Compare commits
91
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
64d12c6658
|
||
|
|
7df61ddcd7
|
||
|
|
34cd98625c
|
||
|
|
fa64cf64a2
|
||
|
|
8336930077
|
||
|
|
1a69f59b32
|
||
|
|
975d1ca614
|
||
|
|
28127bc1f5
|
||
|
|
93e4a65a00
|
||
|
|
8728684c21
|
||
|
|
dfb5b6b794
|
||
|
|
8cf138b035
|
||
|
|
d48f1caa28
|
||
|
|
6a2ad475be
|
||
|
|
942ae25f09
|
||
|
|
b6968f1742
|
||
|
|
4f4e086518
|
||
|
|
a04a1479f8
|
||
|
|
613090d38a
|
||
|
|
f1c540537a
|
||
|
|
1dcdc2b032
|
||
|
|
4545c3ba19
|
||
|
|
bfa1514181
|
||
|
|
f0846308da
|
||
|
|
b3b7fe6359
|
||
|
|
f0b541ee50
|
||
|
|
df9077e3c1
|
||
|
|
74666130c0
|
||
|
|
7c43a4d919
|
||
|
|
520552ec70
|
||
|
|
307095bfd0
|
||
|
|
ae7291d4f1
|
||
|
|
322ca98da9
|
||
|
|
66f3950b83
|
||
|
|
4e115eb514
|
||
|
|
fc9b471a10
|
||
|
|
b33e47e60f
|
||
|
|
9878e4a3e8
|
||
|
|
9c35323bcd
|
||
|
|
e2716d94c0
|
||
|
|
9394f649a6
|
||
|
|
41b9cb722b
|
||
|
|
f1c13d7bd9
|
||
|
|
c6cb9caa6d
|
||
|
|
208977177a
|
||
|
|
9a406b8381
|
||
|
|
4c972bfe7a
|
||
|
|
0191d248f8
|
||
|
|
710afb6c78
|
||
|
|
69e9662133
|
||
|
|
a73d0f29bd
|
||
|
|
7836805570
|
||
|
|
1fc434cb3a
|
||
|
|
dad7d5195e
|
||
|
|
596cad34da
|
||
|
|
aaee5cb4ed
|
||
|
|
ebaca5ba65
|
||
|
|
b6bcfa2ee3
|
||
|
|
9082ee45d8
|
||
|
|
29264aad98
|
||
|
|
259b51a95e
|
||
|
|
fb369530e3
|
||
|
|
5dc10a4d33
|
||
|
|
2297c68046
|
||
|
|
b82ab45c99
|
||
|
|
d12c63db26
|
||
|
|
e6a9ef84ce
|
||
|
|
b7e91344a0
|
||
|
|
0f07e32781
|
||
|
|
1311b5ed6a
|
||
|
|
12f82061e8
|
||
|
|
a07b4369ab
|
||
|
|
2605c06807
|
||
|
|
1db768fb15
|
||
|
|
8a7403df32
|
||
|
|
f0295fef7a
|
||
|
|
090affd304
|
||
|
|
bafddd436b
|
||
|
|
560f193c4b
|
||
|
|
8aabbad5bb
|
||
|
|
ba8d21eb7a
|
||
|
|
53df455d53
|
||
|
|
9f1af3a9aa
|
||
|
|
1d09008ce2
|
||
|
|
57c5317c38
|
||
|
|
41bd920060
|
||
|
|
0815fa6040
|
||
|
|
af0e99aa50
|
||
|
|
f05eec5255
|
||
|
|
66ca2dc6b0
|
||
|
|
800183e9da
|
No files matched your search
@@ -7,16 +7,13 @@ ejabberd, Discourse, Mastodon, remoteStorage, Nostr, LNDHub, and BTCPay.
|
|||||||
## Development environment
|
## Development environment
|
||||||
|
|
||||||
Development runs in Docker Compose — run all commands against the `web` container.
