Compare commits
46 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 35b87a9a98 | |||
| 80262aca9b | |||
| 71a8823b35 | |||
| 10e7f3e70d | |||
| e8f0d4bdc5 | |||
| c77c52271c | |||
| 7e00ed3151 | |||
| 39c9666c0f | |||
| 8eb240440b | |||
| 9dc6fe6eeb | |||
| acfa24d742 | |||
| 88f6b77455 | |||
| bc5e08142a | |||
| 373839cf03 | |||
| 8e31309c55 | |||
| e8391dbf1e | |||
| bc274da006 | |||
| f0b5edff79 | |||
| 5b95c5202e | |||
| 51c17d11f2 | |||
| 91ddc6e864 | |||
| 88f124c991 | |||
| 33c65f21b6 | |||
| fd242a6a0a | |||
| 2892024969 | |||
| 27f5280bbf | |||
| 82898e34cb | |||
| 44392c2c31 | |||
| 58d94b716f | |||
| 579a0ddb75 | |||
| 0f21e8d9ca | |||
| 12f7240cd2 | |||
| 54d8d61358 | |||
| 5052dd9de6 | |||
| bf31ee2d16 | |||
| b847930500 | |||
| 756ff55b4c | |||
| df5a3265a1 | |||
| 2c6da44af8 | |||
| d6d6858002 | |||
| 0cf0bd8dec | |||
| af9826547c | |||
| 87027cf3c9 | |||
| 46f79b002b | |||
| dcc8aae650 | |||
| c9fdf41e0b |
@@ -4,17 +4,20 @@ on:
|
||||
push:
|
||||
tags:
|
||||
- "v*"
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
bump:
|
||||
description: "Version bump type (major stays fixed from latest release)"
|
||||
release_type:
|
||||
description: "Release type"
|
||||
required: false
|
||||
default: "patch"
|
||||
type: choice
|
||||
options:
|
||||
- patch
|
||||
- minor
|
||||
- major
|
||||
- minor
|
||||
- patch
|
||||
- dev
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
@@ -38,12 +41,59 @@ jobs:
|
||||
REPO: ${{ gitea.repository }}
|
||||
EVENT_NAME: ${{ gitea.event_name }}
|
||||
REF_NAME: ${{ gitea.ref_name }}
|
||||
BUMP_TYPE: ${{ gitea.event.inputs.bump || 'patch' }}
|
||||
RELEASE_TYPE: ${{ gitea.event.inputs.release_type || 'patch' }}
|
||||
RUN_NUMBER: ${{ gitea.run_number }}
|
||||
DOCKER_API_VERSION: '1.44'
|
||||
run: |
|
||||
if [ "$EVENT_NAME" = "push" ] && [ -n "$REF_NAME" ]; then
|
||||
if [ "$EVENT_NAME" = "push" ] && [ "$REF_NAME" = "main" ]; then
|
||||
prerelease=true
|
||||
latest_tag="v0.8.31"
|
||||
if meta_json=$(curl -fsSL -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/json" "https://git.invario-software.eu/api/v1/repos/$REPO/releases/latest" 2>/dev/null); then
|
||||
tag_name=$(printf "%s" "$meta_json" | sed -n 's/.*"tag_name"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' | head -n1)
|
||||
if [ -n "$tag_name" ]; then
|
||||
latest_tag="$tag_name"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ "$latest_tag" =~ ^v([0-9]+)\.([0-9]+)\.([0-9]+)$ ]]; then
|
||||
major=${BASH_REMATCH[1]}
|
||||
minor=${BASH_REMATCH[2]}
|
||||
patch=${BASH_REMATCH[3]}
|
||||
else
|
||||
major=0
|
||||
minor=8
|
||||
patch=31
|
||||
fi
|
||||
|
||||
patch=$((patch + 1))
|
||||
TAG="v${major}.${minor}.${patch}-dev.${RUN_NUMBER:-0}"
|
||||
elif [ "$EVENT_NAME" = "workflow_dispatch" ] && [ "$RELEASE_TYPE" = "dev" ]; then
|
||||
prerelease=true
|
||||
latest_tag="v0.8.31"
|
||||
if meta_json=$(curl -fsSL -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/json" "https://git.invario-software.eu/api/v1/repos/$REPO/releases/latest" 2>/dev/null); then
|
||||
tag_name=$(printf "%s" "$meta_json" | sed -n 's/.*"tag_name"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' | head -n1)
|
||||
if [ -n "$tag_name" ]; then
|
||||
latest_tag="$tag_name"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ "$latest_tag" =~ ^v([0-9]+)\.([0-9]+)\.([0-9]+)$ ]]; then
|
||||
major=${BASH_REMATCH[1]}
|
||||
minor=${BASH_REMATCH[2]}
|
||||
patch=${BASH_REMATCH[3]}
|
||||
else
|
||||
major=0
|
||||
minor=8
|
||||
patch=31
|
||||
fi
|
||||
|
||||
patch=$((patch + 1))
|
||||
TAG="v${major}.${minor}.${patch}-dev.${RUN_NUMBER:-0}"
|
||||
elif [ "$EVENT_NAME" = "push" ] && [ -n "$REF_NAME" ]; then
|
||||
prerelease=false
|
||||
TAG="$REF_NAME"
|
||||
else
|
||||
prerelease=false
|
||||
latest_tag="v0.8.31"
|
||||
if meta_json=$(curl -fsSL -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/json" "https://git.invario-software.eu/api/v1/repos/$REPO/releases/latest" 2>/dev/null); then
|
||||
tag_name=$(printf "%s" "$meta_json" | sed -n 's/.*"tag_name"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' | head -n1)
|
||||
@@ -60,14 +110,14 @@ jobs:
|
||||
major=0; minor=8; patch=31
|
||||
fi
|
||||
|
||||
if [ "${BUMP_TYPE:-}" = "major" ]; then
|
||||
if [ "${RELEASE_TYPE:-}" = "major" ]; then
|
||||
major=$((major + 1)); minor=0; patch=0
|
||||
elif [ "${BUMP_TYPE:-}" = "minor" ]; then
|
||||
elif [ "${RELEASE_TYPE:-}" = "minor" ]; then
|
||||
minor=$((minor + 1)); patch=0
|
||||
else
|
||||
patch=$((patch + 1))
|
||||
fi
|
||||
|
||||
|
||||
TAG="v${major}.${minor}.${patch}"
|
||||
fi
|
||||
|
||||
@@ -109,6 +159,7 @@ jobs:
|
||||
echo "tag=$TAG" >> "$GITHUB_OUTPUT"
|
||||
echo "image=$IMAGE" >> "$GITHUB_OUTPUT"
|
||||
echo "lower_repo=$LOWER_REPO" >> "$GITHUB_OUTPUT"
|
||||
echo "prerelease=$prerelease" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Ensure Docker CLI is available and up to date
|
||||
run: |
|
||||
@@ -148,6 +199,7 @@ jobs:
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
|
||||
- name: Build and push release image
|
||||
if: steps.meta.outputs.prerelease != 'true'
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
@@ -157,6 +209,16 @@ jobs:
|
||||
${{ steps.meta.outputs.image }}
|
||||
git.invario-software.eu/${{ steps.meta.outputs.lower_repo }}:latest
|
||||
|
||||
- name: Build and push prerelease image
|
||||
if: steps.meta.outputs.prerelease == 'true'
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
file: ./Dockerfile
|
||||
push: true
|
||||
tags: |
|
||||
${{ steps.meta.outputs.image }}
|
||||
|
||||
- name: Create release-only docker bundle
|
||||
run: |
|
||||
mkdir -p release-bundle
|
||||
@@ -253,5 +315,6 @@ jobs:
|
||||
uses: https://gitea.com/actions/gitea-release-action@v1
|
||||
with:
|
||||
tag_name: ${{ steps.meta.outputs.tag }}
|
||||
prerelease: ${{ steps.meta.outputs.prerelease }}
|
||||
files: |
|
||||
inventarsystem-docker-bundle.tar.gz
|
||||
+740
-879
File diff suppressed because it is too large
Load Diff
@@ -319,15 +319,15 @@ THUMBNAIL_FOLDER = _get(_conf, ['upload', 'thumbnail_folder'], DEFAULTS['upload'
|
||||
PREVIEW_FOLDER = _get(_conf, ['upload', 'preview_folder'], DEFAULTS['upload']['preview_folder'])
|
||||
QR_CODE_FOLDER = _get(_conf, ['upload', 'qrcode_folder'], DEFAULTS['upload']['qrcode_folder'])
|
||||
|
||||
# Normalize to absolute paths to avoid cwd issues
|
||||
# This guarantees exact matching with Docker volume mounts
|
||||
if not os.path.isabs(UPLOAD_FOLDER):
|
||||
UPLOAD_FOLDER = os.path.join(BASE_DIR, os.path.relpath(UPLOAD_FOLDER, BASE_DIR))
|
||||
UPLOAD_FOLDER = os.path.abspath(os.path.join(BASE_DIR, "uploads"))
|
||||
if not os.path.isabs(THUMBNAIL_FOLDER):
|
||||
THUMBNAIL_FOLDER = os.path.join(BASE_DIR, os.path.relpath(THUMBNAIL_FOLDER, BASE_DIR))
|
||||
THUMBNAIL_FOLDER = os.path.abspath(os.path.join(BASE_DIR, "thumbnails"))
|
||||
if not os.path.isabs(PREVIEW_FOLDER):
|
||||
PREVIEW_FOLDER = os.path.join(BASE_DIR, os.path.relpath(PREVIEW_FOLDER, BASE_DIR))
|
||||
PREVIEW_FOLDER = os.path.abspath(os.path.join(BASE_DIR, "previews"))
|
||||
if not os.path.isabs(QR_CODE_FOLDER):
|
||||
QR_CODE_FOLDER = os.path.join(BASE_DIR, os.path.relpath(QR_CODE_FOLDER, BASE_DIR))
|
||||
QR_CODE_FOLDER = os.path.abspath(os.path.join(BASE_DIR, "QRCodes"))
|
||||
MAX_UPLOAD_MB = _get(_conf, ['upload', 'max_size_mb'], DEFAULTS['upload']['max_size_mb'])
|
||||
IMAGE_MAX_UPLOAD_MB = _get(_conf, ['upload', 'image_max_size_mb'], DEFAULTS['upload']['image_max_size_mb'])
|
||||
VIDEO_MAX_UPLOAD_MB = _get(_conf, ['upload', 'video_max_size_mb'], DEFAULTS['upload']['video_max_size_mb'])
|
||||
|
||||
@@ -54,10 +54,34 @@ def _clean_name_fragment(value):
|
||||
return cleaned
|
||||
|
||||
|
||||
def _get_tenant_db(client):
|
||||
def _get_tenant_db(client, tenant_id=None):
|
||||
"""Return the current tenant database for the request, or fall back to default."""
