
else
|
||||
actual=false
|
||||
fi
|
||||
if [ "$actual" != "$valid" ]; then
|
||||
echo "entrypoint policy mismatch for BACKEND_BASE_URL=$value: expected $valid" >&2
|
||||
nginx_config=docker/nginx.conf.template
|
||||
for setting in \
|
||||
'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \
|
||||
'proxy_http_version 1.1;' \
|
||||
'proxy_buffering off;' \
|
||||
'proxy_read_timeout 3600s;'; do
|
||||
if ! grep -Fq "$setting" "$nginx_config"; then
|
||||
echo "missing required nginx API/SSE setting: $setting" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
echo "frontend entrypoint canonical URL corpus: ok"
|
||||
if ! grep -Fqx 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}' \
|
||||
docker/frontend-entrypoint.sh; then
|
||||
echo "frontend entrypoint is missing the private core default" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! grep -Fq "envsubst '\${THT_FRONTEND_API_UPSTREAM}'" docker/frontend-entrypoint.sh; then
|
||||
echo "frontend entrypoint does not render the private upstream" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docker/nginx.conf.template; then
|
||||
echo "frontend runtime routing still accepts a browser-facing backend URL" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "frontend same-origin proxy policy: ok"
|
||||
|
||||
Reference in New Issue
Block a user