|
Development runs in Docker Compose — run all commands against the `web` container.
|
||||||
Start services: `docker compose up` (web, ldap, redis, garage, liquor-cabinet, strfry).
|
Start services: `docker compose up` (web, ldap, redis, minio, liquor-cabinet, strfry).
|
||||||
The `web` service runs `bin/dev` (foreman: Puma + Tailwind CSS watcher) and embeds
|
The `web` service runs `bin/dev` (foreman: Puma + Tailwind CSS watcher) and embeds
|
||||||
Solid Queue workers (`SOLID_QUEUE_IN_PUMA=true`).
|
Solid Queue workers (`SOLID_QUEUE_IN_PUMA=true`).
|
||||||
|
|
||||||
First-time LDAP and database setup is automated: the `ldap-init` service
|
First-time LDAP setup (after creating the 389ds backend once):
|
||||||
creates the 389ds back-end, then the `web` entrypoint seeds LDAP and the
|
`docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be_name="dev"`
|
||||||
databases on first start and runs `db:prepare` on every boot. Manual
|
then `docker compose run web bin/rails ldap:setup`.
|
||||||
equivalents: `docker compose exec ldap dsconf localhost backend create
|
|
||||||
--suffix="dc=kosmos,dc=org" --be-name="dev"` and `docker compose run --rm web
|
|
||||||
bin/rails ldap:setup`.
|
|
||||||
|
|
||||||
## Common commands (prefix with `docker compose exec web`)
|
## Common commands (prefix with `docker compose exec web`)
|
||||||
|
|
||||||
|
|||||||
@@ -14,14 +14,13 @@ so:
|
|||||||
|
|
||||||
1. Make sure [Docker Compose is installed][1] and Docker is running (included in
|
1. Make sure [Docker Compose is installed][1] and Docker is running (included in
|
||||||
Docker Desktop)
|
Docker Desktop)
|
||||||
2. Run `docker compose up --build` and wait until all services have started
|
3. Run `docker compose up --build` and wait until all services have started
|
||||||
(389ds might take an extra minute to be ready). This will take a while when
|
(389ds might take an extra minute to be ready). This will take a while when
|
||||||
running for the first time, so you might want to do something else in the
|
running for the first time, so you might want to do something else in the
|
||||||
meantime.
|
meantime.
|
||||||
|
4. `docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"`
|
||||||
On the first start, the `ldap-init` service creates the 389ds back-end, and the
|
5. `docker compose run web rails ldap:setup`
|
||||||
`web` container then seeds the LDAP directory and the databases automatically.
|
6. `docker compose run web rails db:setup`
|
||||||
On every start, `web` also applies any pending database migrations.
|
|
||||||
|
|
||||||
After these steps, you should have a working Rails app with a handful of test
|
After these steps, you should have a working Rails app with a handful of test
|
||||||
users running on [http://localhost:3000](http://localhost:3000).
|
users running on [http://localhost:3000](http://localhost:3000).
|
||||||
@@ -72,12 +71,15 @@ containers you want to run to the `up` command, like so:
|
|||||||
|
|
||||||
#### LDAP server
|
#### LDAP server
|
||||||
|
|
||||||
On first start, the `ldap-init` service creates the dirsrv back-end
|
After creating the Docker container for the first time (or after deleting it),
|
||||||
automatically, and the `web` container then seeds it with development entries.
|
you need to run the following command once, in order to create the dirsrv
|
||||||
To do either step manually (for example, after changing the setup), run:
|
back-end:
|
||||||
|
|
||||||
docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"
|
docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"
|
||||||
docker compose run --rm web bin/rails ldap:setup
|
|
||||||
|
Now you can seed the back-end with data using this Rails task:
|
||||||
|
|
||||||
|
bundle exec rails ldap:setup
|
||||||
|
|
||||||
The setup task will first delete any existing entries in the directory tree
|
The setup task will first delete any existing entries in the directory tree
|
||||||
("dc=kosmos,dc=org"), and then create our development entries.