|
||||
try:
|
||||
from tenant import get_tenant_db
|
||||
if tenant_id is None:
|
||||
return get_tenant_db(client)
|
||||
|
||||
tenant_id = str(tenant_id).strip()
|
||||
if tenant_id:
|
||||
try:
|
||||
from tenant import get_tenant_config
|
||||
|
||||
config = get_tenant_config(tenant_id)
|
||||
if isinstance(config, dict):
|
||||
explicit_db = config.get('db') or config.get('db_name')
|
||||
if explicit_db:
|
||||
db_name = str(explicit_db).strip()
|
||||
if db_name and not db_name.startswith('inventar_'):
|
||||
db_name = f'inventar_{db_name}'
|
||||
if db_name:
|
||||
return client[db_name]
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
sanitized = ''.join(c for c in tenant_id.lower() if c.isalnum() or c == '_')
|
||||
if sanitized:
|
||||
return client[f'inventar_{sanitized}']
|
||||
|
||||
return get_tenant_db(client)
|
||||
except Exception:
|
||||
return client[cfg.MONGODB_DB]
|
||||
@@ -479,8 +503,45 @@ def check_nm_pwd(username, password):
|
||||
query = {'$or': [{'Username': username}, {'username': username}]}
|
||||
user_record_fallback = users.find_one(query)
|
||||
if user_record_fallback is None:
|
||||
logger.warning("Kein Benutzer für %r in DB %r gefunden.", dp.encrypt_text(username), db_name)
|
||||
return None
|
||||
if db_name != cfg.MONGODB_DB:
|
||||
default_users = client[cfg.MONGODB_DB]['users']
|
||||
user_record_fallback = default_users.find_one(
|
||||
{'$or': [
|
||||
{'Username': dp.encrypt_text(username)},
|
||||
{'username': dp.encrypt_text(username)},
|
||||
{'Username': username},
|
||||
{'username': username},
|
||||
]}
|
||||
)
|
||||
if user_record_fallback is not None:
|
||||
migrated_record = dict(user_record_fallback)
|
||||
migrated_record.pop('_id', None)
|
||||
users.replace_one(
|
||||
{'$or': [
|
||||
{'Username': migrated_record.get('Username')},
|
||||
{'username': migrated_record.get('username')},
|
||||
]},
|
||||
migrated_record,
|
||||
upsert=True,
|
||||
)
|
||||
logger.warning(
|
||||
"Tenant user %r migrated from default DB %r to tenant DB %r.",
|
||||
dp.encrypt_text(username),
|
||||
cfg.MONGODB_DB,
|
||||
db_name,
|
||||
)
|
||||
user_record = users.find_one(
|
||||
{'$or': [
|
||||
{'Username': migrated_record.get('Username')},
|
||||
{'username': migrated_record.get('username')},
|
||||
]}
|
||||
) or migrated_record
|
||||
else:
|
||||
logger.warning("Kein Benutzer für %r in DB %r gefunden.", dp.encrypt_text(username), db_name)
|
||||
return None
|
||||
else:
|
||||
logger.warning("Kein Benutzer für %r in DB %r gefunden.", dp.encrypt_text(username), db_name)
|
||||
return None
|
||||
else:
|
||||
user_record = user_record_fallback
|
||||
|
||||
@@ -497,6 +558,59 @@ def check_nm_pwd(username, password):
|
||||
finally:
|
||||
client.close()
|
||||
|
||||
def add_admin(
|
||||
username,
|
||||
password,
|
||||
name='',
|
||||
last_name='',
|
||||
is_student=False,
|
||||
permission_preset='full_access',
|
||||
action_permissions=None,
|
||||
page_permissions=None,
|
||||
tenant_id=None,
|
||||
):
|
||||
"""
|
||||
Add a new user to the database.
|
||||
"""
|
||||
if not check_password_strength(password):
|
||||
return False
|
||||
|
||||
client = MongoClient(cfg.MONGODB_HOST, cfg.MONGODB_PORT)
|
||||
try:
|
||||
db = _get_tenant_db(client, tenant_id)
|
||||
users = db['users']
|
||||
|
||||
permission_defaults = build_default_permission_payload(permission_preset)
|
||||
|
||||
if isinstance(action_permissions, dict):
|
||||
for key, value in action_permissions.items():
|
||||
permission_defaults['actions'][str(key)] = bool(value)
|
||||
|
||||
if isinstance(page_permissions, dict):
|
||||
for key, value in page_permissions.items():
|
||||
permission_defaults['pages'][str(key)] = bool(value)
|
||||
|
||||
safe_name = name.strip() if name else ''
|
||||
safe_last_name = last_name.strip() if last_name else ''
|
||||
|
||||
user_doc = {
|
||||
'Username': username,
|
||||
'Password': hashing(password),
|
||||
'Admin': True,
|
||||
'active_ausleihung': None,
|
||||
'name': dp.encrypt_text(safe_name) if safe_name else '',
|
||||
'last_name': dp.encrypt_text(safe_last_name) if safe_last_name else '',
|
||||
'IsStudent': bool(is_student),
|
||||
'PermissionPreset': permission_defaults['preset'],
|
||||
'ActionPermissions': permission_defaults['actions'],
|
||||
'PagePermissions': permission_defaults['pages'],
|
||||
}
|
||||
|
||||
users.insert_one(user_doc)
|
||||
return True
|
||||
finally:
|
||||
client.close()
|
||||
|
||||
|
||||
def add_user(
|
||||
username,
|
||||
@@ -509,6 +623,7 @@ def add_user(
|
||||
permission_preset='standard_user',
|
||||
action_permissions=None,
|
||||
page_permissions=None,
|
||||
tenant_id=None,
|
||||
):
|
||||
"""
|
||||
Add a new user to the database.
