fix: standardize deployment data directory and CI linting
This commit is contained in:
1 parent
c2e138f823
commit
e42d1a5d80
4 files changed
+37
-28
No files matched your search
@@ -31,7 +31,7 @@ BASE_URL="${BASE_URL:-https://bzo.in}"
|
||||
|
||||
CONTAINER_NAME="${CONTAINER_NAME:-bzod}"
|
||||
|
||||
DATA_DIR="${BZOD_ROOT}/data"
|
||||
NX9_BZOD_DATA_DIR="${BZOD_ROOT}/data"
|
||||
CONFIG_DIR="${BZOD_ROOT}/config"
|
||||
IMAGES_DIR="${BZOD_ROOT}/images"
|
||||
COMPOSE_DIR="${BZOD_ROOT}/compose"
|
||||
@@ -89,7 +89,7 @@ echo
|
||||
echo "Version: ${BZOD_VERSION}"
|
||||
echo "Image: ${IMAGE}"
|
||||
echo "Application: ${BZOD_ROOT}"
|
||||
echo "Data: ${DATA_DIR}"
|
||||
echo "Data: ${NX9_BZOD_DATA_DIR}"
|
||||
echo "Config: ${CONFIG_DIR}"
|
||||
echo "Images: ${IMAGES_DIR}"
|
||||
echo "Port: ${BZOD_PORT}"
|
||||
@@ -154,7 +154,7 @@ success "✓ Docker and Docker Compose available"
|
||||
info "[2/8] Creating persistent application directories..."
|
||||
|
||||
mkdir -p \
|
||||
"${DATA_DIR}" \
|
||||
"${NX9_BZOD_DATA_DIR}" \
|
||||
"${CONFIG_DIR}" \
|
||||
"${IMAGES_DIR}" \
|
||||
"${COMPOSE_DIR}" \
|
||||
@@ -300,8 +300,8 @@ BACKUP_DIR="${BACKUP_ROOT}/pre-upgrade-${TIMESTAMP}-v${BZOD_VERSION}"
|
||||
|
||||
mkdir -p "${BACKUP_DIR}"
|
||||
|
||||
if [[ -d "${DATA_DIR}" ]]; then
|
||||
cp -a "${DATA_DIR}" "${BACKUP_DIR}/data"
|
||||
if [[ -d "${NX9_BZOD_DATA_DIR}" ]]; then
|
||||
cp -a "${NX9_BZOD_DATA_DIR}" "${BACKUP_DIR}/data"
|
||||
fi
|
||||
|
||||
if [[ -d "${CONFIG_DIR}" ]]; then
|
||||
@@ -451,7 +451,7 @@ echo " http://<server-ip>:${BZOD_PORT}"
|
||||
|
||||
echo
|
||||
echo "Persistent data:"
|
||||
echo " ${DATA_DIR}"
|
||||
echo " ${NX9_BZOD_DATA_DIR}"
|
||||
|
||||
echo
|
||||
echo "Persistent images:"
|
||||
|
||||
@@ -388,7 +388,6 @@ impl Db {
|
||||
#[cfg(test)]
|
||||
mod db_init_tests {
|
||||
use super::*;
|
||||
use std::path::PathBuf;
|
||||
|
||||
#[test]
|
||||
fn test_db_init() {
|
||||
|
||||
+23
-15
@@ -90,10 +90,10 @@ pub(crate) const MAX_JSON_EXPORT_ROWS: usize = 50_000;
|
||||
pub(crate) async fn require_auth(
|
||||
state: &AppState,
|
||||
jar: &CookieJar,
|
||||
) -> Result<(User, String), Response> {
|
||||
) -> Result<(User, String), Box<Response>> {
|
||||
let conn = match state.users_db.lock() {
|
||||
Ok(c) => c,
|
||||
Err(_) => return Err(Redirect::to("/admin/login").into_response()),
|
||||
Err(_) => return Err(Box::new(Redirect::to("/admin/login").into_response())),
|
||||
};
|
||||
|
||||
match authenticate_admin_session(&conn, jar) {
|
||||
@@ -102,16 +102,18 @@ pub(crate) async fn require_auth(
|
||||
// Check if user is logged in as a normal tenant user trying to access admin route
|
||||
if let Ok(Some((tenant_user, _))) = authenticate_user_session(&conn, jar) {
|
||||
if tenant_user.account_type != "admin" {
|
||||
return Err((
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Standard users cannot access Admin routes",
|
||||
)
|
||||
.into_response());
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
}
|
||||
Err(Redirect::to("/admin/login").into_response())
|
||||
Err(Box::new(Redirect::to("/admin/login").into_response()))
|
||||
}
|
||||
Err(_) => Err(Redirect::to("/admin/login").into_response()),
|
||||
Err(_) => Err(Box::new(Redirect::to("/admin/login").into_response())),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -119,41 +121,47 @@ pub(crate) async fn require_auth(
|
||||
pub(crate) async fn require_user_auth(
|
||||
state: &AppState,
|
||||
jar: &CookieJar,
