Harden web root, secrets and realtime auth
- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and app internals; security headers, HSTS over TLS, optional HTTPS redirect - uploads served through app/file.php to signed-in users only - Apache/PHP hardening config for the container (ServerTokens, expose_php) - least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php; SMTP passwords re-encrypted with a random IV (secret_box.php) - Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets - escape notification text; CLI guards on build scripts; no fixed demo password
This commit is contained in:
@@ -10,12 +10,32 @@ CONFIG=$APP_DIR/app/config.php
|
||||
[ "$OTP_REQUIRED" = "true" ] || OTP_REQUIRED=false
|
||||
export OTP_REQUIRED
|
||||
|
||||
# An empty EMIT_SECRET would let anyone call Node's /emit and the PHP cron
|
||||
# endpoints, so refuse to start without one.
|
||||
if [ -z "$EMIT_SECRET" ]; then
|
||||
echo "[entrypoint] ERROR: EMIT_SECRET is empty. Set it in .env (docker/init-env.sh generates one)." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$APP_SECRET_KEY" ]; then
|
||||
echo "[entrypoint] WARNING: APP_SECRET_KEY is not set; SMTP passwords stay in the legacy fixed-key format."
|
||||
fi
|
||||
|
||||
# The app connects as a least-privilege account (see provision.php). Without
|
||||
# DB_APP_PASSWORD it keeps connecting as root, as before.
|
||||
: "${DB_APP_USER:=wms_app}"
|
||||
if [ -z "$DB_APP_PASSWORD" ]; then
|
||||
echo "[entrypoint] WARNING: DB_APP_PASSWORD is not set; the app connects as root. Re-run docker/init-env.sh to add it."
|
||||
DB_APP_USER=root
|
||||
DB_APP_PASSWORD=$DB_ROOT_PASSWORD
|
||||
fi
|
||||
export DB_APP_USER DB_APP_PASSWORD APP_SECRET_KEY CONFIG
|
||||
|
||||
# Generate app/config.php from template on first run only.
|
||||
# Restrict envsubst to known placeholders so it never touches the app's own
|
||||
# $variable syntax (envsubst blanks out any $NAME it doesn't recognize).
|
||||
if [ ! -f "$CONFIG" ]; then
|
||||
echo "[entrypoint] generating app/config.php"
|
||||
envsubst '${DB_ROOT_PASSWORD} ${PUBLIC_HOST} ${EMIT_SECRET} ${SMTP_USERNAME} ${SMTP_PASSWORD} ${OTP_REQUIRED}' \
|
||||
envsubst '${DB_APP_USER} ${DB_APP_PASSWORD} ${PUBLIC_HOST} ${EMIT_SECRET} ${SMTP_USERNAME} ${SMTP_PASSWORD} ${OTP_REQUIRED} ${APP_SECRET_KEY}' \
|
||||
< /usr/local/etc/wms/config.php.template > "$CONFIG"
|
||||
fi
|
||||
|
||||
@@ -45,7 +65,10 @@ until mysqladmin ping -h db -u root -p"$DB_ROOT_PASSWORD" --silent 2>/dev/null;
|
||||
sleep 2
|
||||
done
|
||||
|
||||
php /usr/local/etc/wms/provision.php
|
||||
|
||||
# setup.php creates databases and tables, so it runs as root, not the app account.
|
||||
echo "[entrypoint] running setup.php (idempotent schema sync)"
|
||||
php "$APP_DIR/setup.php" || true
|
||||
DB_SETUP_USER=root DB_SETUP_PASSWORD="$DB_ROOT_PASSWORD" php "$APP_DIR/setup.php" || true
|
||||
|
||||
exec "$@"
|
||||
|
||||
Reference in New Issue
Block a user