|
("dc=kosmos,dc=org"), and then create our development entries.
|
||||||
@@ -86,42 +88,20 @@ Note that all 389ds data is stored in the `389ds-data` volume. So if you want
|
|||||||
to start over with a fresh installation, delete both that volume as well as the
|
to start over with a fresh installation, delete both that volume as well as the
|
||||||
container.
|
container.
|
||||||
|
|
||||||
To reset the development environment completely, remove all volumes plus the
|
#### Minio / remoteStorage
|
||||||
generated database files and the first-run marker, then start over:
|
|
||||||
|
|
||||||
docker compose down -v
|
If you want to run remoteStorage accounts locally, you will have to create the
|
||||||
rm -f db/*.sqlite3 tmp/.setup-complete
|
respective bucket first. With the `minio` container running (run by default
|
||||||
docker compose up --build
|
when using Docker Compose), follow these steps:
|
||||||
|
|
||||||
#### Garage / remoteStorage
|
* `docker compose up web redis minio liquor-cabinet`
|
||||||
|
* Head to http://localhost:9001 and log in with user `minioadmin`, password
|
||||||
remoteStorage accounts use the `garage` S3-compatible object store. On first
|
`minioadmin`
|
||||||
start, Garage automatically configures a single-node cluster and creates the
|
* Create a new bucket called `remotestorage` (or whatever you
|
||||||
`remotestorage` bucket together with a `dev-key1` access key (secret
|
change the `S3_BUCKET` config to)
|
||||||
`1234567890123456`), so no manual setup is required.
|
* Create a new key with ID "dev-key" and secret "123456789" (or whatever you
|
||||||
|
change `S3_ACCESS_KEY` and `S3_SECRET_KEY` to). Leave the policy field empty,
|
||||||
If you want to run remoteStorage accounts locally, the `garage` container is
|
as it will automatically allow access to the bucket you created.
|
||||||
started by default when using Docker Compose. To run just the remoteStorage
|
|
||||||
stack:
|
|
||||||
|
|
||||||
* `docker compose up web redis garage liquor-cabinet`
|
|
||||||
|
|
||||||
The S3 API is available at http://localhost:3900 (region `garage`). If you want
|
|
||||||
to start over with a fresh storage, delete the `garage-data` volume as well as
|
|
||||||
the container.
|
|
||||||
|
|
||||||
#### Accessing remoteStorage from another machine
|
|
||||||
|
|
||||||
remoteStorage clients force HTTPS for any host except `localhost`, and browsers
|
|
||||||
block plain-HTTP requests to a LAN IP as mixed content. To connect to the dev
|
|
||||||
remoteStorage from a browser on another machine (including production apps such
|
|
||||||
as Inspektor), forward the ports over SSH and connect as `localhost`:
|
|
||||||
|
|
||||||
ssh -N -L 3000:localhost:3000 -L 4567:localhost:4567 <user>@<dev-host>
|
|
||||||
|
|
||||||
Then use `<user>@localhost:3000` as the remoteStorage address in the client.
|
|
||||||
WeFinger discovery and storage requests are served through the forwarded ports,
|
|
||||||
so no TLS setup is needed.
|
|
||||||
|
|
||||||
### Adding npm modules to use with Stimulus controllers
|
### Adding npm modules to use with Stimulus controllers
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
class Services::RemotestorageController < Services::BaseController
|
class Services::RemotestorageController < Services::BaseController
|
||||||
before_action :authenticate_user!
|
before_action :authenticate_user!
|
||||||
before_action :require_service_available
|
before_action :require_service_available
|
||||||
before_action :require_service_enabled
|
before_action :require_feature_enabled
|
||||||
|
|
||||||
# Dashboard
|
# Dashboard
|
||||||
def show
|
def show
|
||||||
@@ -17,8 +17,8 @@ class Services::RemotestorageController < Services::BaseController
|
|||||||
http_status :not_found unless Setting.remotestorage_enabled?
