96 lines
2.8 KiB
Bash
Executable File
96 lines
2.8 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
cd "$(dirname "$0")/../.."
|
|
|
|
nginx_config=docker/nginx.conf.template
|
|
for setting in \
|
|
'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \
|
|
'proxy_http_version 1.1;' \
|
|
'proxy_set_header Host $http_host;' \
|
|
'proxy_buffering off;' \
|
|
'proxy_read_timeout 3600s;'; do
|
|
if ! grep -Fq "$setting" "$nginx_config"; then
|
|
echo "missing required nginx API/SSE setting: $setting" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
for location in \
|
|
'location = /index.html {' \
|
|
'location = /config.js {'; do
|
|
if ! grep -Fq "$location" "$nginx_config"; then
|
|
echo "missing exact frontend cache location: $location" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
if ! grep -Fq 'location ~* \.(js|css)$ {' "$nginx_config"; then
|
|
echo "missing frontend JS/CSS asset cache location" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$(grep -Fc 'add_header Cache-Control "no-store, no-cache, must-revalidate" always;' "$nginx_config")" -lt 2 ]; then
|
|
echo "frontend index/config locations must disable caching" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! grep -Fq 'add_header Cache-Control "public, max-age=31536000, immutable" always;' "$nginx_config"; then
|
|
echo "frontend JS/CSS assets must use immutable long-lived caching" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$(grep -Fc 'try_files $uri =404;' "$nginx_config")" -lt 2 ]; then
|
|
echo "frontend config/assets must fail with 404 instead of falling back to the SPA" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! grep -Fqx 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}' \
|
|
docker/frontend-entrypoint.sh; then
|
|
echo "frontend entrypoint is missing the private core default" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! grep -Fq "envsubst '\${THT_FRONTEND_API_UPSTREAM}'" docker/frontend-entrypoint.sh; then
|
|
echo "frontend entrypoint does not render the private upstream" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docker/nginx.conf.template; then
|
|
echo "frontend runtime routing still accepts a browser-facing backend URL" >&2
|
|
exit 1
|
|
fi
|
|
|
|
upstream_validator=docker/validate-frontend-api-upstream.sh
|
|
for upstream in http://core:8787; do
|
|
if ! "$upstream_validator" "$upstream"; then
|
|
echo "frontend upstream validator rejected $upstream" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
if grep -Fq 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM%/}' docker/frontend-entrypoint.sh; then
|
|
echo "frontend entrypoint must not normalize an upstream path component" >&2
|
|
exit 1
|
|
fi
|
|
|
|
for upstream in \
|
|
https://core:8787 \
|
|
http://core:8080 \
|
|
http://core:8787/ \
|
|
http://core:8787// \
|
|
http://core:8787/// \
|
|
http://core:8787/api \
|
|
http://user:pass@core:8787 \
|
|
'http://core:8787?next=evil' \
|
|
'http://core:8787#fragment' \
|
|
'http://core:8787 injected' \
|
|
'http://core:8787;proxy_pass http://evil'; do
|
|
if "$upstream_validator" "$upstream" >/dev/null 2>&1; then
|
|
echo "frontend upstream validator accepted unsafe upstream: $upstream" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
echo "frontend same-origin proxy policy: ok"
|