Files
ThothII/docker/smoke/frontend-policy-smoke.sh
T

35 lines
1015 B
Bash
Executable File

#!/bin/sh
set -eu
cd "$(dirname "$0")/../.."
nginx_config=docker/nginx.conf.template
for setting in \
'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \
'proxy_http_version 1.1;' \
'proxy_buffering off;' \
'proxy_read_timeout 3600s;'; do
if ! grep -Fq "$setting" "$nginx_config"; then
echo "missing required nginx API/SSE setting: $setting" >&2
exit 1
fi
done
if ! grep -Fqx 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}' \
docker/frontend-entrypoint.sh; then
echo "frontend entrypoint is missing the private core default" >&2
exit 1
fi
if ! grep -Fq "envsubst '\${THT_FRONTEND_API_UPSTREAM}'" docker/frontend-entrypoint.sh; then
echo "frontend entrypoint does not render the private upstream" >&2
exit 1
fi
if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docker/nginx.conf.template; then
echo "frontend runtime routing still accepts a browser-facing backend URL" >&2
exit 1
fi
echo "frontend same-origin proxy policy: ok"