|
http_status :not_found unless Setting.remotestorage_enabled?
|
||||||
end
|
end
|
||||||
|
|
||||||
def require_service_enabled
|
def require_feature_enabled
|
||||||
unless current_user.service_enabled?(:remotestorage)
|
unless Flipper.enabled?(:remotestorage, current_user)
|
||||||
http_status :forbidden
|
http_status :forbidden
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,7 +1,8 @@
|
|||||||
class Services::RsAuthsController < Services::BaseController
|
class Services::RsAuthsController < Services::BaseController
|
||||||
before_action :authenticate_user!
|
before_action :authenticate_user!
|
||||||
before_action :require_service_enabled
|
before_action :require_feature_enabled
|
||||||
before_action :require_service_available
|
before_action :require_service_available
|
||||||
|
# before_action :require_service_enabled
|
||||||
before_action :find_rs_auth, only: [:destroy, :launch_app]
|
before_action :find_rs_auth, only: [:destroy, :launch_app]
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@@ -22,12 +23,9 @@ class Services::RsAuthsController < Services::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def launch_app
|
def launch_app
|
||||||
user_address =
|
user_address = Rails.env.development? ?
|
||||||
if Rails.env.development?
|
"#{current_user.cn}@localhost:3000" :
|
||||||
"#{current_user.cn}@#{request.host_with_port}"
|
|
||||||
else
|
|
||||||
current_user.address
|
current_user.address
|
||||||
end
|
|
||||||
|
|
||||||
launch_url = "#{@auth.launch_url}#remotestorage=#{user_address}"
|
launch_url = "#{@auth.launch_url}#remotestorage=#{user_address}"
|
||||||
|
|
||||||
@@ -36,8 +34,8 @@ class Services::RsAuthsController < Services::BaseController
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def require_service_enabled
|
def require_feature_enabled
|
||||||
unless current_user.service_enabled?(:remotestorage)
|
unless Flipper.enabled?(:remotestorage, current_user)
|
||||||
http_status :forbidden
|
http_status :forbidden
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -88,14 +88,8 @@ class WebfingerController < WellKnownController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def remotestorage_link
|
def remotestorage_link
|
||||||
auth_url =
|
auth_url = new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
|
||||||
if Rails.env.development?
|
storage_url = "#{Setting.rs_storage_url}/#{@username}"
|
||||||
new_rs_oauth_url(@username)
|
|
||||||
else
|
|
||||||
new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
|
|
||||||
end
|
|
||||||
|
|
||||||
storage_url = "#{remotestorage_storage_base_url}/#{@username}"
|
|
||||||
|
|
||||||
{
|
{
|
||||||
rel: "http://tools.ietf.org/id/draft-dejong-remotestorage",
|
rel: "http://tools.ietf.org/id/draft-dejong-remotestorage",
|
||||||
@@ -109,12 +103,4 @@ class WebfingerController < WellKnownController
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
end
|
end
|
||||||
|
|
||||||
def remotestorage_storage_base_url
|
|
||||||
return Setting.rs_storage_url unless Rails.env.development?