|
||||
@@ -518,7 +633,7 @@ def add_user(
|
||||
|
||||
client = MongoClient(cfg.MONGODB_HOST, cfg.MONGODB_PORT)
|
||||
try:
|
||||
db = _get_tenant_db(client)
|
||||
db = _get_tenant_db(client, tenant_id)
|
||||
users = db['users']
|
||||
|
||||
permission_defaults = build_default_permission_payload(permission_preset)
|
||||
|
||||
@@ -17,4 +17,5 @@ cryptography>=42.0.0
|
||||
pywebpush
|
||||
py-vapid>=1.9.0
|
||||
beautifulsoup4
|
||||
pywebpush
|
||||
pywebpush
|
||||
pandas
|
||||
@@ -7,7 +7,7 @@
|
||||
<div style="display:flex; justify-content:space-between; align-items:flex-start; gap:12px; flex-wrap:wrap; margin-bottom:16px;">
|
||||
<div>
|
||||
<h1 style="margin:0;">Defekte Items</h1>
|
||||
<p style="margin:6px 0 0; color:#64748b;">Eigenes Verwaltungsfenster fuer gemeldete Defekte mit schneller Reparatur-Funktion.</p>
|
||||
<p style="margin:6px 0 0; color:#64748b;">Eigenes Verwaltungsfenster für gemeldete Defekte mit schneller Reparatur-Funktion.</p>
|
||||
</div>
|
||||
<div style="display:flex; gap:8px; flex-wrap:wrap;">
|
||||
<a class="btn btn-outline-secondary" href="{{ url_for('admin_borrowings') }}">Ausleihen</a>
|
||||
@@ -42,7 +42,13 @@
|
||||
{% if item.isbn %}<div style="font-size:0.82rem; color:#64748b;">ISBN: {{ item.isbn }}</div>{% endif %}
|
||||
</td>
|
||||
<td style="padding:11px; border-bottom:1px solid #eef2f7; vertical-align:top;">
|
||||
<div style="display:inline-block; padding:3px 9px; border-radius:999px; background:#fee2e2; color:#991b1b; font-size:0.75rem; font-weight:700;">Defekt</div>
|
||||
|
||||
<!-- HIER IST DIE ÄNDERUNG: Dynamischer Status-Badge -->
|
||||
<div class="badge bg-{{ item.status_color }} rounded-pill" style="font-size:0.75rem; font-weight:700; padding:4px 10px;">
|
||||
{{ item.status_text }}
|
||||
</div>
|
||||
<!-- ENDE DER ÄNDERUNG -->
|
||||
|
||||
<div style="font-size:0.84rem; color:#475569; margin-top:6px;">Meldungen: {{ item.damage_count }}</div>
|
||||
<div style="font-size:0.84rem; color:#475569;">Condition: {{ item.condition or '-' }}</div>
|
||||
<div style="font-size:0.84rem; color:#475569;">Verfuegbar: {{ 'Ja' if item.available else 'Nein' }}</div>
|
||||
@@ -66,7 +72,12 @@
|
||||
{% endif %}
|
||||
</td>
|
||||
<td style="padding:11px; border-bottom:1px solid #eef2f7; vertical-align:top;">
|
||||
<!-- Button wird ausgeblendet, falls das Item bereits repariert ist -->
|
||||
{% if item.condition not in ['repaired', 'fixed'] %}
|
||||
<button class="btn btn-success btn-sm" onclick="repairDamage('{{ item.id }}', this)">Als repariert markieren</button>
|
||||
{% else %}
|
||||
<span class="text-success" style="font-size: 0.85rem;"><i class="bi bi-check-circle"></i> Repariert</span>
|
||||
{% endif %}
|
||||
</td>
|
||||
</tr>
|
||||
{% endfor %}
|
||||
@@ -118,4 +129,4 @@ function repairDamage(itemId, button) {
|
||||
});
|
||||
}
|
||||
</script>
|
||||
{% endblock %}
|
||||
{% endblock %}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -4569,12 +4569,7 @@ document.addEventListener('DOMContentLoaded', ()=>{
|
||||
<div class="detail-label">Code:</div>
|
||||
<div class="detail-value">${escapeHtml(item.Code_4 || '-')}</div>
|
||||
</div>
|
||||
|
||||
<div class="detail-group">
|
||||
<div class="detail-label">Anzahl:</div>
|
||||
<div class="detail-value">${escapeHtml(String(item.GroupedDisplayCount || 1))}</div>
|
||||
</div>
|
||||
|
||||
|
||||
${isGroupedItem ? `
|
||||
<div class="detail-group">
|
||||
<div class="detail-label">Verfügbar:</div>
|
||||
|
||||
@@ -229,7 +229,7 @@
|
||||
<div class="container">
|
||||
<div class="student-card-header">
|
||||
<div>
|
||||
<h1>📚 Bibliotheksausweise (Bibliotek)</h1>
|
||||
<h1>📚 Bibliotheksausweise (Bibliothek)</h1>
|
||||
</div>
|
||||
<div class="export-buttons">
|
||||
<a href="{{ url_for('student_card_barcode_download') }}" class="btn-print" style="background: #28a745;">📥 Alle Ausweise (PDF)</a>
|
||||
|
||||
@@ -280,7 +280,7 @@
|
||||
<button type="button" data-target-step="0">1. Startseite</button>
|
||||
<button type="button" data-target-step="1">2. {{ 'Artikel erfassen' if is_admin else 'Artikel finden' }}</button>
|
||||
{% if library_module_enabled %}
|
||||
<button type="button" data-target-step="2">3. Bibliotek</button>
|
||||
<button type="button" data-target-step="2">3. Bibliothek</button>
|
||||
{% endif %}
|
||||
<button type="button" data-target-step="{{ '3' if library_module_enabled else '2' }}">4. Alltag</button>
|
||||
</div>
|
||||
@@ -341,7 +341,7 @@
|
||||
|
||||
{% if library_module_enabled %}
|
||||
<article class="workflow-step" data-step-index="2" data-step-key="library">
|
||||
<h3>Bibliotek-Bereich</h3>
|
||||
<h3>Bibliothek-Bereich</h3>
|
||||
<p>Dieser Bereich ist speziell für Bücher und Medienausleihe.</p>
|
||||
<ul>
|
||||
{% if is_admin %}
|
||||
@@ -358,7 +358,7 @@
|
||||
</ul>
|
||||
|
||||
<div class="tutorial-actions">
|
||||
<a class="btn btn-outline-primary btn-sm" href="{{ url_for('library_view') }}">Zur Bibliotek</a>
|
||||
<a class="btn btn-outline-primary btn-sm" href="{{ url_for('library_view') }}">Zur Bibliothek</a>
|
||||
{% if is_admin %}
|
||||
<a class="btn btn-outline-secondary btn-sm" href="{{ url_for('library_loans_admin') }}">Ausleihen ansehen</a>
|
||||
{% endif %}
|
||||
|
||||
@@ -0,0 +1,262 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="de">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Batch Upload</title>
|
||||
|
||||
<!-- CSRF-Token für JavaScript bereitstellen -->
|
||||
<meta name="csrf-token" content="{{ session.get('_csrf_token', '') }}">
|
||||
|
||||
<style>
|
||||
body { font-family: sans-serif; padding: 20px; background: #f4f7f6; }
|
||||
.upload-container { background: white; padding: 20px; border-radius: 8px; max-width: 500px; margin: 0 auto; }
|
||||
.form-group { margin-bottom: 15px; }
|
||||
label { display: block; font-weight: bold; margin-bottom: 5px; }
|
||||
input[type="file"] { width: 100%; padding: 8px; box-sizing: border-box; }
|
||||
.btn-submit { width: 100%; padding: 10px; background: #4a90e2; color: white; border: none; border-radius: 4px; font-weight: bold; cursor: pointer; }
|
||||
.btn-submit:disabled { background: #ccc; }
|
||||
#uploadProgress { margin-top: 20px; display: none; }
|
||||
progress { width: 100%; height: 20px; }
|
||||
#logList { background: #fafafa; border: 1px solid #eee; padding: 10px; max-height: 150px; overflow-y: auto; font-size: 0.85em; list-style: none; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="upload-container">
|
||||
<h2>Inventar Batch Upload</h2>
|
||||
|
||||
<form id="batchUploadForm">
|
||||
<div class="form-group">
|
||||
<label for="csv_file">1. items.csv auswählen</label>
|
||||
<input type="file" id="csv_file" name="csv_file" accept=".csv" required>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<label for="images">2. Bilder auswählen</label>
|
||||
<input type="file" id="images" name="images" accept="image/*" multiple required>
|
||||
</div>
|
||||
|
||||
<button type="submit" id="uploadBtn" class="btn-submit">Daten hochladen</button>
|
||||
</form>
|
||||
|
||||
<div id="uploadProgress">
|
||||
<div id="progressText">Bereite Upload vor...</div>
|
||||
<progress id="progressBar" value="0" max="100"></progress>
|
||||
<ul id="logList"></ul>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script>
|
||||
