#!/bin/sh set -eu cd "$(dirname "$0")/../.." nginx_config=docker/nginx.conf.template for setting in \ 'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \ 'proxy_http_version 1.1;' \ 'proxy_buffering off;' \ 'proxy_read_timeout 3600s;'; do if ! grep -Fq "$setting" "$nginx_config"; then echo "missing required nginx API/SSE setting: $setting" >&2 exit 1 fi done if ! grep -Fqx 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}' \ docker/frontend-entrypoint.sh; then echo "frontend entrypoint is missing the private core default" >&2 exit 1 fi if ! grep -Fq "envsubst '\${THT_FRONTEND_API_UPSTREAM}'" docker/frontend-entrypoint.sh; then echo "frontend entrypoint does not render the private upstream" >&2 exit 1 fi if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docker/nginx.conf.template; then echo "frontend runtime routing still accepts a browser-facing backend URL" >&2 exit 1 fi upstream_validator=docker/validate-frontend-api-upstream.sh for upstream in http://core:8787 http://core:8787/; do if ! "$upstream_validator" "$upstream"; then echo "frontend upstream validator rejected $upstream" >&2 exit 1 fi done for upstream in \ https://core:8787 \ http://core:8080 \ http://core:8787/api \ http://user:pass@core:8787 \ 'http://core:8787?next=evil' \ 'http://core:8787#fragment' \ 'http://core:8787 injected' \ 'http://core:8787;proxy_pass http://evil'; do if "$upstream_validator" "$upstream" >/dev/null 2>&1; then echo "frontend upstream validator accepted unsafe upstream: $upstream" >&2 exit 1 fi done echo "frontend same-origin proxy policy: ok"