fix(deploy): unify backend URL policy
This commit is contained in:
@@ -2,19 +2,10 @@
|
||||
set -eu
|
||||
|
||||
backend_base_url=${BACKEND_BASE_URL-/api}
|
||||
case "$backend_base_url" in
|
||||
""|/|/api|/api/) ;;
|
||||
http://*|https://*)
|
||||
if printf '%s' "$backend_base_url" | grep -Eq '[[:space:]]|^https?://[^/]*@'; then
|
||||
echo "Invalid BACKEND_BASE_URL: credentials and whitespace are not allowed" >&2
|
||||
exit 2
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo "Invalid BACKEND_BASE_URL: use empty/root, /api, or an absolute http(s) URL" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
if ! /usr/local/bin/validate-backend-url "$backend_base_url"; then
|
||||
echo "Invalid BACKEND_BASE_URL: use empty/root, /api, or a valid http(s) base without credentials, query, or fragment" >&2
|
||||
exit 2
|
||||
fi
|
||||
runtime_config=$(jq -cn --arg backend_base_url "$backend_base_url" \
|
||||
'{backendBaseUrl: $backend_base_url}')
|
||||
printf 'window.__THOTHII_CONFIG__ = %s;\n' "$runtime_config" \
|
||||
|
||||
@@ -12,8 +12,13 @@ RUN apk add --no-cache jq
|
||||
COPY --from=build /src/frontend/dist /usr/share/nginx/html
|
||||
COPY docker/nginx.conf.template /etc/nginx/conf.d/default.conf
|
||||
COPY docker/frontend-entrypoint.sh /usr/local/bin/frontend-entrypoint
|
||||
COPY docker/validate-backend-url.sh /usr/local/bin/validate-backend-url
|
||||
COPY docker/smoke/frontend-smoke.sh /usr/local/bin/frontend-config-smoke
|
||||
RUN chmod 0555 /usr/local/bin/frontend-entrypoint /usr/local/bin/frontend-config-smoke \
|
||||
COPY docker/smoke/frontend-policy-smoke.sh /usr/local/bin/frontend-policy-smoke
|
||||
COPY frontend/src/api/backend-url-policy.json /etc/thothii/backend-url-policy.json
|
||||
COPY frontend/src/api/backend-url-cases.json /etc/thothii/backend-url-cases.json
|
||||
RUN chmod 0555 /usr/local/bin/frontend-entrypoint /usr/local/bin/validate-backend-url \
|
||||
/usr/local/bin/frontend-config-smoke /usr/local/bin/frontend-policy-smoke \
|
||||
&& chown -R 101:101 /usr/share/nginx/html
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
corpus=/etc/thothii/backend-url-cases.json
|
||||
|
||||
jq -c '.[]' "$corpus" | while IFS= read -r case_json; do
|
||||
value=$(printf '%s' "$case_json" | jq -r '.value')
|
||||
valid=$(printf '%s' "$case_json" | jq -r '.valid')
|
||||
if BACKEND_BASE_URL="$value" /usr/local/bin/frontend-entrypoint true \
|
||||
>/dev/null 2>&1; then
|
||||
actual=true
|
||||
else
|
||||
actual=false
|
||||
fi
|
||||
if [ "$actual" != "$valid" ]; then
|
||||
echo "entrypoint policy mismatch for BACKEND_BASE_URL=$value: expected $valid" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
echo "frontend entrypoint canonical URL corpus: ok"
|
||||
Executable
+30
@@ -0,0 +1,30 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
value=${1-}
|
||||
policy_file=${BACKEND_URL_POLICY_FILE:-/etc/thothii/backend-url-policy.json}
|
||||
|
||||
if jq -e --arg value "$value" '.relativeBases | index($value) != null' \
|
||||
"$policy_file" >/dev/null; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if ! jq -e --arg value "$value" \
|
||||
'.absolutePattern as $pattern | $value | test($pattern)' \
|
||||
"$policy_file" >/dev/null; then
|
||||
exit 2
|
||||
fi
|
||||
|
||||
authority=${value#*://}
|
||||
authority=${authority%%/*}
|
||||
port=""
|
||||
case "$authority" in
|
||||
*]:*) port=${authority##*:} ;;
|
||||
*]) ;;
|
||||
*:*) port=${authority##*:} ;;
|
||||
esac
|
||||
|
||||
if [ -n "$port" ]; then
|
||||
max_port=$(jq -r '.maxPort' "$policy_file")
|
||||
if [ "${#port}" -gt 5 ] || [ "$port" -gt "$max_port" ]; then exit 2; fi
|
||||
fi
|
||||
Reference in New Issue
Block a user