Files
Thanakorn ae98dcdcdd Harden web root, secrets and realtime auth
- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and
  app internals; security headers, HSTS over TLS, optional HTTPS redirect
- uploads served through app/file.php to signed-in users only
- Apache/PHP hardening config for the container (ServerTokens, expose_php)
- least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php;
  SMTP passwords re-encrypted with a random IV (secret_box.php)
- Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets
- escape notification text; CLI guards on build scripts; no fixed demo password
2026-09-24 14:53:40 +07:00

78 lines
2.1 KiB
Bash
Executable File

#!/bin/bash
# Interactively creates the root .env file used by docker-compose.yml.
# Run from the repo root: ./docker/init-env.sh
set -e
cd "$(dirname "$0")/.."
ENV_FILE=".env"
if [ -f "$ENV_FILE" ]; then
read -r -p "$ENV_FILE already exists — overwrite? [y/N] " confirm
case "$confirm" in
[yY]*) ;;
*) echo "Aborted."; exit 0 ;;
esac
fi
detected_ip=$(curl -s --max-time 3 ifconfig.me || true)
echo
echo "== Database =="
read -r -s -p "DB root password [leave blank to auto-generate]: " db_pass; echo
if [ -z "$db_pass" ]; then
db_pass=$(openssl rand -base64 24 | tr -d '/+=' | cut -c1-24)
echo " generated: $db_pass"
fi
echo
echo "== Server =="
read -r -p "Public IP or domain the browser uses to reach this server [${detected_ip:-required}]: " public_host
public_host=${public_host:-$detected_ip}
if [ -z "$public_host" ]; then
echo "PUBLIC_HOST is required." >&2
exit 1
fi
read -r -p "HTTP port to expose [80]: " http_port
http_port=${http_port:-80}
echo
echo "== PHP <-> Node shared secret =="
read -r -p "EMIT_SECRET [leave blank to auto-generate]: " emit_secret
if [ -z "$emit_secret" ]; then
emit_secret=$(openssl rand -hex 32)
echo " generated: $emit_secret"
fi
echo
echo "== App secrets (generated) =="
db_app_pass=$(openssl rand -hex 24)
app_secret=$(openssl rand -hex 32)
echo " DB_APP_PASSWORD and APP_SECRET_KEY generated (stored in $ENV_FILE only)."
read -r -p "Serve over HTTPS (redirect HTTP → HTTPS)? Only answer y once TLS is set up [y/N]: " force_https
case "$force_https" in [yY]*) force_https=true ;; *) force_https=false ;; esac
echo
echo "== SMTP (outgoing mail) =="
read -r -p "SMTP username (email address): " smtp_user
read -r -s -p "SMTP password (Gmail app password): " smtp_pass; echo
cat > "$ENV_FILE" <<EOF
DB_ROOT_PASSWORD=$db_pass
PUBLIC_HOST=$public_host
EMIT_SECRET=$emit_secret
SMTP_USERNAME=$smtp_user
SMTP_PASSWORD=$smtp_pass
OTP_REQUIRED=false
HTTP_PORT=$http_port
DB_APP_USER=wms_app
DB_APP_PASSWORD=$db_app_pass
APP_SECRET_KEY=$app_secret
FORCE_HTTPS=$force_https
EOF
chmod 600 "$ENV_FILE"
echo
echo "Wrote $ENV_FILE (permissions 600)."
echo "Next: docker compose up -d --build"