// 1. Robuster CSV-Parser, der Zeilenumbrüche und Kommas in Texten korrekt ignoriert
|
||||
function parseCSV(csvString) {
|
||||
const rows = [];
|
||||
let currentRow = [];
|
||||
let currentCell = '';
|
||||
let insideQuotes = false;
|
||||
|
||||
for (let i = 0; i < csvString.length; i++) {
|
||||
const char = csvString[i];
|
||||
const nextChar = csvString[i + 1];
|
||||
|
||||
if (char === '"' && insideQuotes && nextChar === '"') {
|
||||
currentCell += '"';
|
||||
i++; // Escaped Quotes ("") überspringen
|
||||
} else if (char === '"') {
|
||||
insideQuotes = !insideQuotes;
|
||||
} else if (char === ',' && !insideQuotes) {
|
||||
currentRow.push(currentCell);
|
||||
currentCell = '';
|
||||
} else if ((char === '\n' || char === '\r') && !insideQuotes) {
|
||||
if (char === '\r' && nextChar === '\n') i++; // Windows Umbrüche überspringen
|
||||
currentRow.push(currentCell);
|
||||
if (currentRow.length > 1 || currentRow[0] !== '') {
|
||||
rows.push(currentRow);
|
||||
}
|
||||
currentRow = [];
|
||||
currentCell = '';
|
||||
} else {
|
||||
currentCell += char;
|
||||
}
|
||||
}
|
||||
if (currentCell !== '' || currentRow.length > 0) {
|
||||
currentRow.push(currentCell);
|
||||
if (currentRow.length > 1 || currentRow[0] !== '') {
|
||||
rows.push(currentRow);
|
||||
}
|
||||
}
|
||||
return rows;
|
||||
}
|
||||
|
||||
// 2. Baut das Array wieder sicher zu einer sauberen CSV-Zeile für das Backend zusammen
|
||||
function rowToCSV(rowArray) {
|
||||
return rowArray.map(cell => {
|
||||
if (cell === null || cell === undefined) return '';
|
||||
let cellStr = String(cell);
|
||||
if (cellStr.includes(',') || cellStr.includes('"') || cellStr.includes('\n') || cellStr.includes('\r')) {
|
||||
return '"' + cellStr.replace(/"/g, '""') + '"';
|
||||
}
|
||||
return cellStr;
|
||||
}).join(',');
|
||||
}
|
||||
|
||||
// 3. Bildnamen extrahieren
|
||||
function extractImageNames(cellValue) {
|
||||
if (!cellValue) return [];
|
||||
let raw = String(cellValue).replace(/^["']|["']$/g, '').trim();
|
||||
if (raw.startsWith('[') && raw.endsWith(']')) {
|
||||
try {
|
||||
const jsonValid = raw.replace(/'/g, '"');
|
||||
return JSON.parse(jsonValid);
|
||||
} catch (e) {
|
||||
const matches = raw.match(/['"]([^'"]+)['"]/g);
|
||||
if (matches) return matches.map(m => m.replace(/['"]/g, ''));
|
||||
}
|
||||
}
|
||||
return raw ? [raw] : [];
|
||||
}
|
||||
|
||||
document.getElementById('batchUploadForm').addEventListener('submit', async function(e) {
|
||||
e.preventDefault();
|
||||
|
||||
const csvInput = document.getElementById('csv_file');
|
||||
const imageInput = document.getElementById('images');
|
||||
const uploadBtn = document.getElementById('uploadBtn');
|
||||
const progressContainer = document.getElementById('uploadProgress');
|
||||
const progressBar = document.getElementById('progressBar');
|
||||
const progressText = document.getElementById('progressText');
|
||||
const logList = document.getElementById('logList');
|
||||
|
||||
const csrfToken = document.querySelector('meta[name="csrf-token"]')?.getAttribute('content');
|
||||
|
||||
if (!csvInput.files.length) {
|
||||
alert("Bitte wähle eine CSV-Datei aus.");
|
||||
return;
|
||||
}
|
||||
|
||||
uploadBtn.disabled = true;
|
||||
progressContainer.style.display = 'block';
|
||||
logList.innerHTML = '';
|
||||
|
||||
const log = (msg) => {
|
||||
const li = document.createElement('li');
|
||||
li.textContent = msg;
|
||||
logList.appendChild(li);
|
||||
logList.scrollTop = logList.scrollHeight;
|
||||
};
|
||||
|
||||
const csvFile = csvInput.files[0];
|
||||
const allImages = Array.from(imageInput.files);
|
||||
|
||||
const imageMap = new Map();
|
||||
allImages.forEach(file => {
|
||||
imageMap.set(file.name.toLowerCase(), file);
|
||||
});
|
||||
|
||||
const BATCH_SIZE = 20;
|
||||
|
||||
try {
|
||||
const csvText = await csvFile.text();
|
||||
const allRows = parseCSV(csvText);
|
||||
|
||||
if (allRows.length <= 1) {
|
||||
throw new Error("CSV-Datei ist leer oder enthält nur Kopfzeilen.");
|
||||
}
|
||||
|
||||
const headerRow = allRows[0];
|
||||
const dataRows = allRows.slice(1);
|
||||
|
||||
log(`${dataRows.length} Einträge gefunden. Bereite Batches vor...`);
|
||||
|
||||
const imagesColIndex = headerRow.findIndex(h => h.toLowerCase().trim() === 'images');
|
||||
|
||||
const batches = [];
|
||||
for (let i = 0; i < dataRows.length; i += BATCH_SIZE) {
|
||||
batches.push(dataRows.slice(i, i + BATCH_SIZE));
|
||||
}
|
||||
|
||||
progressBar.max = batches.length;
|
||||
progressBar.value = 0;
|
||||
|
||||
// Sequenzieller Upload mit Fehlertoleranz pro Batch
|
||||
for (let b = 0; b < batches.length; b++) {
|
||||
const batchRows = batches[b];
|
||||
progressText.textContent = `Lade Batch ${b + 1} von ${batches.length} hoch...`;
|
||||
|
||||
try {
|
||||
const requiredImagesForBatch = new Set();
|
||||
|
||||
if (imagesColIndex !== -1) {
|
||||
batchRows.forEach(rowCols => {
|
||||
if (rowCols[imagesColIndex]) {
|
||||
const imgNames = extractImageNames(rowCols[imagesColIndex]);
|
||||
imgNames.forEach(name => {
|
||||
const fileMatch = imageMap.get(name.toLowerCase());
|
||||
if (fileMatch) {
|
||||
requiredImagesForBatch.add(fileMatch);
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
const batchCsvArray = [headerRow, ...batchRows];
|
||||
const batchCsvText = batchCsvArray.map(rowToCSV).join('\n');
|
||||
const batchCsvBlob = new Blob([batchCsvText], { type: 'text/csv' });
|
||||
|
||||
const formData = new FormData();
|
||||
formData.append('csv_file', batchCsvBlob, `batch_${b + 1}.csv`);
|
||||
|
||||
if (csrfToken) {
|
||||
formData.append('csrf_token', csrfToken);
|
||||
}
|
||||
|
||||
requiredImagesForBatch.forEach(imgFile => {
|
||||
formData.append('images', imgFile);
|
||||
});
|
||||
|
||||
log(`Batch ${b + 1}: ${batchRows.length} Items & ${requiredImagesForBatch.size} zugehörige Bilder.`);
|
||||
|
||||
const response = await fetch('/upload_csv_batch', {
|
||||
method: 'POST',
|
||||
body: formData,
|
||||
headers: {
|
||||
'X-CSRFToken': csrfToken || ''
|
||||
}
|
||||
});
|
||||
|
||||
const responseText = await response.text();
|
||||
let result;
|
||||
|
||||
try {
|
||||
result = JSON.parse(responseText);
|
||||
} catch (parseErr) {
|
||||
throw new Error(`Server-Fehler (Status ${response.status}). HTML statt JSON erhalten.`);
|
||||
}
|
||||
|
||||
if (!response.ok || !result.success) {
|
||||
throw new Error(result.message || `Server-Fehler ${response.status}`);
|
||||
}
|
||||
|
||||
log(`Batch ${b + 1} erfolgreich abgeschlossen.`);
|
||||
|
||||
} catch (batchErr) {
|
||||
log(`⚠️ FEHLER in Batch ${b + 1}: ${batchErr.message}. Überspringe und fahre fort...`);
|
||||
console.error(`Batch ${b + 1} fehlgeschlagen:`, batchErr);
|
||||
}
|
||||
|
||||
progressBar.value = b + 1;
|
||||
}
|
||||
|
||||
progressText.textContent = "Upload-Prozess beendet!";
|
||||
uploadBtn.disabled = false;
|
||||
|
||||
} catch (err) {
|
||||
alert("Upload abgebrochen: " + err.message);
|
||||
log("Fehler: " + err.message);
|
||||
uploadBtn.disabled = false;
|
||||
}
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
+35
-17
@@ -166,6 +166,11 @@ def _find_registered_tenant_id(candidate):
|
||||
return None
|
||||
|
||||
|
||||
def _resolve_registered_tenant_id(candidate):
|
||||
"""Return the canonical registered tenant id for a candidate, or None."""