|
|
||||||
|
|
||||||
uri = URI.parse(Setting.rs_storage_url)
|
|
||||||
uri.host = request.host
|
|
||||||
uri.to_s
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
@@ -305,7 +305,7 @@
|
|||||||
<td>remoteStorage</td>
|
<td>remoteStorage</td>
|
||||||
<td>
|
<td>
|
||||||
<%= render FormElements::ToggleComponent.new(
|
<%= render FormElements::ToggleComponent.new(
|
||||||
enabled: @services_enabled.include?("remotestorage"),
|
enabled: Flipper.enabled?(:remotestorage, current_user) && @services_enabled.include?("remotestorage"),
|
||||||
input_enabled: false
|
input_enabled: false
|
||||||
) %>
|
) %>
|
||||||
</td>
|
</td>
|
||||||
|
|||||||
@@ -43,7 +43,8 @@
|
|||||||
<% end %>
|
<% end %>
|
||||||
</div>
|
</div>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% if Setting.remotestorage_enabled? %>
|
<% if Setting.remotestorage_enabled? &&
|
||||||
|
Flipper.enabled?(:remotestorage, current_user) %>
|
||||||
<div class="border border-gray-300 rounded-md hover:border-gray-400
|
<div class="border border-gray-300 rounded-md hover:border-gray-400
|
||||||
bg-[length:80%] bg-[center_top_-156px] bg-no-repeat
|
bg-[length:80%] bg-[center_top_-156px] bg-no-repeat
|
||||||
bg-[url(/img/logos/icon_remotestorage.svg)]">
|
bg-[url(/img/logos/icon_remotestorage.svg)]">
|
||||||
|
|||||||
@@ -25,7 +25,8 @@
|
|||||||
active: @settings_section.to_s == "lightning"
|
active: @settings_section.to_s == "lightning"
|
||||||
) %>
|
) %>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% if Setting.remotestorage_enabled? %>
|
<% if Setting.remotestorage_enabled? &&
|
||||||
|
Flipper.enabled?(:remotestorage, current_user) %>
|
||||||
<%= render SidenavLinkComponent.new(
|
<%= render SidenavLinkComponent.new(
|
||||||
name: "Storage", path: setting_path(:remotestorage), icon: "remotestorage",
|
name: "Storage", path: setting_path(:remotestorage), icon: "remotestorage",
|
||||||
active: @settings_section.to_s == "remotestorage"
|
active: @settings_section.to_s == "remotestorage"
|
||||||
|
|||||||
@@ -1,4 +1,6 @@
|
|||||||
:concurrency: 2
|
:concurrency: 2
|
||||||
|
production:
|
||||||
|
:concurrency: 10
|
||||||
:queues:
|
:queues:
|
||||||
- default
|
- default
|
||||||
- mailers
|
- mailers
|
||||||
|
|||||||
+3
-6
@@ -1,9 +1,8 @@
|
|||||||
|
require 'sidekiq/testing'
|
||||||
|
|
||||||
ldap = LdapService.new
|
ldap = LdapService.new
|
||||||
|
|
||||||
original_queue_adapter = ActiveJob::Base.queue_adapter
|
Sidekiq::Testing.inline! do
|
||||||
ActiveJob::Base.queue_adapter = :inline
|
|
||||||
|
|
||||||
begin
|
|
||||||
ldap.delete_all_users!
|
ldap.delete_all_users!
|
||||||
|
|
||||||
puts "Create user: admin"
|
puts "Create user: admin"
|
||||||
@@ -26,6 +25,4 @@ begin
|
|||||||
password: "user is user", confirmed: true
|
password: "user is user", confirmed: true
|
||||||
})
|
})
|
||||||
end
|
end
|
||||||
ensure
|
|
||||||
ActiveJob::Base.queue_adapter = original_queue_adapter
|
|
||||||
end
|
end
|
||||||
+14
-40
@@ -12,20 +12,6 @@ services:
|
|||||||
DS_DM_PASSWORD: passthebutter
|
DS_DM_PASSWORD: passthebutter
|
||||||
SUFFIX_NAME: "dc=kosmos,dc=org"
|
SUFFIX_NAME: "dc=kosmos,dc=org"
|
||||||
|
|
||||||
ldap-init:
|
|
||||||
image: 4teamwork/389ds:latest
|
|
||||||
networks:
|
|
||||||
- internal_network
|
|
||||||
volumes:
|
|
||||||
- ./docker/ldap-init.sh:/ldap-init.sh:ro
|
|
||||||
environment:
|
|
||||||
LDAP_ADMIN_PASSWORD: passthebutter
|
|
||||||
LDAP_SUFFIX: "dc=kosmos,dc=org"
|
|
||||||
depends_on:
|
|
||||||
ldap:
|
|
||||||
condition: service_healthy
|
|
||||||
command: ["/bin/sh", "/ldap-init.sh"]
|
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
restart: always
|
restart: always
|
||||||
image: redis:7-alpine
|
image: redis:7-alpine
|
||||||
@@ -40,7 +26,7 @@ services:
|
|||||||
web:
|
web:
|
||||||
build: .
