Build image / build (push) Successful in 3m18s
- Dockerfile bakes the app and every CSV in data/ into an nginx image - UI discovers data/*.csv via nginx JSON autoindex and offers a dropdown when there is more than one dataset - docker-entrypoint.d/40-basic-auth.sh creates .htpasswd from BASIC_AUTH_USER / BASIC_AUTH_PASSWORD(_FILE) and refuses to start without credentials; replaces set-password.sh - Gitea Actions workflow builds and pushes registry.traberph.de/public/interval_viz (latest, sha-*, semver) - Escape resets the chart zoom Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
36 lines
1.5 KiB
Bash
Executable File
36 lines
1.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# Creates the basic-auth file for nginx from environment variables.
|
|
#
|
|
# BASIC_AUTH_USER user name
|
|
# BASIC_AUTH_PASSWORD password, or
|
|
# BASIC_AUTH_PASSWORD_FILE path to a file containing the password (e.g. a mounted secret)
|
|
#
|
|
# Without these variables an already mounted /etc/nginx/.htpasswd is used.
|
|
# If neither exists the container refuses to start, so the app is never served unprotected.
|
|
set -eu
|
|
|
|
HTPASSWD=/etc/nginx/.htpasswd
|
|
ME=$(basename "$0")
|
|
|
|
if [ -n "${BASIC_AUTH_PASSWORD_FILE:-}" ]; then
|
|
[ -r "$BASIC_AUTH_PASSWORD_FILE" ] || { echo "$ME: cannot read $BASIC_AUTH_PASSWORD_FILE" >&2; exit 1; }
|
|
BASIC_AUTH_PASSWORD=$(cat "$BASIC_AUTH_PASSWORD_FILE")
|
|
fi
|
|
|
|
if [ -n "${BASIC_AUTH_USER:-}" ] || [ -n "${BASIC_AUTH_PASSWORD:-}" ]; then
|
|
: "${BASIC_AUTH_USER:?$ME: BASIC_AUTH_USER is not set}"
|
|
: "${BASIC_AUTH_PASSWORD:?$ME: BASIC_AUTH_PASSWORD is empty}"
|
|
case "$BASIC_AUTH_USER" in *:*) echo "$ME: BASIC_AUTH_USER must not contain ':'" >&2; exit 1 ;; esac
|
|
|
|
# SHA-512 crypt; password is passed on stdin so it never shows up in the process list
|
|
hash=$(printf '%s' "$BASIC_AUTH_PASSWORD" | mkpasswd -m sha512 -P 0)
|
|
printf '%s:%s\n' "$BASIC_AUTH_USER" "$hash" > "$HTPASSWD"
|
|
chmod 644 "$HTPASSWD"
|
|
echo "$ME: basic auth configured for user '$BASIC_AUTH_USER'"
|
|
elif [ -s "$HTPASSWD" ]; then
|
|
echo "$ME: using existing $HTPASSWD"
|
|
else
|
|
echo "$ME: no credentials - set BASIC_AUTH_USER and BASIC_AUTH_PASSWORD (or mount $HTPASSWD)" >&2
|
|
exit 1
|
|
fi
|