|
||||
return _find_registered_tenant_id(candidate)
|
||||
|
||||
|
||||
def _is_ip_host(hostname):
|
||||
hostname = str(hostname or '').strip()
|
||||
if not hostname:
|
||||
@@ -185,6 +190,8 @@ def get_tenant_config(tenant_id=None):
|
||||
ctx = get_tenant_context()
|
||||
tenant_id = ctx.tenant_id if ctx and ctx.tenant_id else 'default'
|
||||
|
||||
tenant_id = _resolve_registered_tenant_id(tenant_id) or tenant_id
|
||||
|
||||
if tenant_id in TENANT_REGISTRY:
|
||||
return TENANT_REGISTRY[tenant_id] or {}
|
||||
|
||||
@@ -481,20 +488,22 @@ class TenantContext:
|
||||
or request.args.get('tenantId', '').strip()
|
||||
)
|
||||
if tenant_from_query:
|
||||
matched_tenant = _find_registered_tenant_id(tenant_from_query) or tenant_from_query
|
||||
self.tenant_id = matched_tenant
|
||||
self.config = get_tenant_config(matched_tenant)
|
||||
session['tenant_id'] = matched_tenant
|
||||
return self._get_db_name(matched_tenant)
|
||||
matched_tenant = _resolve_registered_tenant_id(tenant_from_query)
|
||||
if matched_tenant:
|
||||
self.tenant_id = matched_tenant
|
||||
self.config = get_tenant_config(matched_tenant)
|
||||
session['tenant_id'] = matched_tenant
|
||||
return self._get_db_name(matched_tenant)
|
||||
|
||||
# Priority 1: X-Tenant-ID header (for testing/internal APIs)
|
||||
tenant_from_header = request.headers.get('X-Tenant-ID', '').strip()
|
||||
if tenant_from_header:
|
||||
matched_tenant = _find_registered_tenant_id(tenant_from_header) or tenant_from_header
|
||||
self.tenant_id = matched_tenant
|
||||
self.config = get_tenant_config(matched_tenant)
|
||||
session['tenant_id'] = matched_tenant
|
||||
return self._get_db_name(matched_tenant)
|
||||
matched_tenant = _resolve_registered_tenant_id(tenant_from_header)
|
||||
if matched_tenant:
|
||||
self.tenant_id = matched_tenant
|
||||
self.config = get_tenant_config(matched_tenant)
|
||||
session['tenant_id'] = matched_tenant
|
||||
return self._get_db_name(matched_tenant)
|
||||
|
||||
# Priority 2: Port/host based tenant mapping
|
||||
host_candidates = _request_host_candidates()
|
||||
@@ -544,11 +553,11 @@ class TenantContext:
|
||||
if len(parts) >= 2:
|
||||
potential_subdomain = parts[0]
|
||||
if potential_subdomain not in ('www', 'api', 'admin', 'app', 'mail'):
|
||||
matched_tenant = _find_registered_tenant_id(potential_subdomain)
|
||||
matched_tenant = _resolve_registered_tenant_id(potential_subdomain)
|
||||
if not matched_tenant and potential_subdomain.startswith('school'):
|
||||
matched_tenant = _find_registered_tenant_id('schule' + potential_subdomain[len('school'):])
|
||||
matched_tenant = _resolve_registered_tenant_id('schule' + potential_subdomain[len('school'):])
|
||||
elif not matched_tenant and potential_subdomain.startswith('schule'):
|
||||
matched_tenant = _find_registered_tenant_id('school' + potential_subdomain[len('schule'):])
|
||||
matched_tenant = _resolve_registered_tenant_id('school' + potential_subdomain[len('schule'):])
|
||||
if matched_tenant:
|
||||
self.subdomain = potential_subdomain
|
||||
self.tenant_id = matched_tenant
|
||||
@@ -565,12 +574,21 @@ class TenantContext:
|
||||
# Priority 4: sticky tenant from the authenticated session
|
||||
session_tenant = session.get('tenant_id', '').strip() if session.get('tenant_id') else ''
|
||||
if session_tenant:
|
||||
self.tenant_id = session_tenant
|
||||
self.config = get_tenant_config(session_tenant)
|
||||
matched_tenant = _resolve_registered_tenant_id(session_tenant)
|
||||
if matched_tenant:
|
||||
self.tenant_id = matched_tenant
|
||||
self.config = get_tenant_config(matched_tenant)
|
||||
session['tenant_id'] = matched_tenant
|
||||
logger.info(
|
||||
f"Tenant resolution by session: host={primary_host} tenant={matched_tenant} config={self.config}"
|
||||
)
|
||||
return self._get_db_name(matched_tenant)
|
||||
session.pop('tenant_id', None)
|
||||
logger.info(
|
||||
f"Tenant resolution by session: host={primary_host} tenant={session_tenant} config={self.config}"
|
||||
"Discarded stale tenant session reference: host=%s tenant=%s",
|
||||
primary_host,
|
||||
session_tenant,
|
||||
)
|
||||
return self._get_db_name(session_tenant)
|
||||
|
||||
# Fallback to default tenant if no tenant identifier found.
|
||||
# If no explicit 'default' tenant config exists, use configured MongoDB DB.
|
||||
|
||||
+308
-89
@@ -12,6 +12,250 @@ fi
|
||||
# Resolve script directory so config paths are deterministic even when called via sudo
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
CONFIG_FILE="$SCRIPT_DIR/config.json"
|
||||
NGINX_DOMAIN_BASE="${INVENTAR_TENANT_DOMAIN_BASE:-invario-software.de}"
|
||||
NGINX_PROXY_HOST="${INVENTAR_NGINX_PROXY_HOST:-172.17.0.1}"
|
||||
NGINX_SITES_AVAILABLE="${INVENTAR_NGINX_SITES_AVAILABLE:-/etc/nginx/sites-available}"
|
||||
NGINX_SITES_ENABLED="${INVENTAR_NGINX_SITES_ENABLED:-/etc/nginx/sites-enabled}"
|
||||
NGINX_SITE_PREFIX="${INVENTAR_NGINX_SITE_PREFIX:-inventarsystem}"
|
||||
CERTBOT_EMAIL="${INVENTAR_CERTBOT_EMAIL:-}"
|
||||
|
||||
tenant_domain() {
|
||||
printf '%s.%s' "$1" "$NGINX_DOMAIN_BASE"
|
||||
}
|
||||
|
||||
tenant_nginx_site_path() {
|
||||
printf '%s/%s-%s.conf' "$NGINX_SITES_AVAILABLE" "$NGINX_SITE_PREFIX" "$1"
|
||||
}
|
||||
|
||||
tenant_nginx_enabled_path() {
|
||||
printf '%s/%s-%s.conf' "$NGINX_SITES_ENABLED" "$NGINX_SITE_PREFIX" "$1"
|
||||
}
|
||||
|
||||
run_host_command() {
|
||||
if [ "$(id -u)" -eq 0 ]; then
|
||||
"$@"
|
||||
elif command -v sudo >/dev/null 2>&1; then
|
||||
sudo "$@"
|
||||
else
|
||||
return 127
|
||||
fi
|
||||
}
|
||||
|
||||
reload_host_nginx() {
|
||||
if command -v nginx >/dev/null 2>&1 || command -v sudo >/dev/null 2>&1; then
|
||||
if ! run_host_command nginx -t; then
|
||||
echo "Warning: nginx configuration test failed; skipping reload."
|
||||
return 1
|
||||
fi
|
||||
|
||||
if command -v systemctl >/dev/null 2>&1; then
|
||||
if ! run_host_command systemctl reload nginx; then
|
||||
echo "Warning: systemctl reload nginx failed."
|
||||
return 1
|
||||
fi
|
||||
else
|
||||
if ! run_host_command nginx -s reload; then
|
||||
echo "Warning: nginx reload failed."
|
||||
return 1
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
write_tenant_nginx_config() {
|
||||
local tenant_id="$1"
|
||||
local port="$2"
|
||||
local domain site_path enabled_path
|
||||
|
||||
domain="$(tenant_domain "$tenant_id")"
|
||||
site_path="$(tenant_nginx_site_path "$tenant_id")"
|
||||
enabled_path="$(tenant_nginx_enabled_path "$tenant_id")"
|
||||
|
||||
if [ -z "$port" ]; then
|
||||
echo "Warning: No port configured for tenant '$tenant_id'; skipping nginx vhost creation."
|
||||
return 0
|
||||
fi
|
||||
|
||||
if ! run_host_command mkdir -p "$NGINX_SITES_AVAILABLE" "$NGINX_SITES_ENABLED"; then
|
||||
echo "Warning: Unable to prepare nginx site directories; skipping reverse-proxy setup."
|
||||
return 0
|
||||
fi
|
||||
|
||||
local have_cert=false
|
||||
|
||||
if [ -f "/etc/letsencrypt/live/$domain/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$domain/privkey.pem" ]; then
|
||||
have_cert=true
|
||||
else
|
||||
if [ "$(id -u)" -eq 0 ]; then
|
||||
cat > "$site_path" <<EOF
|
||||
# ==========================================
|
||||
# INVENTARSYSTEM ($tenant_id)
|
||||
# ==========================================
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name $domain;
|
||||
client_max_body_size 100M;
|
||||
|
||||
location / {
|
||||
proxy_pass http://$NGINX_PROXY_HOST:$port;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
else
|
||||
sudo tee "$site_path" >/dev/null <<EOF
|
||||
# ==========================================
|
||||
# INVENTARSYSTEM ($tenant_id)
|
||||
# ==========================================
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name $domain;
|
||||
client_max_body_size 100M;
|
||||
|
||||
location / {
|
||||
proxy_pass http://$NGINX_PROXY_HOST:$port;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
fi
|
||||
|
||||
if ! run_host_command ln -sfn "$site_path" "$enabled_path"; then
|
||||
echo "Warning: Could not enable nginx site for tenant '$tenant_id'."
