mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
Bot review round on #10007. The SUPER_ADMIN gate and the SharedEntity scope filter both still had a way through, and three sites answered a refused or missing row with the wrong outcome. - auth register: `/auth/register` is public and `createdByUserId` is a BODY field, so checking only that the referenced user is a super admin authorized nobody. Require an AUTHENTICATED caller holding SUPER_ADMIN_EDIT, require the field to name that caller, and pin the persisted value to it. - shared entity: fail closed where a row cannot be judged. An unresolved relation left `tenantId` out of the nested select and the filter kept every row that did not carry one; it now takes the hop metadata and drops a row whose target HAS a tenantId column but presents no matching value. Building a select for an unresolvable relation is refused outright, `null`/non-object sub-rules are rejected instead of expanding to `relation: true`, and update() accepts the inherited object criterion instead of silently matching nothing. - time-off + github repository: `findOneByIdString` resolves to null rather than throwing, so discarding it let an unknown id fall through to save() and INSERT a new row. Assert the lookup, and give the GitHub repository controller the TenantPermissionGuard every sibling controller already has. - product type: the update is a delete-then-recreate and `translations` cascades, so an omitted `translations` erased them; they are carried over as new rows now. Intentional HTTP exceptions are no longer flattened to 400. - goal controller: stop swallowing the error — a refused cross-tenant write answered 202 with an empty body. - bootstrap: validate CORP_POLICY. helmet throws on an unknown policy, so a typo would have stopped the API from booting. - hubstaff: validate `access_token` before persisting, and only rotate the stored refresh token when the provider actually returned one. - docker-compose.build: the API image built `development` while running `production`. Adds shared-entity.helper.spec.ts (17) and corp-policy.spec.ts (6), both with CONTROL arms reproducing the pre-fix behaviour. core: 30 suites / 229 tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
168 lines
6.4 KiB
YAML
168 lines
6.4 KiB
YAML
include:
|
|
- ./docker-compose.infra.yml
|
|
|
|
services:
|
|
api:
|
|
container_name: api
|
|
image: gauzy-api:latest
|
|
build:
|
|
context: .
|
|
dockerfile: .deploy/api/Dockerfile
|
|
# Only NODE_ENV is passed as a build arg here (picks the dev/prod nx build);
|
|
# the Dockerfile also accepts DEMO, NODE_OPTIONS and NX_BRANCH with built-in
|
|
# defaults. All other configuration is runtime environment (see `environment:`
|
|
# below) — the API image does not bake env values at build time.
|
|
# Same default as the runtime `NODE_ENV` below: with `development` here the image shipped the
|
|
# dev nx build while running as production.
|
|
args:
|
|
NODE_ENV: ${NODE_ENV:-production}
|
|
environment:
|
|
API_HOST: ${API_HOST:-api}
|
|
API_PORT: ${API_PORT:-3000}
|
|
NODE_ENV: ${NODE_ENV:-production}
|
|
DB_HOST: db
|
|
API_BASE_URL: ${API_BASE_URL:-http://localhost:3000}
|
|
CLIENT_BASE_URL: ${CLIENT_BASE_URL:-http://localhost:4200}
|
|
CLOUD_PROVIDER: ${CLOUD_PROVIDER:-}
|
|
SENTRY_DSN: ${SENTRY_DSN:-}
|
|
SENTRY_HTTP_TRACING_ENABLED: ${SENTRY_HTTP_TRACING_ENABLED:-}
|
|
SENTRY_POSTGRES_TRACKING_ENABLED: ${SENTRY_POSTGRES_TRACKING_ENABLED:-}
|
|
SENTRY_PROFILING_ENABLED: ${SENTRY_PROFILING_ENABLED:-}
|
|
POSTHOG_KEY: ${POSTHOG_KEY:-}
|
|
POSTHOG_HOST: ${POSTHOG_HOST:-}
|
|
POSTHOG_ENABLED: ${POSTHOG_ENABLED:-}
|
|
POSTHOG_FLUSH_INTERVAL: ${POSTHOG_FLUSH_INTERVAL:-}
|
|
JITSU_SERVER_URL: ${JITSU_SERVER_URL:-}
|
|
OTEL_EXPORTER_OTLP_TRACES_ENDPOINT: ${OTEL_EXPORTER_OTLP_TRACES_ENDPOINT:-}
|
|
OTEL_EXPORTER_OTLP_HEADERS: ${OTEL_EXPORTER_OTLP_HEADERS:-}
|
|
OTEL_ENABLED: ${OTEL_ENABLED:-}
|
|
OTEL_PROVIDER: ${OTEL_PROVIDER:-}
|
|
JITSU_SERVER_WRITE_KEY: ${JITSU_SERVER_WRITE_KEY:-}
|
|
GAUZY_GITHUB_CLIENT_ID: ${GAUZY_GITHUB_CLIENT_ID:-}
|
|
GAUZY_GITHUB_CLIENT_SECRET: ${GAUZY_GITHUB_CLIENT_SECRET:-}
|
|
GAUZY_GITHUB_WEBHOOK_URL: ${GAUZY_GITHUB_WEBHOOK_URL:-}
|
|
GAUZY_GITHUB_WEBHOOK_SECRET: ${GAUZY_GITHUB_WEBHOOK_SECRET:-}
|
|
GAUZY_GITHUB_APP_PRIVATE_KEY: ${GAUZY_GITHUB_APP_PRIVATE_KEY:-}
|
|
GAUZY_GITHUB_APP_ID: ${GAUZY_GITHUB_APP_ID:-}
|
|
GAUZY_GITHUB_APP_NAME: ${GAUZY_GITHUB_APP_NAME:-}
|
|
GAUZY_GITHUB_POST_INSTALL_URL: ${GAUZY_GITHUB_POST_INSTALL_URL:-}
|
|
GAUZY_GITHUB_OAUTH_CLIENT_ID: ${GAUZY_GITHUB_OAUTH_CLIENT_ID:-}
|
|
GAUZY_GITHUB_OAUTH_CLIENT_SECRET: ${GAUZY_GITHUB_OAUTH_CLIENT_SECRET:-}
|
|
GAUZY_GITHUB_OAUTH_CALLBACK_URL: ${GAUZY_GITHUB_OAUTH_CALLBACK_URL:-}
|
|
MAGIC_CODE_EXPIRATION_TIME: ${MAGIC_CODE_EXPIRATION_TIME:-}
|
|
APP_NAME: ${APP_NAME:-}
|
|
APP_LOGO: ${APP_LOGO:-}
|
|
APP_SIGNATURE: ${APP_SIGNATURE:-}
|
|
APP_LINK: ${APP_LINK:-}
|
|
APP_EMAIL_CONFIRMATION_URL: ${APP_EMAIL_CONFIRMATION_URL:-}
|
|
APP_MAGIC_SIGN_URL: ${APP_MAGIC_SIGN_URL:-}
|
|
COMPANY_LINK: ${COMPANY_LINK:-}
|
|
COMPANY_NAME: ${COMPANY_NAME:-}
|
|
|
|
env_file:
|
|
- .env.compose
|
|
entrypoint: './entrypoint.compose.sh'
|
|
command: ['node', 'main.js']
|
|
restart: on-failure
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
zipkin:
|
|
condition: service_started
|
|
redis:
|
|
condition: service_started
|
|
minio:
|
|
condition: service_healthy
|
|
minio_create_buckets:
|
|
condition: service_started
|
|
opensearch:
|
|
condition: service_healthy
|
|
cube:
|
|
condition: service_started
|
|
links:
|
|
- db:${DB_HOST:-db}
|
|
- cube:${CUBE_HOST:-cube}
|
|
- redis:${REDIS_HOST:-redis}
|
|
- minio:${MINIO_HOST:-minio}
|
|
- opensearch:${ES_HOST:-opensearch}
|
|
# volumes:
|
|
# - webapp_node_modules:/srv/gauzy/node_modules
|
|
# - api_node_modules:/srv/gauzy/apps/api/node_modules
|
|
ports:
|
|
- '3000:${API_PORT:-3000}'
|
|
networks:
|
|
- overlay
|
|
|
|
webapp:
|
|
container_name: webapp
|
|
image: gauzy-webapp:latest
|
|
build:
|
|
context: .
