Files
OpenMAIC/Dockerfile
T
Nguyen Quang Thiepandwyuc 3e3cac5f76 fix: enable Pro workbench flag in Docker builds; allow non-TLS localhost cookie (#1484)
* fix: enable Pro workbench flag in Docker builds; allow non-TLS localhost cookie

Two deployment fixes discovered while self-hosting with Docker Compose:

1. Expose NEXT_PUBLIC_PRO_WORKBENCH_ENABLED as a Docker build arg.
   Persistence and other NEXT_PUBLIC_* flags are already wired through
   Dockerfile + docker-compose.yml, but the Pro workbench entry flag was
   missing, so Docker deployments could not enable the workbench at all.

2. Add COOKIE_SECURE opt-out for the anonymous owner cookie.
   Production builds always set `Secure` on the anonymous_id cookie. Safari
   refuses to store Secure cookies served over plain http://localhost (it
   does not special-case localhost like Chromium/Firefox), so every request
   minted a fresh anonymous owner and owner-scoped document writes were
   rejected with 403 — scenes never persisted and generation appeared to
   hang after the first scene. COOKIE_SECURE=0 lets plain-HTTP deployments
   opt out; the default (Secure in production) is unchanged.

Documents COOKIE_SECURE in .env.example alongside the persistence opt-ins.

* fix: share the COOKIE_SECURE opt-out with the Server Action cookie mint

Review follow-up on the COOKIE_SECURE opt-out.

- Extract anonymousCookieSecure() in owner.ts and use it in
  lib/workbench/workspace-actions.ts, which re-implements the anonymous_id
  mint: with COOKIE_SECURE=0 that path still sent a Secure cookie, so a
  Server Action running before any /api/agent/* request (e.g. deleting a
  workspace session) minted an ephemeral owner in Safari.
- State the opt-out accurately in owner.ts; the previous comment claimed the
  flag never forces Secure off.
- Add the regression test beside the existing production case (verified it
  fails when the opt-out is dropped).
- .env.example: document the security cost of dropping Secure and that only
  the exact value 0 disables it.

---------

Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
2026-09-14 17:01:59 +02:00

117 lines
3.7 KiB
Docker

# syntax=docker/dockerfile:1
# ---- Stage 1: Base ----
FROM node:22-alpine AS base
ARG ALPINE_MIRROR=""
ARG NPM_REGISTRY=""
RUN if [ -n "$ALPINE_MIRROR" ]; then \
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
fi && \
apk add --no-cache libc6-compat
RUN npm_registry="$NPM_REGISTRY"; \
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
npm_registry="${npm_registry%/}"; \
done; \
if [ -n "$npm_registry" ]; then \
export COREPACK_NPM_REGISTRY="$npm_registry"; \
fi && \
corepack enable && \
corepack prepare pnpm@10.28.0 --activate
WORKDIR /app
# ---- Stage 2: Dependencies ----
FROM base AS deps
ARG NPM_REGISTRY
# Native build tools for sharp, @napi-rs/canvas
RUN apk add --no-cache python3 build-base g++ cairo-dev pango-dev jpeg-dev giflib-dev librsvg-dev
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
COPY packages/ ./packages/
COPY scripts/ ./scripts/
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
npm_registry="$NPM_REGISTRY"; \
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
npm_registry="${npm_registry%/}"; \
done; \
if [ -n "$npm_registry" ]; then \
pnpm config set registry "$npm_registry"; \
fi && \
pnpm install --frozen-lockfile
# ---- Stage 3: Builder ----
FROM base AS builder
ARG ALLOWED_FRAME_ANCESTORS
ARG NEXT_PUBLIC_PERSISTENCE
ARG NEXT_PUBLIC_PERSISTENCE_TOKEN
ARG NEXT_PUBLIC_MAIC_EDITOR_ENABLED
ARG NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
ARG NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
ARG NEXT_PUBLIC_PI_CHAT_ENABLED
ARG NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
ARG NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
ARG NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
ARG NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
ARG NEXT_PUBLIC_ENABLE_PPTX_IMPORT
ARG NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
ENV ALLOWED_FRAME_ANCESTORS=$ALLOWED_FRAME_ANCESTORS
ENV NEXT_PUBLIC_PERSISTENCE=$NEXT_PUBLIC_PERSISTENCE
ENV NEXT_PUBLIC_PERSISTENCE_TOKEN=$NEXT_PUBLIC_PERSISTENCE_TOKEN
ENV NEXT_PUBLIC_MAIC_EDITOR_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_ENABLED
ENV NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
ENV NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
ENV NEXT_PUBLIC_PI_CHAT_ENABLED=$NEXT_PUBLIC_PI_CHAT_ENABLED
ENV NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED=$NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
ENV NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI=$NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
ENV NEXT_PUBLIC_ENABLE_VIDEO_EXPORT=$NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
ENV NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION=$NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
ENV NEXT_PUBLIC_ENABLE_PPTX_IMPORT=$NEXT_PUBLIC_ENABLE_PPTX_IMPORT
ENV NEXT_PUBLIC_PRO_WORKBENCH_ENABLED=$NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
COPY --from=deps /app/node_modules ./node_modules
COPY --from=deps /app/packages ./packages
COPY . .
COPY --from=deps /app/public/vendor ./public/vendor
RUN pnpm build
# ---- Stage 4: Runner ----
FROM node:22-alpine AS runner
ARG ALPINE_MIRROR=""
WORKDIR /app
ENV NODE_ENV=production
ENV HOSTNAME=0.0.0.0
ENV PORT=3000
RUN if [ -n "$ALPINE_MIRROR" ]; then \
cp /etc/apk/repositories /tmp/apk.repositories; \
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
fi && \
apk add --no-cache libc6-compat cairo pango jpeg giflib librsvg && \
if [ -n "$ALPINE_MIRROR" ]; then \
mv /tmp/apk.repositories /etc/apk/repositories; \
fi
RUN addgroup --system --gid 1001 nodejs && \
adduser --system --uid 1001 nextjs
COPY --from=builder /app/public ./public
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
USER nextjs
EXPOSE 3000
CMD ["node", "server.js"]