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! reload_host_nginx; then
|
||||
echo "Warning: Initial nginx reload failed for tenant '$tenant_id'."
|
||||
fi
|
||||
|
||||
if command -v certbot >/dev/null 2>&1 || command -v sudo >/dev/null 2>&1; then
|
||||
local certbot_args=(certbot --nginx --non-interactive --agree-tos -d "$domain")
|
||||
if [ -n "$CERTBOT_EMAIL" ]; then
|
||||
certbot_args+=(--email "$CERTBOT_EMAIL")
|
||||
else
|
||||
certbot_args+=(--register-unsafely-without-email)
|
||||
fi
|
||||
|
||||
if ! run_host_command "${certbot_args[@]}"; then
|
||||
echo "Warning: certbot failed for tenant '$tenant_id'; keeping HTTP-only vhost for now."
|
||||
return 1
|
||||
fi
|
||||
|
||||
have_cert=true
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "$have_cert" != true ]; then
|
||||
echo "Warning: No TLS certificate available for tenant '$tenant_id'; leaving HTTP-only nginx config in place."
|
||||
return 1
|
||||
fi
|
||||
|
||||
if [ "$(id -u)" -eq 0 ]; then
|
||||
cat > "$site_path" <<EOF
|
||||
# ==========================================
|
||||
# INVENTARSYSTEM ($tenant_id)
|
||||
# ==========================================
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name $domain;
|
||||
client_max_body_size 100M;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/$domain/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/$domain/privkey.pem;
|
||||
|
||||
location / {
|
||||
proxy_pass http://$NGINX_PROXY_HOST:$port;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
}
|
||||
}
|
||||
|
||||
# Gezielte HTTP zu HTTPS Weiterleitung für $tenant_id
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name $domain;
|
||||
return 301 https://$domain\$request_uri;
|
||||
}
|
||||
EOF
|
||||
else
|
||||
sudo tee "$site_path" >/dev/null <<EOF
|
||||
# ==========================================
|
||||
# INVENTARSYSTEM ($tenant_id)
|
||||
# ==========================================
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name $domain;
|
||||
client_max_body_size 100M;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/$domain/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/$domain/privkey.pem;
|
||||
|
||||
location / {
|
||||
proxy_pass http://$NGINX_PROXY_HOST:$port;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
}
|
||||
}
|
||||
|
||||
# Gezielte HTTP zu HTTPS Weiterleitung für $tenant_id
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name $domain;
|
||||
return 301 https://$domain\$request_uri;
|
||||
}
|
||||
EOF
|
||||
fi
|
||||
|
||||
if ! run_host_command ln -sfn "$site_path" "$enabled_path"; then
|
||||
echo "Warning: Could not enable nginx site for tenant '$tenant_id'."
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! reload_host_nginx; then
|
||||
echo "Warning: nginx reload after tenant '$tenant_id' configuration update failed."
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
remove_tenant_nginx_config() {
|
||||
local tenant_id="$1"
|
||||
local domain site_path enabled_path
|
||||
|
||||
domain="$(tenant_domain "$tenant_id")"
|
||||
site_path="$(tenant_nginx_site_path "$tenant_id")"
|
||||
enabled_path="$(tenant_nginx_enabled_path "$tenant_id")"
|
||||
|
||||
if [ -f "$enabled_path" ] || [ -L "$enabled_path" ]; then
|
||||
run_host_command rm -f "$enabled_path" || true
|
||||
fi
|
||||
|
||||
if [ -f "$site_path" ]; then
|
||||
run_host_command rm -f "$site_path" || true
|
||||
fi
|
||||
|
||||
if command -v certbot >/dev/null 2>&1 || command -v sudo >/dev/null 2>&1; then
|
||||
run_host_command certbot delete --cert-name "$domain" --non-interactive >/dev/null 2>&1 || true
|
||||
fi
|
||||
|
||||
reload_host_nginx || true
|
||||
}
|
||||
|
||||
ensure_runtime_config_json() {
|
||||
local config_path backup_path
|
||||
@@ -201,65 +445,35 @@ sys.path.insert(0, "/app/Web")
|
||||
from Web.modules.database import settings
|
||||
from pymongo import MongoClient
|
||||
import Web.modules.inventarsystem.data_protection as dp
|
||||
import Web.modules.database.user as us
|
||||
|
||||
tenant_id = sys.argv[1].lower()
|
||||
mode = sys.argv[2]
|
||||
sanitized = "".join(c for c in tenant_id if c.isalnum() or c == "_")
|
||||
db_name = f"inventar_{sanitized}"
|
||||
client = MongoClient(settings.MONGODB_HOST, int(settings.MONGODB_PORT))
|
||||
db_name = f"inventar_{sanitized}" if sanitized else settings.MONGODB_DB
|
||||
|
||||
client = MongoClient(settings.MONGODB_HOST, settings.MONGODB_PORT)
|
||||
db = client[db_name]
|
||||
|
||||
pw_bytes = "admin123".encode("utf-8")
|
||||
random_salt = os.urandom(16)
|
||||
hashed = hashlib.scrypt(pw_bytes, salt=random_salt, n=16384, r=8, p=1)
|
||||
hashed_pw_string = f"v1${random_salt.hex()}${hashed.hex()}"
|
||||
|
||||
action_permissions = {
|
||||
"can_borrow": True,
|
||||
"can_insert": True,
|
||||
"can_edit": True,
|
||||
"can_delete": True,
|
||||
"can_manage_users": True,
|
||||
"can_manage_settings": True,
|
||||
"can_view_logs": True,
|
||||
users = db["users"]
|
||||
permission_defaults = us.build_default_permission_payload("full_access")
|
||||
admin_doc = {
|
||||
"Username": "admin",
|
||||
"Password": us.hashing("admin123"),
|
||||
"Admin": True,
|
||||
"active_ausleihung": None,
|
||||
"name": dp.encrypt_text("admin"),
|
||||
"last_name": dp.encrypt_text("admin"),
|
||||
"IsStudent": False,
|
||||
"PermissionPreset": permission_defaults["preset"],
|
||||
"ActionPermissions": permission_defaults["actions"],
|
||||
"PagePermissions": permission_defaults["pages"],
|
||||
}
|
||||
|
||||
page_permissions = {
|
||||
"home": True,
|
||||
"tutorial_page": True,
|
||||
"my_borrowed_items": True,
|
||||
"notifications_view": True,
|
||||
"impressum": True,
|
||||
"license": True,
|
||||
"library_view": True,
|
||||
"terminplan": True,
|
||||
"home_admin": True,
|
||||
"upload_admin": True,
|
||||
"library_admin": True,
|
||||
"admin_borrowings": True,
|
||||
"library_loans_admin": True,
|
||||
"admin_damaged_items": True,
|
||||
"admin_audit_dashboard": True,
|
||||
"logs": True,
|
||||
"manage_filters": True,
|
||||
"manage_locations": True,
|
||||
}
|
||||
|
||||
if db.users.count_documents({"Username": dp.encrypt_text("admin")}) == 0:
|
||||
db.users.insert_one({
|
||||
"Username": dp.encrypt_text("admin"),
|
||||
"Password": hashed_pw_string,
|
||||
"Admin": True,
|
||||
"active_ausleihung": None,
|
||||
"name": dp.encrypt_text("Admin"),
|
||||
"last_name": dp.encrypt_text("User"),
|
||||
"IsStudent": False,
|
||||
"PermissionPreset": "full_access",
|
||||
"ActionPermissions": action_permissions,
|
||||
"PagePermissions": page_permissions,
|
||||
})
|
||||
users.replace_one({"Username": "admin"}, admin_doc, upsert=True)
|
||||
print("Fallback successfully applied")
|
||||
|
||||
if mode == "trial":
|
||||
client = MongoClient(settings.MONGODB_HOST, settings.MONGODB_PORT)
|
||||
db = client[db_name]
|
||||
db.settings.update_one(
|
||||
{"setting_type": "tenant_trial"},
|
||||
{"$set": {
|
||||
@@ -272,6 +486,8 @@ if mode == "trial":
|
||||
upsert=True,
|
||||
)
|
||||
|
||||
client.close()
|
||||
|
||||
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / admin123")
|
||||
PY
|
||||
}
|
||||
@@ -533,15 +749,18 @@ ${YELLOW}Nutzung:${RESET} $0 <befehl> [tenant_id] [optionen]
|
||||
|
||||
${BLUE}${BOLD}VERFÜGBARE BEFEHLE:${RESET}
|
||||
${GREEN}add${RESET} <tenant_id> [port]
|
||||
Legt einen neuen Tenant an, registriert den Port und initialisiert
|
||||
die MongoDB-Datenbank mit einem Standard-Admin (${YELLOW}admin / admin123${RESET}).
|
||||
Legt einen neuen Tenant an, registriert den Port, richtet den nginx-Host
|
||||
für ${YELLOW}<tenant_id>.invario-software.de${RESET} ein und initialisiert
|
||||
die MongoDB-Datenbank mit einem Standard-Admin (${YELLOW}admin / admin123${RESET}).
|
||||
|
||||
${GREEN}trial${RESET} <tenant_id> [port] [tage]
|
||||
Erstellt einen temporären Test-Tenant. Standardlaufzeit: 7 Tage.
|
||||
Läuft automatisch ab und löscht sich selbst.
|
||||
Läuft automatisch ab, löscht sich selbst und bekommt die gleiche nginx/
|
||||
Certbot-Anbindung wie ein normaler Tenant.
|
||||
|
||||
${GREEN}remove${RESET} [-y|--yes] <tenant_id>
|
||||
Löscht einen Tenant, seine Konfiguration, Ports und die Datenbank.
|
||||
Löscht einen Tenant, seine Konfiguration, Ports, nginx-VHost und das
|
||||
zugehörige Let's-Encrypt-Zertifikat sowie die Datenbank.
|
||||
Nutze ${RED}-y${RESET}, um die Bestätigungsabfrage zu überspringen.
|
||||
|
||||
${GREEN}restart-tenant${RESET} <tenant_id>
|
||||
@@ -602,11 +821,16 @@ case "$COMMAND" in
|
||||
register_tenant_port "$TENANT_ID" "$PORT_ARG"
|
||||
update_runtime_ports "$PORT_ARG"
|
||||
sync_tenant_port_map
|
||||
if ! write_tenant_nginx_config "$TENANT_ID" "$PORT_ARG"; then
|
||||
echo "Warning: nginx/certbot provisioning for '$TENANT_ID' could not be completed automatically."
