mirror of
https://github.com/THU-MAIC/OpenMAIC.git
synced 2026-10-04 18:29:01 +08:00
* fix: enable Pro workbench flag in Docker builds; allow non-TLS localhost cookie Two deployment fixes discovered while self-hosting with Docker Compose: 1. Expose NEXT_PUBLIC_PRO_WORKBENCH_ENABLED as a Docker build arg. Persistence and other NEXT_PUBLIC_* flags are already wired through Dockerfile + docker-compose.yml, but the Pro workbench entry flag was missing, so Docker deployments could not enable the workbench at all. 2. Add COOKIE_SECURE opt-out for the anonymous owner cookie. Production builds always set `Secure` on the anonymous_id cookie. Safari refuses to store Secure cookies served over plain http://localhost (it does not special-case localhost like Chromium/Firefox), so every request minted a fresh anonymous owner and owner-scoped document writes were rejected with 403 — scenes never persisted and generation appeared to hang after the first scene. COOKIE_SECURE=0 lets plain-HTTP deployments opt out; the default (Secure in production) is unchanged. Documents COOKIE_SECURE in .env.example alongside the persistence opt-ins. * fix: share the COOKIE_SECURE opt-out with the Server Action cookie mint Review follow-up on the COOKIE_SECURE opt-out. - Extract anonymousCookieSecure() in owner.ts and use it in lib/workbench/workspace-actions.ts, which re-implements the anonymous_id mint: with COOKIE_SECURE=0 that path still sent a Secure cookie, so a Server Action running before any /api/agent/* request (e.g. deleting a workspace session) minted an ephemeral owner in Safari. - State the opt-out accurately in owner.ts; the previous comment claimed the flag never forces Secure off. - Add the regression test beside the existing production case (verified it fails when the opt-out is dropped). - .env.example: document the security cost of dropping Secure and that only the exact value 0 disables it. --------- Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
117 lines
3.7 KiB
Docker
117 lines
3.7 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# ---- Stage 1: Base ----
|
|
FROM node:22-alpine AS base
|
|
|
|
ARG ALPINE_MIRROR=""
|
|
ARG NPM_REGISTRY=""
|
|
|
|
RUN if [ -n "$ALPINE_MIRROR" ]; then \
|
|
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
|
|
fi && \
|
|
apk add --no-cache libc6-compat
|
|
|
|
RUN npm_registry="$NPM_REGISTRY"; \
|
|
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
|
|
npm_registry="${npm_registry%/}"; \
|
|
done; \
|
|
if [ -n "$npm_registry" ]; then \
|
|
export COREPACK_NPM_REGISTRY="$npm_registry"; \
|
|
fi && \
|
|
corepack enable && \
|
|
corepack prepare pnpm@10.28.0 --activate
|
|
|
|
WORKDIR /app
|
|
|
|
# ---- Stage 2: Dependencies ----
|
|
FROM base AS deps
|
|
|
|
ARG NPM_REGISTRY
|
|
|
|
# Native build tools for sharp, @napi-rs/canvas
|
|
RUN apk add --no-cache python3 build-base g++ cairo-dev pango-dev jpeg-dev giflib-dev librsvg-dev
|
|
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
|
|
COPY packages/ ./packages/
|
|
COPY scripts/ ./scripts/
|
|
|
|
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
|
npm_registry="$NPM_REGISTRY"; \
|
|
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
|
|
npm_registry="${npm_registry%/}"; \
|
|
done; \
|
|
if [ -n "$npm_registry" ]; then \
|
|
pnpm config set registry "$npm_registry"; \
|
|
fi && \
|
|
pnpm install --frozen-lockfile
|
|
|
|
# ---- Stage 3: Builder ----
|
|
FROM base AS builder
|
|
|
|
ARG ALLOWED_FRAME_ANCESTORS
|
|
ARG NEXT_PUBLIC_PERSISTENCE
|
|
ARG NEXT_PUBLIC_PERSISTENCE_TOKEN
|
|
ARG NEXT_PUBLIC_MAIC_EDITOR_ENABLED
|
|
ARG NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
|
|
ARG NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
|
|
ARG NEXT_PUBLIC_PI_CHAT_ENABLED
|
|
ARG NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
|
|
ARG NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
|
|
ARG NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
|
|
ARG NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
|
|
ARG NEXT_PUBLIC_ENABLE_PPTX_IMPORT
|
|
ARG NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
|
|
ENV ALLOWED_FRAME_ANCESTORS=$ALLOWED_FRAME_ANCESTORS
|
|
ENV NEXT_PUBLIC_PERSISTENCE=$NEXT_PUBLIC_PERSISTENCE
|
|
ENV NEXT_PUBLIC_PERSISTENCE_TOKEN=$NEXT_PUBLIC_PERSISTENCE_TOKEN
|
|
ENV NEXT_PUBLIC_MAIC_EDITOR_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_ENABLED
|
|
ENV NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
|
|
ENV NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
|
|
ENV NEXT_PUBLIC_PI_CHAT_ENABLED=$NEXT_PUBLIC_PI_CHAT_ENABLED
|
|
ENV NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED=$NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
|
|
ENV NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI=$NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
|
|
ENV NEXT_PUBLIC_ENABLE_VIDEO_EXPORT=$NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
|
|
ENV NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION=$NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
|
|
ENV NEXT_PUBLIC_ENABLE_PPTX_IMPORT=$NEXT_PUBLIC_ENABLE_PPTX_IMPORT
|
|
ENV NEXT_PUBLIC_PRO_WORKBENCH_ENABLED=$NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
|
|
|
|
COPY --from=deps /app/node_modules ./node_modules
|
|
COPY --from=deps /app/packages ./packages
|
|
COPY . .
|
|
COPY --from=deps /app/public/vendor ./public/vendor
|
|
|
|
RUN pnpm build
|
|
|
|
# ---- Stage 4: Runner ----
|
|
FROM node:22-alpine AS runner
|
|
|
|
ARG ALPINE_MIRROR=""
|
|
|
|
WORKDIR /app
|
|
|
|
ENV NODE_ENV=production
|
|
ENV HOSTNAME=0.0.0.0
|
|
ENV PORT=3000
|
|
|
|
RUN if [ -n "$ALPINE_MIRROR" ]; then \
|
|
cp /etc/apk/repositories /tmp/apk.repositories; \
|
|
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
|
|
fi && \
|
|
apk add --no-cache libc6-compat cairo pango jpeg giflib librsvg && \
|
|
if [ -n "$ALPINE_MIRROR" ]; then \
|
|
mv /tmp/apk.repositories /etc/apk/repositories; \
|
|
fi
|
|
|
|
RUN addgroup --system --gid 1001 nodejs && \
|
|
adduser --system --uid 1001 nextjs
|
|
|
|
COPY --from=builder /app/public ./public
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
|
|
|
|
USER nextjs
|
|
|
|
EXPOSE 3000
|
|
|
|
CMD ["node", "server.js"]
|