- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and app internals; security headers, HSTS over TLS, optional HTTPS redirect - uploads served through app/file.php to signed-in users only - Apache/PHP hardening config for the container (ServerTokens, expose_php) - least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php; SMTP passwords re-encrypted with a random IV (secret_box.php) - Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets - escape notification text; CLI guards on build scripts; no fixed demo password
78 lines
2.1 KiB
Bash
Executable File
78 lines
2.1 KiB
Bash
Executable File
#!/bin/bash
|
|
# Interactively creates the root .env file used by docker-compose.yml.
|
|
# Run from the repo root: ./docker/init-env.sh
|
|
set -e
|
|
|
|
cd "$(dirname "$0")/.."
|
|
ENV_FILE=".env"
|
|
|
|
if [ -f "$ENV_FILE" ]; then
|
|
read -r -p "$ENV_FILE already exists — overwrite? [y/N] " confirm
|
|
case "$confirm" in
|
|
[yY]*) ;;
|
|
*) echo "Aborted."; exit 0 ;;
|
|
esac
|
|
fi
|
|
|
|
detected_ip=$(curl -s --max-time 3 ifconfig.me || true)
|
|
|
|
echo
|
|
echo "== Database =="
|
|
read -r -s -p "DB root password [leave blank to auto-generate]: " db_pass; echo
|
|
if [ -z "$db_pass" ]; then
|
|
db_pass=$(openssl rand -base64 24 | tr -d '/+=' | cut -c1-24)
|
|
echo " generated: $db_pass"
|
|
fi
|
|
|
|
echo
|
|
echo "== Server =="
|
|
read -r -p "Public IP or domain the browser uses to reach this server [${detected_ip:-required}]: " public_host
|
|
public_host=${public_host:-$detected_ip}
|
|
if [ -z "$public_host" ]; then
|
|
echo "PUBLIC_HOST is required." >&2
|
|
exit 1
|
|
fi
|
|
|
|
read -r -p "HTTP port to expose [80]: " http_port
|
|
http_port=${http_port:-80}
|
|
|
|
echo
|
|
echo "== PHP <-> Node shared secret =="
|
|
read -r -p "EMIT_SECRET [leave blank to auto-generate]: " emit_secret
|
|
if [ -z "$emit_secret" ]; then
|
|
emit_secret=$(openssl rand -hex 32)
|
|
echo " generated: $emit_secret"
|
|
fi
|
|
|
|
echo
|
|
echo "== App secrets (generated) =="
|
|
db_app_pass=$(openssl rand -hex 24)
|
|
app_secret=$(openssl rand -hex 32)
|
|
echo " DB_APP_PASSWORD and APP_SECRET_KEY generated (stored in $ENV_FILE only)."
|
|
read -r -p "Serve over HTTPS (redirect HTTP → HTTPS)? Only answer y once TLS is set up [y/N]: " force_https
|
|
case "$force_https" in [yY]*) force_https=true ;; *) force_https=false ;; esac
|
|
|
|
echo
|
|
echo "== SMTP (outgoing mail) =="
|
|
read -r -p "SMTP username (email address): " smtp_user
|
|
read -r -s -p "SMTP password (Gmail app password): " smtp_pass; echo
|
|
|
|
cat > "$ENV_FILE" <<EOF
|
|
DB_ROOT_PASSWORD=$db_pass
|
|
PUBLIC_HOST=$public_host
|
|
EMIT_SECRET=$emit_secret
|
|
SMTP_USERNAME=$smtp_user
|
|
SMTP_PASSWORD=$smtp_pass
|
|
OTP_REQUIRED=false
|
|
HTTP_PORT=$http_port
|
|
DB_APP_USER=wms_app
|
|
DB_APP_PASSWORD=$db_app_pass
|
|
APP_SECRET_KEY=$app_secret
|
|
FORCE_HTTPS=$force_https
|
|
EOF
|
|
chmod 600 "$ENV_FILE"
|
|
|
|
echo
|
|
echo "Wrote $ENV_FILE (permissions 600)."
|
|
echo "Next: docker compose up -d --build"
|