|
||||
fi
|
||||
if [ -n "$(docker ps -qf 'name=app' | head -n 1)" ]; then
|
||||
restart_app_container
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
|
||||
echo "Adding new tenant '$TENANT_ID'..."
|
||||
echo "Initializing database for $TENANT_ID..."
|
||||
initialize_tenant_database "$TENANT_ID" "standard"
|
||||
@@ -631,6 +855,9 @@ case "$COMMAND" in
|
||||
register_tenant_port "$TENANT_ID" "$PORT_ARG"
|
||||
update_runtime_ports "$PORT_ARG"
|
||||
sync_tenant_port_map
|
||||
if ! write_tenant_nginx_config "$TENANT_ID" "$PORT_ARG"; then
|
||||
echo "Warning: nginx/certbot provisioning for trial tenant '$TENANT_ID' could not be completed automatically."
|
||||
fi
|
||||
fi
|
||||
|
||||
write_trial_tenant_config "$TENANT_ID" "$PORT_ARG" "$DAYS_ARG"
|
||||
@@ -643,11 +870,11 @@ case "$COMMAND" in
|
||||
initialize_tenant_database "$TENANT_ID" "trial"
|
||||
echo "Trial tenant '$TENANT_ID' successfully configured. It will expire after $DAYS_ARG day(s) and self-delete."
|
||||
;;
|
||||
|
||||
|
||||
remove)
|
||||
FORCE_REMOVE=false
|
||||
TENANT_ARG="${2:-}"
|
||||
|
||||
|
||||
if [ "$TENANT_ARG" = "--yes" ] || [ "$TENANT_ARG" = "-y" ]; then
|
||||
FORCE_REMOVE=true
|
||||
TENANT_ID="${3:-}"
|
||||
@@ -672,40 +899,31 @@ case "$COMMAND" in
|
||||
echo "Removing tenant '$TENANT_ID'..."
|
||||
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
|
||||
port_to_remove=""
|
||||
|
||||
|
||||
if [ -n "$APP_CONTAINER" ]; then
|
||||
# Zuerst die Datenbank via PyMongo hart droppen (Erzwungenes Löschen)
|
||||
port_to_remove="$(docker exec "$APP_CONTAINER" python3 - "$TENANT_ID" <<'PY'
|
||||
import sys, re
|
||||
sys.path.insert(0, '/app')
|
||||
sys.path.insert(0, '/app/Web')
|
||||
from tenant import delete_tenant, get_tenant_config
|
||||
from Web.modules.database import settings
|
||||
from pymongo import MongoClient
|
||||
# MongoDB-Datenbank via PyMongo direkt im Container droppen
|
||||
docker exec -i "$APP_CONTAINER" python3 -c '
|
||||
import sys, os
|
||||
try:
|
||||
import pymongo
|
||||
tenant_id = sys.argv[1]
|
||||
mongo_uri = os.environ.get("MONGO_URI", "mongodb://localhost:27017/")
|
||||
client = pymongo.MongoClient(mongo_uri, serverSelectionTimeoutMS=2000)
|
||||
db_name = f"inventar_{tenant_id}"
|
||||
if db_name in client.list_database_names():
|
||||
client.drop_database(db_name)
|
||||
print(f"Dropped database: {db_name}")
|
||||
except Exception as e:
|
||||
print(f"Error dropping database: {e}", file=sys.stderr)
|
||||
' "$TENANT_ID" > /dev/null 2>&1
|
||||
|
||||
tenant_id = sys.argv[1]
|
||||
tenant_cfg = get_tenant_config(tenant_id)
|
||||
port = tenant_cfg.get('port')
|
||||
# Konfiguration und Port via Host-Funktion bereinigen und Port ermitteln
|
||||
if port_to_remove="$(remove_tenant_port "$TENANT_ID" 2>/dev/null)"; then
|
||||
:
|
||||
else
|
||||
port_to_remove=""
|
||||
fi
|
||||
|
||||
# Datenbanknamen exakt rekonstruieren
|
||||
sanitized = "".join(c for c in tenant_id if c.isalnum() or c == "_")
|
||||
db_name = f"inventar_{sanitized}"
|
||||
|
||||
try:
|
||||
client = MongoClient(settings.MONGODB_HOST, int(settings.MONGODB_PORT))
|
||||
client.drop_database(db_name)
|
||||
print(f"MongoDB database '{db_name}' dropped successfully.", file=sys.stderr)
|
||||
except Exception as e:
|
||||
print(f"Warning: Could not drop database '{db_name}': {e}", file=sys.stderr)
|
||||
|
||||
if not delete_tenant(tenant_id):
|
||||
print(f'Error: failed to delete tenant {tenant_id}', file=sys.stderr)
|
||||
sys.exit(1)
|
||||
|
||||
if port is not None:
|
||||
print(port)
|
||||
PY
|
||||
)"
|
||||
echo "Tenant '$TENANT_ID' database and config removed."
|
||||
else
|
||||
echo "Warning: Application container not running. Tenant database may still exist in MongoDB."
|
||||
@@ -719,6 +937,7 @@ PY
|
||||
if [ -n "$port_to_remove" ]; then
|
||||
remove_runtime_port "$port_to_remove"
|
||||
fi
|
||||
remove_tenant_nginx_config "$TENANT_ID"
|
||||
sync_tenant_port_map
|
||||
if [ -n "$(docker ps -qf 'name=app' | head -n 1)" ]; then
|
||||
restart_app_container
|
||||
@@ -728,7 +947,7 @@ PY
|
||||
else
|
||||
echo "Removed tenant '$TENANT_ID'. No port mapping was present."
|
||||
fi
|
||||
;;
|
||||
;;
|
||||
|
||||
restart-tenant)
|
||||
TENANT_ID="${2:-}"
|
||||
|
||||
+2
-1
@@ -17,4 +17,5 @@ cryptography>=42.0.0
|
||||
pywebpush
|
||||
py-vapid>=1.9.0
|
||||
beautifulsoup4
|
||||
pywebpush
|
||||
pywebpush
|
||||
pandas
|
||||
@@ -9,13 +9,13 @@ LOG_DIR="$PROJECT_DIR/logs"
|
||||
LOG_FILE="$LOG_DIR/update.log"
|
||||
STATE_FILE="$PROJECT_DIR/.release-version"
|
||||
REPO_SLUG="Invario/Inventarsystem"
|
||||
API_URL="https://git.invario-software.eu/api/v1/repos/$REPO_SLUG/releases/latest"
|
||||
API_BASE_URL="https://git.invario-software.eu/api/v1/repos/$REPO_SLUG"
|
||||
BUNDLE_ASSET="inventarsystem-docker-bundle.tar.gz"
|
||||
ENV_FILE="$PROJECT_DIR/.docker-build.env"
|
||||
APP_IMAGE_REPO="git.invario-software.eu/invario/inventarsystem"
|
||||
COMPOSE_FILE="docker-compose-multitenant.yml"
|
||||
MIN_ROOT_FREE_MB="${INVENTAR_MIN_ROOT_FREE_MB:-2048}"
|
||||
MODE="release"
|
||||
MODE="stable"
|
||||
|
||||
mkdir -p "$LOG_DIR"
|
||||
chmod 777 "$LOG_DIR" 2>/dev/null || true
|
||||
@@ -119,6 +119,7 @@ usage() {
|
||||
Usage: $0 [options]
|
||||
|
||||
Options:
|
||||
-dev Install the latest prerelease build
|
||||
--multitenant Use docker-compose-multitenant.yml (default)
|
||||
-h, --help Show this help message
|
||||
EOF
|
||||
@@ -127,6 +128,10 @@ EOF
|
||||
parse_args() {
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
-dev)
|
||||
MODE="development"
|
||||
shift
|
||||
;;
|
||||
--multitenant)
|
||||
COMPOSE_FILE="docker-compose-multitenant.yml"
|
||||
shift
|
||||
@@ -179,7 +184,8 @@ create_backup() {
|
||||
|
||||
fetch_release_metadata() {
|
||||
local meta_file="$1"
|
||||
curl -fsSL "$API_URL" -o "$meta_file"
|
||||
local endpoint="${2:-latest}"
|
||||
curl -fsSL "$API_BASE_URL/releases/$endpoint" -o "$meta_file"
|
||||
}
|
||||
|
||||
parse_latest_tag() {
|
||||
@@ -207,6 +213,124 @@ for asset in data.get('assets', []):
|
||||
PY
|
||||
}
|
||||
|
||||
parse_release_tag() {
|
||||
local meta_file="$1"
|
||||
python3 - <<'PY' "$meta_file"
|
||||
import json, sys
|
||||
with open(sys.argv[1], 'r', encoding='utf-8') as f:
|
||||
data = json.load(f)
|
||||
print(data.get('tag_name', '').strip())
|
||||
PY
|
||||
}
|
||||
|
||||
strip_prerelease_suffix() {
|
||||
local tag="$1"
|
||||
python3 - <<'PY' "$tag"
|
||||
import re, sys
|
||||
tag = sys.argv[1].strip()
|
||||
match = re.match(r'^(v\d+\.\d+\.\d+)', tag)
|
||||
print(match.group(1) if match else tag)
|
||||
PY
|
||||
}
|
||||
|
||||
compare_semver_tags() {
|
||||
local left_tag="$1"
|
||||
local right_tag="$2"
|
||||
python3 - <<'PY' "$left_tag" "$right_tag"
|
||||
import re, sys
|
||||
|
||||
def parse(tag):
|
||||
match = re.match(r'^v(\d+)\.(\d+)\.(\d+)', tag.strip())
|
||||
if not match:
|
||||
return None
|
||||
return tuple(int(part) for part in match.groups())
|
||||
|
||||
