mirror of
https://github.com/R0m1k3/PleinR.git
synced 2026-10-11 17:27:54 +02:00
La redirection vers /login utilisait http://localhost:8413 (ancienne valeur par défaut d'AUTH_URL). On retire ce défaut localhost : AUTH_URL prend la valeur fournie (ex. https://pleinr.ffnancy.fr) et pilote la redirection. Ajout de AUTH_TRUST_HOST=true (confiance aux en-têtes X-Forwarded-*) et l'entrypoint supprime AUTH_URL si vide. Vérifié : la redirection pointe vers le domaine public. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XwfhYHzC9hQWPDnQ2p53GL
35 lines
1.1 KiB
Bash
35 lines
1.1 KiB
Bash
#!/bin/sh
|
|
set -e
|
|
|
|
# Ensure an AUTH_SECRET exists. If none is provided, generate one and persist it
|
|
# to the app-data volume so sessions stay valid across restarts.
|
|
if [ -z "$AUTH_SECRET" ]; then
|
|
SECRET_FILE=/app/data/auth_secret
|
|
if [ -f "$SECRET_FILE" ]; then
|
|
AUTH_SECRET=$(cat "$SECRET_FILE")
|
|
else
|
|
AUTH_SECRET=$(node -e "console.log(require('crypto').randomBytes(32).toString('base64'))")
|
|
mkdir -p /app/data
|
|
printf '%s' "$AUTH_SECRET" > "$SECRET_FILE"
|
|
echo "→ AUTH_SECRET généré et persisté dans $SECRET_FILE"
|
|
fi
|
|
export AUTH_SECRET
|
|
fi
|
|
|
|
# If AUTH_URL is empty, unset it so Auth.js derives the public URL from the
|
|
# reverse-proxy headers (trustHost) instead of falling back to a hardcoded host.
|
|
if [ -z "$AUTH_URL" ]; then
|
|
unset AUTH_URL
|
|
fi
|
|
|
|
echo "→ Applying database migrations…"
|
|
node dist/migrate.cjs
|
|
|
|
if [ "$SEED_ON_START" = "true" ]; then
|
|
echo "→ Seeding database (SEED_ON_START=true)…"
|
|
node dist/seed.cjs || echo " seed step reported an issue, continuing"
|
|
fi
|
|
|
|
echo "→ Starting Plein R on port ${PORT:-3000}…"
|
|
exec node server.js
|