|
build: .
|
||||||
tty: true
|
tty: true
|
||||||
command: ["bash", "docker/web-entrypoint.sh"]
|
command: bash -c "rm -f /akkounts/tmp/pids/server.pid; bin/dev"
|
||||||
volumes:
|
volumes:
|
||||||
- .:/akkounts
|
- .:/akkounts
|
||||||
- /akkounts/node_modules
|
- /akkounts/node_modules
|
||||||
@@ -71,28 +57,20 @@ services:
|
|||||||
NOSTR_PRIVATE_KEY: 7c3ef7e448505f0615137af38569d01807d3b05b5005d5ecf8aaafcd40323cea
|
NOSTR_PRIVATE_KEY: 7c3ef7e448505f0615137af38569d01807d3b05b5005d5ecf8aaafcd40323cea
|
||||||
NOSTR_RELAY_URL: ws://strfry:7777
|
NOSTR_RELAY_URL: ws://strfry:7777
|
||||||
depends_on:
|
depends_on:
|
||||||
ldap:
|
- ldap
|
||||||
condition: service_started
|
- redis
|
||||||
ldap-init:
|
|
||||||
condition: service_completed_successfully
|
|
||||||
redis:
|
|
||||||
condition: service_started
|
|
||||||
|
|
||||||
garage:
|
minio:
|
||||||
image: dxflrs/garage:v2.4.1
|
image: quay.io/minio/minio:latest
|
||||||
command: ["/garage", "server", "--single-node", "--default-bucket"]
|
command: "server /data --console-address ':9001'"
|
||||||
networks:
|
networks:
|
||||||
- external_network
|
- external_network
|
||||||
- internal_network
|
- internal_network
|
||||||
ports:
|
ports:
|
||||||
- "3900:3900"
|
- "9000:9000"
|
||||||
|
- "9001:9001"
|
||||||
volumes:
|
volumes:
|
||||||
- ./docker/garage/garage.toml:/etc/garage.toml:ro
|
- minio-data:/data
|
||||||
- garage-data:/var/lib/garage
|
|
||||||
environment:
|
|
||||||
GARAGE_DEFAULT_ACCESS_KEY: dev-key1
|
|
||||||
GARAGE_DEFAULT_SECRET_KEY: "1234567890123456"
|
|
||||||
GARAGE_DEFAULT_BUCKET: remotestorage
|
|
||||||
|
|
||||||
liquor-cabinet:
|
liquor-cabinet:
|
||||||
image: gitea.kosmos.org/5apps/liquor-cabinet:2.0.0-rc.1
|
image: gitea.kosmos.org/5apps/liquor-cabinet:2.0.0-rc.1
|
||||||
@@ -101,21 +79,17 @@ services:
|
|||||||
- internal_network
|
- internal_network
|
||||||
ports:
|
ports:
|
||||||
- "4567:4567"
|
- "4567:4567"
|
||||||
volumes:
|
|
||||||
- ./docker/liquor-cabinet/rainbows.conf.rb:/etc/liquor-cabinet/rainbows.conf.rb:ro
|
|
||||||
command: ["bundle", "exec", "rainbows", "-c", "/etc/liquor-cabinet/rainbows.conf.rb", "--listen", "0.0.0.0:4567"]
|
|
||||||
environment:
|
environment:
|
||||||
RACK_ENV: staging
|
RACK_ENV: staging
|
||||||
REDIS_HOST: redis
|
REDIS_HOST: redis
|
