#!/bin/sh set -e APP_DIR=/var/www/html/wms-app CONFIG=$APP_DIR/app/config.php # Email OTP on sign-in, OFF BY DEFAULT. Only the exact string "true" turns it # on; a missing variable or anything else means false. : "${OTP_REQUIRED:=false}" [ "$OTP_REQUIRED" = "true" ] || OTP_REQUIRED=false export OTP_REQUIRED # An empty EMIT_SECRET would let anyone call Node's /emit and the PHP cron # endpoints, so refuse to start without one. if [ -z "$EMIT_SECRET" ]; then echo "[entrypoint] ERROR: EMIT_SECRET is empty. Set it in .env (docker/init-env.sh generates one)." >&2 exit 1 fi if [ -z "$APP_SECRET_KEY" ]; then echo "[entrypoint] WARNING: APP_SECRET_KEY is not set; SMTP passwords stay in the legacy fixed-key format." fi # The app connects as a least-privilege account (see provision.php). Without # DB_APP_PASSWORD it keeps connecting as root, as before. : "${DB_APP_USER:=wms_app}" if [ -z "$DB_APP_PASSWORD" ]; then echo "[entrypoint] WARNING: DB_APP_PASSWORD is not set; the app connects as root. Re-run docker/init-env.sh to add it." DB_APP_USER=root DB_APP_PASSWORD=$DB_ROOT_PASSWORD fi export DB_APP_USER DB_APP_PASSWORD APP_SECRET_KEY CONFIG # Generate app/config.php from template on first run only. # Restrict envsubst to known placeholders so it never touches the app's own # $variable syntax (envsubst blanks out any $NAME it doesn't recognize). if [ ! -f "$CONFIG" ]; then echo "[entrypoint] generating app/config.php" envsubst '${DB_APP_USER} ${DB_APP_PASSWORD} ${PUBLIC_HOST} ${EMIT_SECRET} ${SMTP_USERNAME} ${SMTP_PASSWORD} ${OTP_REQUIRED} ${APP_SECRET_KEY}' \ < /usr/local/etc/wms/config.php.template > "$CONFIG" fi # config.php is never regenerated once it exists, so OTP_REQUIRED is the one # line reconciled on every start: the .env value always wins, and a config.php # written before this switch existed gets the line added. if grep -q "define('OTP_REQUIRED'" "$CONFIG"; then if ! grep -q "define('OTP_REQUIRED', ${OTP_REQUIRED});" "$CONFIG"; then sed -i "s/define('OTP_REQUIRED', [A-Za-z]*);/define('OTP_REQUIRED', ${OTP_REQUIRED});/" "$CONFIG" echo "[entrypoint] OTP_REQUIRED is now ${OTP_REQUIRED}" fi else # Drop a closing ?> on the last line so the appended block stays inside PHP. sed -i -e '${/^[[:space:]]*?>[[:space:]]*$/d}' "$CONFIG" printf "\nif (!defined('OTP_REQUIRED')) {\n\tdefine('OTP_REQUIRED', %s);\n}\n" "$OTP_REQUIRED" >> "$CONFIG" echo "[entrypoint] added OTP_REQUIRED = ${OTP_REQUIRED} to an existing config.php" fi if [ "$OTP_REQUIRED" = "false" ]; then echo "[entrypoint] email OTP is off (OTP_REQUIRED=false); sign-in is password only." fi mkdir -p "$APP_DIR/app/uploads" chown -R www-data:www-data "$APP_DIR/app/uploads" echo "[entrypoint] waiting for database at db:3306" until mysqladmin ping -h db -u root -p"$DB_ROOT_PASSWORD" --silent 2>/dev/null; do sleep 2 done php /usr/local/etc/wms/provision.php # setup.php creates databases and tables, so it runs as root, not the app account. echo "[entrypoint] running setup.php (idempotent schema sync)" DB_SETUP_USER=root DB_SETUP_PASSWORD="$DB_ROOT_PASSWORD" php "$APP_DIR/setup.php" || true exec "$@"