security upgrade #17

Merged
fauno merged 6 commits from upgrade into main 2025-04-23 19:46:19 +00:00
4 changed files with 8 additions and 6 deletions

View File

@ -1,2 +1,2 @@
export ENTRYPOINT_CONF_VERSION=v11 export ENTRYPOINT_CONF_VERSION=v12
export PG_BACKUP_VERSION=v1 export PG_BACKUP_VERSION=v1

View File

@ -2,7 +2,7 @@ version: "3.8"
services: services:
app: app:
environment: environment:
- POSTGRES_ENABLED=1 - CMD_DB_TYPE=postgres
- CMD_DB_NAME=codimd - CMD_DB_NAME=codimd
- CMD_DB_USER=codimd - CMD_DB_USER=codimd
- CMD_DB_HOST=db - CMD_DB_HOST=db

View File

@ -1,7 +1,7 @@
version: "3.8" version: "3.8"
services: services:
app: app:
image: quay.io/hedgedoc/hedgedoc:1.10.1 image: quay.io/hedgedoc/hedgedoc:1.10.3
environment: environment:
- CMD_USECDN=false - CMD_USECDN=false
- CMD_URL_ADDPORT=false - CMD_URL_ADDPORT=false

View File

@ -22,7 +22,9 @@ file_env() {
} }
load_vars() { load_vars() {
if [ -n "${CMD_DB_PASSWORD_FILE:-""}" ] ; then
file_env "CMD_DB_PASSWORD" file_env "CMD_DB_PASSWORD"
fi
file_env "CMD_OAUTH2_CLIENT_SECRET" file_env "CMD_OAUTH2_CLIENT_SECRET"
file_env "CMD_SESSION_SECRET" file_env "CMD_SESSION_SECRET"
} }
@ -40,8 +42,8 @@ main() {
main main
if [ -n "$POSTGRES_ENABLED" ]; then if [ -n "${CMD_DB_PASSWORD_FILE:-""}" ] ; then
export CMD_DB_URL="postgres://$CMD_DB_USER:$CMD_DB_PASSWORD@$CMD_DB_HOST:5432/$CMD_DB_NAME" export CMD_DB_URL="${CMD_DB_TYPE}://$CMD_DB_USER:$CMD_DB_PASSWORD@$CMD_DB_HOST:5432/$CMD_DB_NAME"
fi fi
# 3wc: `source /docker-entrypoint.sh -e` to load CMD_DB_URL for CLI scripts # 3wc: `source /docker-entrypoint.sh -e` to load CMD_DB_URL for CLI scripts