||||||
REDIS_PORT: 6379
|
REDIS_PORT: 6379
|
||||||
REDIS_DB: 1
|
REDIS_DB: 1
|
||||||
S3_ENDPOINT: http://garage:3900
|
S3_ENDPOINT: http://minio:9000
|
||||||
S3_REGION: garage
|
S3_ACCESS_KEY: dev-key
|
||||||
S3_ACCESS_KEY: dev-key1
|
S3_SECRET_KEY: 123456789
|
||||||
S3_SECRET_KEY: "1234567890123456"
|
|
||||||
S3_BUCKET: remotestorage
|
S3_BUCKET: remotestorage
|
||||||
depends_on:
|
depends_on:
|
||||||
- garage
|
- minio
|
||||||
- redis
|
- redis
|
||||||
|
|
||||||
strfry:
|
strfry:
|
||||||
@@ -153,7 +127,7 @@ networks:
|
|||||||
volumes:
|
volumes:
|
||||||
389ds-data:
|
389ds-data:
|
||||||
driver: local
|
driver: local
|
||||||
garage-data:
|
minio-data:
|
||||||
driver: local
|
driver: local
|
||||||
redis-data:
|
redis-data:
|
||||||
driver: local
|
driver: local
|
||||||
|
|||||||
@@ -1,14 +0,0 @@
|
|||||||
metadata_dir = "/var/lib/garage/meta"
|
|
||||||
data_dir = "/var/lib/garage/data"
|
|
||||||
db_engine = "sqlite"
|
|
||||||
|
|
||||||
replication_factor = 1
|
|
||||||
|
|
||||||
rpc_bind_addr = "[::]:3901"
|
|
||||||
rpc_public_addr = "127.0.0.1:3901"
|
|
||||||
rpc_secret = "1799bccfd7411eddcf9ebd316bc1f5287ad12a68094e1c6ac6abde7e6feae1ec"
|
|
||||||
|
|
||||||
[s3_api]
|
|
||||||
s3_region = "garage"
|
|
||||||
api_bind_addr = "[::]:3900"
|
|
||||||
root_domain = ".s3.garage.localhost"
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
set -e
|
|
||||||
|
|
||||||
SUFFIX="${LDAP_SUFFIX:-dc=kosmos,dc=org}"
|
|
||||||
URI="ldap://ldap:3389"
|
|
||||||
|
|
||||||
if dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
|
|
||||||
backend suffix list --suffix 2>/dev/null | grep -Fqx "$SUFFIX"; then
|
|
||||||
echo "LDAP backend for $SUFFIX already exists, skipping."
|
|
||||||
else
|
|
||||||
echo "Creating LDAP backend for $SUFFIX..."
|
|
||||||
dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
|
|
||||||
backend create --suffix "$SUFFIX" --be-name dev
|
|
||||||
fi
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
Rainbows! do
|
|
||||||
use :ThreadPool
|
|
||||||
worker_connections 16
|
|
||||||
client_max_body_size 100 * 1024 * 1024
|
|
||||||
end
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
set -e
|
|
||||||
|
|
||||||
if [ ! -f tmp/.setup-complete ]; then
|
|
||||||
echo "First start: setting up LDAP entries and databases..."