|
||||
) -> Result<(crate::models::TenantUser, String), Response> {
|
||||
) -> Result<(crate::models::TenantUser, String), Box<Response>> {
|
||||
let conn = match state.users_db.lock() {
|
||||
Ok(c) => c,
|
||||
Err(_) => return Err(Redirect::to("/login").into_response()),
|
||||
Err(_) => return Err(Box::new(Redirect::to("/login").into_response())),
|
||||
};
|
||||
|
||||
// If an Admin session is present, Core Admin is trying to access /user/* routes -> Reject with 403 Forbidden
|
||||
if let Ok(Some((_admin_user, _))) = authenticate_admin_session(&conn, jar) {
|
||||
return Err((
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response());
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
// Now check tenant user session
|
||||
match authenticate_user_session(&conn, jar) {
|
||||
Ok(Some((user, session_id))) => {
|
||||
if user.account_type == "admin" {
|
||||
return Err((
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response());
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
if user.tenant_id.is_none() {
|
||||
return Err((
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: User has no assigned TenantId",
|
||||
)
|
||||
.into_response());
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
Ok((user, session_id))
|
||||
}
|
||||
_ => Err(Redirect::to("/login").into_response()),
|
||||
_ => Err(Box::new(Redirect::to("/login").into_response())),
|
||||
}
|
||||
}
|
||||
#[derive(Deserialize)]
|
||||
|
||||
+8
-6
@@ -7,7 +7,7 @@ set -euo pipefail
|
||||
SERVICE_USER="bzod"
|
||||
INSTALL_PATH="/usr/local/bin/bzod"
|
||||
CONFIG_DIR="/etc/bzod"
|
||||
DATA_DIR="/var/lib/bzod/data"
|
||||
NX9_BZOD_DATA_DIR="/var/lib/bzod/data"
|
||||
ENV_FILE="${CONFIG_DIR}/bzod.env"
|
||||
SYSTEMD_UNIT="/etc/systemd/system/bzod.service"
|
||||
|
||||
@@ -110,7 +110,7 @@ fi
|
||||
|
||||
# 4. Setup Directories
|
||||
echo -e "\n${BLUE}[4/8] Setting up directories...${NC}"
|
||||
mkdir -p "${CONFIG_DIR}" "${DATA_DIR}"
|
||||
mkdir -p "${CONFIG_DIR}" "${NX9_BZOD_DATA_DIR}"
|
||||
chown -R "${SERVICE_USER}:${SERVICE_USER}" "/var/lib/bzod"
|
||||
chmod 700 "${CONFIG_DIR}"
|
||||
|
||||
@@ -121,7 +121,7 @@ if [ ! -f "${ENV_FILE}" ]; then
|
||||
cat <<EOF > "${ENV_FILE}"
|
||||
HOST=0.0.0.0
|
||||
PORT=8654
|
||||
NX9_BZOD_DATA_DIR=${DATA_DIR}
|
||||
NX9_BZOD_DATA_DIR=${NX9_BZOD_DATA_DIR}
|
||||
COOKIE_SECURE=true
|
||||
RUST_LOG=info
|
||||
SESSION_SECRET=$(openssl rand -hex 32)
|
||||
@@ -175,11 +175,13 @@ systemctl daemon-reload
|
||||
# 7. Initialize & Start
|
||||
echo -e "\n${BLUE}[7/8] Initializing and starting service...${NC}"
|
||||
|
||||
if [ ! -f "${DATA_DIR}/content.db" ] && [ ! -f "${DATA_DIR}/admin.db" ] && [ ! -f "${DATA_DIR}/analytics.db" ]; then
|
||||
runuser -u "${SERVICE_USER}" -- "${INSTALL_PATH}" init-db --data-dir "${DATA_DIR}"
|
||||
echo -e "${GREEN}✓ Databases initialized${NC}"
|
||||
if [ ! -f "${NX9_BZOD_DATA_DIR}/admin/users.db" ] && [ ! -f "${NX9_BZOD_DATA_DIR}/admin.db" ]; then
|
||||
runuser -u "${SERVICE_USER}" -- "${INSTALL_PATH}" migrate --data-dir "${NX9_BZOD_DATA_DIR}"
|
||||
echo -e "${GREEN}✓ Database topology initialized${NC}"
|
||||
else
|
||||
echo -e "${GREEN}✓ Existing database detected (upgrade mode)${NC}"
|
||||
runuser -u "${SERVICE_USER}" -- "${INSTALL_PATH}" migrate --data-dir "${NX9_BZOD_DATA_DIR}"
|
||||
echo -e "${GREEN}✓ Migrations verified${NC}"
|
||||
fi
|
||||
|
||||
systemctl enable --now bzod
|
||||
|
||||
Reference in new issue
Block a user