From d3e8890100df619222541d3f88a18a031756e941 Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 11 Jul 2026 02:32:25 +0000 Subject: [PATCH] =?UTF-8?q?Corrige=20la=20connexion=20BDD=20:=20alias=20un?= =?UTF-8?q?ique=20sbc-db=20et=20variables=20PG=20discr=C3=A8tes?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sur le réseau partagé nginx_default, le nom « db » peut résoudre vers le PostgreSQL d'une autre stack : l'application se connectait au mauvais serveur (password authentication failed pour sbc_app alors que db-sync, lui, visait le bon). Reproduit et vérifié avec un conteneur leurre. - La base obtient l'alias réseau unique « sbc-db » ; l'app et db-sync s'y connectent via ce nom, jamais via « db » - DATABASE_URL remplacé par PGHOST/PGPORT/PGDATABASE/PGUSER/PGPASSWORD : insensible aux caractères spéciaux du mot de passe et aux ambiguïtés de résolution DNS Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o --- docker-compose.yml | 16 ++++++++++++++-- server/src/config.js | 8 +++++++- server/src/db.js | 2 +- 3 files changed, 22 insertions(+), 4 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index ce932ac..d9f4cf1 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -18,6 +18,12 @@ services: # Loopback only: reachable from the host machine (psql, backups), # never from the network. Remove this mapping to close it entirely. - "127.0.0.1:${DB_PORT:-58412}:5432" + networks: + default: + aliases: + # Unique hostname: "db" alone is ambiguous when other stacks on a + # shared network (nginx_default) also expose a "db" service. + - sbc-db healthcheck: test: ["CMD-SHELL", "pg_isready -U postgres -d sbc"] interval: 5s @@ -33,7 +39,7 @@ services: db: condition: service_healthy environment: - PGHOST: db + PGHOST: sbc-db PGUSER: postgres PGDATABASE: sbc PGPASSWORD: ${POSTGRES_PASSWORD:-sbc-pg-c7f3a91d284e6b05} @@ -48,7 +54,13 @@ services: environment: NODE_ENV: production PORT: "8321" - DATABASE_URL: postgres://sbc_app:${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605}@db:5432/sbc + # Discrete variables (no URL): immune to special characters in the + # password and to hostname ambiguity on shared networks + PGHOST: sbc-db + PGPORT: "5432" + PGDATABASE: sbc + PGUSER: sbc_app + PGPASSWORD: ${APP_DB_PASSWORD:-sbc-app-9e12d47ab8c3f605} # Empty by default: the app then generates a random ephemeral secret at # startup. Set a fixed value to keep sessions across restarts. JWT_SECRET: ${JWT_SECRET:-} diff --git a/server/src/config.js b/server/src/config.js index 787ef9e..69fdc15 100644 --- a/server/src/config.js +++ b/server/src/config.js @@ -23,7 +23,13 @@ if (jwtSecret.length < 32) { export const config = { port: Number(process.env.PORT || 8321), - databaseUrl: required('DATABASE_URL'), + db: { + host: process.env.PGHOST || 'localhost', + port: Number(process.env.PGPORT || 5432), + database: process.env.PGDATABASE || 'sbc', + user: process.env.PGUSER || 'sbc_app', + password: required('PGPASSWORD'), + }, jwtSecret, cookieSecure: process.env.COOKIE_SECURE === 'true', // set to "true" only when running behind a reverse proxy (TLS termination) diff --git a/server/src/db.js b/server/src/db.js index bfae3cc..0e0cd97 100644 --- a/server/src/db.js +++ b/server/src/db.js @@ -2,7 +2,7 @@ import pg from 'pg'; import { config } from './config.js'; export const pool = new pg.Pool({ - connectionString: config.databaseUrl, + ...config.db, max: 10, idleTimeoutMillis: 30_000, connectionTimeoutMillis: 5_000,