|
|
||||||
bin/rails ldap:setup
|
|
||||||
bin/rails db:setup
|
|
||||||
touch tmp/.setup-complete
|
|
||||||
else
|
|
||||||
bin/rails db:prepare
|
|
||||||
fi
|
|
||||||
|
|
||||||
rm -f tmp/pids/server.pid
|
|
||||||
exec bin/dev
|
|
||||||
+1
-1
@@ -11,7 +11,7 @@
|
|||||||
"postcss-preset-env": "^7.8.3",
|
"postcss-preset-env": "^7.8.3",
|
||||||
"tailwindcss": "^3.4.0"
|
"tailwindcss": "^3.4.0"
|
||||||
},
|
},
|
||||||
"version": "0.11.1",
|
"version": "0.11.0",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"build:css:tailwind": "bun ./node_modules/tailwindcss/lib/cli.js --postcss -i ./app/assets/stylesheets/application.tailwind.css -o ./app/assets/builds/application.css",
|
"build:css:tailwind": "bun ./node_modules/tailwindcss/lib/cli.js --postcss -i ./app/assets/stylesheets/application.tailwind.css -o ./app/assets/builds/application.css",
|
||||||
"build:css": "bun run build:css:tailwind"
|
"build:css": "bun run build:css:tailwind"
|
||||||
|
|||||||
@@ -6,9 +6,7 @@ RSpec.describe Services::RsAuthsController, type: :controller do
|
|||||||
before do
|
before do
|
||||||
allow_any_instance_of(AppCatalog::WebApp).to receive(:update_metadata).and_return(true)
|
allow_any_instance_of(AppCatalog::WebApp).to receive(:update_metadata).and_return(true)
|
||||||
allow_any_instance_of(RemoteStorageAuthorization).to receive(:remove_token_expiry_job).and_return(nil)
|
allow_any_instance_of(RemoteStorageAuthorization).to receive(:remove_token_expiry_job).and_return(nil)
|
||||||
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([
|
allow_any_instance_of(Flipper).to receive(:enabled?).and_return(true)
|
||||||
{ services_enabled: ["remotestorage"] }
|
|
||||||
])
|
|
||||||
end
|
end
|
||||||
|
|
||||||
describe "GET /services/storage/rs_auths/:id/launch_app" do
|
describe "GET /services/storage/rs_auths/:id/launch_app" do
|
||||||
@@ -37,20 +35,6 @@ RSpec.describe Services::RsAuthsController, type: :controller do
|
|||||||
expect(response).to redirect_to(launch_url)
|
expect(response).to redirect_to(launch_url)
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
context "when remoteStorage is not enabled for the user" do
|
|
||||||
before do
|
|
||||||
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([
|
|
||||||
{ services_enabled: [] }
|
|
||||||
])
|
|
||||||
|
|
||||||
get :launch_app, params: { id: 1 }
|
|
||||||
end
|
|
||||||
|
|
||||||
it "responds with forbidden" do
|
|
||||||
expect(response).to have_http_status(:forbidden)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
@@ -11,7 +11,6 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
|
|||||||
end
|
end
|
||||||
|
|
||||||
describe "#create" do
|
describe "#create" do
|
||||||
before(:each) { redis_rs_delete_keys("authorizations:*") }
|
|
||||||
after(:each) { clear_enqueued_jobs }
|
after(:each) { clear_enqueued_jobs }
|
||||||
after(:all) { redis_rs_delete_keys("authorizations:*") }
|
after(:all) { redis_rs_delete_keys("authorizations:*") }
|
||||||
|
|
||||||
@@ -28,9 +27,10 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
|
|||||||
end
|
end
|
||||||
|
|
||||||
it "stores a token in redis" do
|
it "stores a token in redis" do
|
||||||
auth
|
user_auth_keys = redis_rs.keys("authorizations:#{user.cn}:*")
|
||||||
|
expect(user_auth_keys.length).to eq(1)
|
||||||
|
|
||||||
authorizations = redis_rs.smembers("authorizations:#{user.cn}:#{auth.token}")
|
authorizations = redis_rs.smembers(user_auth_keys.first)
|
||||||
expect(authorizations.sort).to eq(%w(documents photos contacts:rw videos:r tasks/work:r).sort)
|
expect(authorizations.sort).to eq(%w(documents photos contacts:rw videos:r tasks/work:r).sort)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user