left = parse(sys.argv[1])
|
||||
right = parse(sys.argv[2])
|
||||
if left is None or right is None:
|
||||
print('unknown')
|
||||
elif left > right:
|
||||
print('gt')
|
||||
elif left < right:
|
||||
print('lt')
|
||||
else:
|
||||
print('eq')
|
||||
PY
|
||||
}
|
||||
|
||||
parse_prerelease_flag() {
|
||||
local meta_file="$1"
|
||||
python3 - <<'PY' "$meta_file"
|
||||
import json, sys
|
||||
with open(sys.argv[1], 'r', encoding='utf-8') as f:
|
||||
data = json.load(f)
|
||||
print('true' if data.get('prerelease') else 'false')
|
||||
PY
|
||||
}
|
||||
|
||||
latest_stable_release() {
|
||||
local meta_file="$1"
|
||||
local releases_file="$2"
|
||||
local release_count=0
|
||||
|
||||
if ! curl -fsSL "$API_BASE_URL/releases" -o "$releases_file"; then
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! python3 - <<'PY' "$releases_file" "$meta_file"
|
||||
import json, sys
|
||||
releases_path, target_path = sys.argv[1], sys.argv[2]
|
||||
with open(releases_path, 'r', encoding='utf-8') as f:
|
||||
releases = json.load(f)
|
||||
for release in releases:
|
||||
if not release.get('prerelease') and not release.get('draft'):
|
||||
with open(target_path, 'w', encoding='utf-8') as out:
|
||||
json.dump(release, out)
|
||||
raise SystemExit(0)
|
||||
raise SystemExit(1)
|
||||
PY
|
||||
then
|
||||
return 1
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
latest_prerelease() {
|
||||
local meta_file="$1"
|
||||
local releases_file="$2"
|
||||
|
||||
if ! curl -fsSL "$API_BASE_URL/releases" -o "$releases_file"; then
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! python3 - <<'PY' "$releases_file" "$meta_file"
|
||||
import json, sys
|
||||
releases_path, target_path = sys.argv[1], sys.argv[2]
|
||||
with open(releases_path, 'r', encoding='utf-8') as f:
|
||||
releases = json.load(f)
|
||||
for release in releases:
|
||||
if release.get('prerelease') and not release.get('draft'):
|
||||
with open(target_path, 'w', encoding='utf-8') as out:
|
||||
json.dump(release, out)
|
||||
raise SystemExit(0)
|
||||
raise SystemExit(1)
|
||||
PY
|
||||
then
|
||||
return 1
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
fetch_latest_release_bundle() {
|
||||
local release_meta="$1"
|
||||
local bundle_url
|
||||
bundle_url="$(parse_asset_url "$release_meta" "$BUNDLE_ASSET")"
|
||||
if [ -z "$bundle_url" ]; then
|
||||
return 1
|
||||
fi
|
||||
printf '%s' "$bundle_url"
|
||||
}
|
||||
|
||||
refresh_runtime_scripts_from_main() {
|
||||
local start_url stop_url restart_url update_url
|
||||
start_url="https://git.invario-software.eu/$REPO_SLUG/raw/branch/main/start.sh"
|
||||
@@ -368,12 +492,66 @@ main() {
|
||||
archive_logs
|
||||
create_backup
|
||||
|
||||
# If user requested a development install, perform a simple dev deploy flow
|
||||
# If user requested a development install, deploy the latest prerelease.
|
||||
if [ "$MODE" = "development" ]; then
|
||||
log_message "Requested development install"
|
||||
local tag="dev"
|
||||
local app_image="$APP_IMAGE_REPO:$tag"
|
||||
local compose_path="$PROJECT_DIR/$COMPOSE_FILE"
|
||||
local tag meta_file releases_file stable_meta_file stable_tag prerelease_tag prerelease_base_tag bundle_url app_image compose_path
|
||||
local tmp_dir
|
||||
|
||||
tmp_dir="$(mktemp -d)"
|
||||
meta_file="$tmp_dir/prerelease.json"
|
||||
stable_meta_file="$tmp_dir/stable.json"
|
||||
releases_file="$tmp_dir/releases.json"
|
||||
trap 'rm -rf "${tmp_dir:-}"' EXIT
|
||||
|
||||
if ! fetch_release_metadata "$stable_meta_file" "latest"; then
|
||||
log_message "ERROR: Could not fetch latest stable release metadata"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
stable_tag="$(parse_release_tag "$stable_meta_file")"
|
||||
if [ -z "$stable_tag" ]; then
|
||||
log_message "ERROR: Could not determine latest stable release tag"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if latest_prerelease "$meta_file" "$releases_file"; then
|
||||
prerelease_tag="$(parse_release_tag "$meta_file")"
|
||||
prerelease_base_tag="$(strip_prerelease_suffix "$prerelease_tag")"
|
||||
else
|
||||
prerelease_tag=""
|
||||
prerelease_base_tag=""
|
||||
fi
|
||||
|
||||
if [ -n "$prerelease_tag" ]; then
|
||||
case "$(compare_semver_tags "$stable_tag" "$prerelease_base_tag")" in
|
||||
gt|eq)
|
||||
log_message "Latest stable release ($stable_tag) supersedes prerelease ($prerelease_tag); using stable release"
|
||||
tag="$stable_tag"
|
||||
meta_file="$stable_meta_file"
|
||||
;;
|
||||
lt)
|
||||
tag="$prerelease_tag"
|
||||
;;
|
||||
*)
|
||||
log_message "WARNING: Could not compare stable and prerelease versions; preferring prerelease when available"
|
||||
tag="$prerelease_tag"
|
||||
;;
|
||||
esac
|
||||
else
|
||||
log_message "No prerelease found; falling back to stable release $stable_tag"
|
||||
tag="$stable_tag"
|
||||
meta_file="$stable_meta_file"
|
||||
fi
|
||||
|
||||
bundle_url="$(fetch_latest_release_bundle "$meta_file")"
|
||||
if [ -z "$bundle_url" ]; then
|
||||
log_message "ERROR: Release asset not found: $BUNDLE_ASSET"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
app_image="$APP_IMAGE_REPO:$tag"
|
||||
compose_path="$PROJECT_DIR/$COMPOSE_FILE"
|
||||
|
||||
if [ ! -f "$compose_path" ]; then
|
||||
log_message "ERROR: compose file not found: $compose_path"
|
||||
@@ -399,6 +577,9 @@ EOF
|
||||
exit 1
|
||||
fi
|
||||
|
||||
download_and_extract_bundle "$bundle_url" "$tmp_dir"
|
||||
refresh_runtime_scripts_from_main
|
||||
|
||||
# Bring up stack
|
||||
docker compose -f "$compose_path" --env-file "$ENV_FILE" pull mongodb redis >> "$LOG_FILE" 2>&1 || true
|
||||
docker compose -f "$compose_path" --env-file "$ENV_FILE" up -d --remove-orphans >> "$LOG_FILE" 2>&1
|
||||
@@ -409,7 +590,7 @@ EOF
|
||||
fi
|
||||
|
||||
echo "$tag" > "$STATE_FILE"
|
||||
log_message "Development update completed successfully"
|
||||
log_message "Development update completed successfully to prerelease $tag"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
@@ -419,8 +600,8 @@ EOF
|
||||
|
||||
trap 'rm -rf "${tmp_dir:-}"' EXIT
|
||||
|
||||
log_message "Checking latest Gitea release for $REPO_SLUG..."
|
||||
if ! fetch_release_metadata "$meta_file"; then
|
||||
log_message "Checking latest stable Gitea release for $REPO_SLUG..."
|
||||
if ! fetch_release_metadata "$meta_file" "latest"; then
|
||||
log_message "WARNING: Could not fetch release metadata. Falling back to self-healing start path."
|
||||
if INVENTAR_SETUP_CRON=0 bash "$PROJECT_DIR/start.sh" >> "$LOG_FILE" 2>&1; then
|
||||
if verify_stack_health; then
|
||||
@@ -436,7 +617,7 @@ EOF
|
||||
exit 0
|
||||
fi
|
||||
|
||||
latest_tag="$(parse_latest_tag "$meta_file")"
|
||||
latest_tag="$(parse_release_tag "$meta_file")"
|
||||
if [ -z "$latest_tag" ]; then
|
||||
log_message "WARNING: Could not determine latest release tag. Falling back to self-healing start path."
|
||||
if INVENTAR_SETUP_CRON=0 bash "$PROJECT_DIR/start.sh" >> "$LOG_FILE" 2>&1; then
|
||||
|
||||
Reference in New Issue
Block a user