diff --git a/bin/server.dart b/bin/server.dart index b7061fd..83dbef5 100644 --- a/bin/server.dart +++ b/bin/server.dart @@ -108,57 +108,9 @@ void main(List args) async { const Pipeline() .addMiddleware(authMiddleware(db)) .addHandler(settingsHandler.router.call), - ) - // Xtream Proxy (SECURED) - ..mount( - '/api/xtream', // Mounting at /api/xtream means handler sees /http://... - const Pipeline() - .addMiddleware(authMiddleware(db)) - .addHandler((request) { - // Router mount strips the prefix, but ProxyHandler expects /api/xtream prefix? - // Wait, shelf_router mount usually strips the prefix for the inner handler. - // If I mount at '/api/xtream', the inner handler receives requests relative to that. - // My ProxyHandler implementation checks: if (!path.startsWith('api/xtream/')) - // If I mount it, shelf strips it. - // Let's adjust usage. - // Actually, `mount` does strip. - // Option 1: Fix ProxyHandler to not care about prefix. - // Option 2: Use `all` route in main router instead of strict sub-router if I want full path. - // Let's modify the Pipeline here to just pass it to a handler that expects the full path? - // No, shelf_router `mount` is specific. - - // BETTER APPROACH: - // ProxyHandler expects `/api/xtream/...`. - // If we mount at `/api/xtream`, the request passed to handler will have `path` starting with `/`. - // e.g. `/http://server...` - // Modifying ProxyHandler is cleaner, but I already wrote it. - // Let's WRAP it here to prepend? No that's hacky. - - // Let's use `router.all('/api/xtream/', ...)` instead of `mount` if we want to keep full path? - // Or just rely on the fact that I can change the handler logic easily? - // I'll stick to `mount` and `ProxyHandler` needs check. - // Actually, let's look at `server.dart` original `_createXtreamProxyHandler`. - // It was manually checking `path.startsWith('api/xtream/')`. - // If I use `mount`, I should probably adjust the handler. - - // For now, I'll instantiate ProxyHandler and let it handle the request, - // BUT I will modify how I add it to the router to ensure it works. - // The cleanest is to use `apiRouter.all('/api/xtream/', ...)` - // verifying authentication, then passing to ProxyHandler. - // BUT ProxyHandler checks `api/xtream` prefix. - - // Let's simply add it to the Cascade as before but WITH middleware wrapped manually? - // No, `authMiddleware` expects to be in a pipeline. - - // I will go with: Add to `apiRouter` using `mount`, - // AND I will patch `ProxyHandler` in the next step to be flexible or - // I will use a simple wrapper here that reconstructs what ProxyHandler expects? - // No, simpler: Update `server.dart` to NOT mount it inside `apiRouter` but - // add it to the `Cascade` BUT wrapped in a Pipeline with Auth. - // That preserves the path structure `ProxyHandler` expects (`/api/xtream/...`). - return Response.notFound('Should not be reached if using Cascade'); - }), ); + // NOTE: /api/xtream is handled by proxyHandler in the Cascade below + // Do NOT mount here as it would intercept and block the actual proxy // Initialize Cleanup Service final cleanupService = CleanupService(); diff --git a/task.md b/task.md index 9638b9e..ed9293b 100644 --- a/task.md +++ b/task.md @@ -1,23 +1,21 @@ -# Fix Docker Database Permissions +# Fix Docker Database & Proxy Issues ## Context -SQLite database in Docker container is read-only due to volume permissions mismatch between root and xtremuser. - -## Current Focus - -Implementation complete - ready for rebuild and deploy. +1. SQLite database read-only error on login (permissions) +2. Xtream proxy 401 Unauthorized errors ## Master Plan -- [x] Analyze the error and identify root cause -- [x] Create entrypoint.sh script to fix permissions at startup -- [x] Update Dockerfile to use entrypoint script with gosu -- [ ] Rebuild and deploy to test +- [x] Analyze database readonly error → volume permissions mismatch +- [x] Create `entrypoint.sh` with gosu for privilege drop +- [x] Update `Dockerfile` to use entrypoint +- [x] Analyze proxy 401 errors → broken mount in apiRouter +- [x] Remove duplicate `/api/xtream` mount from `server.dart` +- [ ] Rebuild and deploy -## Progress Log +## Changes Made -- Identified `SqliteException(8): attempt to write a readonly database` error -- Root cause: Docker volume created with different permissions than xtremuser -- Created `entrypoint.sh` with chown fix and gosu privilege drop -- Updated Dockerfile: added gosu, ENTRYPOINT, removed USER directive +- `entrypoint.sh`: Fixes /app/data permissions at startup, then runs as xtremuser +- `Dockerfile`: Added gosu, ENTRYPOINT, removed USER directive +- `server.dart`: Removed broken /api/xtream mount that was blocking proxy