|
|
dockerfile: .deploy/webapp/Dockerfile
|
|
# Only NODE_ENV and DEMO are passed as build args here; the Dockerfile also
|
|
# accepts NODE_OPTIONS and NX_BRANCH with built-in defaults. The Angular bundle
|
|
# is compiled with DOCKER_* placeholders; all other values are substituted from
|
|
# the RUNTIME environment (see `environment:` below) by the container entrypoint
|
|
# at startup.
|
|
args:
|
|
NODE_ENV: ${NODE_ENV:-development}
|
|
DEMO: 'true'
|
|
environment:
|
|
WEB_HOST: ${WEB_HOST:-webapp}
|
|
WEB_PORT: ${WEB_PORT:-4200}
|
|
NODE_ENV: ${NODE_ENV:-development}
|
|
API_BASE_URL: ${API_BASE_URL:-http://localhost:3000}
|
|
CLIENT_BASE_URL: ${CLIENT_BASE_URL:-http://localhost:4200}
|
|
SENTRY_DSN: ${SENTRY_DSN:-}
|
|
SENTRY_TRACES_SAMPLE_RATE: ${SENTRY_TRACES_SAMPLE_RATE:-0.1}
|
|
SENTRY_PROFILE_SAMPLE_RATE: ${SENTRY_PROFILE_SAMPLE_RATE:-1}
|
|
CHATWOOT_SDK_TOKEN: ${CHATWOOT_SDK_TOKEN:-}
|
|
CLOUDINARY_CLOUD_NAME: ${CLOUDINARY_CLOUD_NAME:-}
|
|
CLOUDINARY_API_KEY: ${CLOUDINARY_API_KEY:-}
|
|
GOOGLE_MAPS_API_KEY: ${GOOGLE_MAPS_API_KEY:-}
|
|
GOOGLE_PLACE_AUTOCOMPLETE: ${GOOGLE_PLACE_AUTOCOMPLETE:-false}
|
|
DEFAULT_LATITUDE: ${DEFAULT_LATITUDE:-42.6459136}
|
|
DEFAULT_LONGITUDE: ${DEFAULT_LONGITUDE:-23.3332736}
|
|
DEFAULT_CURRENCY: ${DEFAULT_CURRENCY:-USD}
|
|
GAUZY_GITHUB_CLIENT_ID: ${GAUZY_GITHUB_CLIENT_ID:-}
|
|
GAUZY_GITHUB_APP_NAME: ${GAUZY_GITHUB_APP_NAME:-}
|
|
GAUZY_GITHUB_REDIRECT_URL: ${GAUZY_GITHUB_REDIRECT_URL:-}
|
|
GAUZY_GITHUB_POST_INSTALL_URL: ${GAUZY_GITHUB_POST_INSTALL_URL:-}
|
|
GAUZY_GITHUB_APP_ID: ${GAUZY_GITHUB_APP_ID:-}
|
|
JITSU_BROWSER_URL: ${JITSU_BROWSER_URL:-}
|
|
JITSU_BROWSER_WRITE_KEY: ${JITSU_BROWSER_WRITE_KEY:-}
|
|
DEMO: 'true'
|
|
API_HOST: ${API_HOST:-api}
|
|
API_PORT: ${API_PORT:-3000}
|
|
entrypoint: './entrypoint.compose.sh'
|
|
command: ['nginx', '-g', 'daemon off;']
|
|
env_file:
|
|
- .env.compose
|
|
restart: on-failure
|
|
links:
|
|
- db:${DB_HOST:-db}
|
|
- api:${API_HOST:-api}
|
|
- cube:${CUBE_HOST:-cube}
|
|
- redis:${REDIS_HOST:-redis}
|
|
- minio:${MINIO_HOST:-minio}
|
|
- opensearch:${ES_HOST:-opensearch}
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
redis:
|
|
condition: service_started
|
|
minio:
|
|
condition: service_healthy
|
|
minio_create_buckets:
|
|
condition: service_started
|
|
opensearch:
|
|
condition: service_started
|
|
api:
|
|
condition: service_started
|
|
# volumes:
|
|
# - webapp_node_modules:/srv/gauzy/node_modules
|
|
ports:
|
|
- '4200:${UI_PORT:-4200}'
|
|
networks:
|
|
- overlay
|