Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e1e488f723 | |||
| 0562aee04b | |||
| b1c104f36c | |||
| 5afe05b2d2 | |||
| 7207fef0d4 | |||
| 3f9fae10af | |||
| f45988d0e7 |
@@ -1,11 +0,0 @@
|
||||
NUITKA_BUILD=0
|
||||
INVENTAR_HTTP_PORT=10000
|
||||
INVENTAR_HTTP_PORTS=10000
|
||||
INVENTAR_APP_IMAGE=ghcr.io/aiirondev/legendary-octo-garbanzo:v0.7.42
|
||||
INVENTAR_APP_CPUS=1.0
|
||||
INVENTAR_APP_MEM_LIMIT=384m
|
||||
INVENTAR_APP_MEM_SWAP_LIMIT=768m
|
||||
INVENTAR_WORKERS=4
|
||||
INVENTAR_THREADS=2
|
||||
INVENTAR_WORKER_TIMEOUT=30
|
||||
INVENTAR_WORKER_CONNECTIONS=100
|
||||
@@ -256,7 +256,7 @@ jobs:
|
||||
EOF
|
||||
|
||||
# Copy runtime scripts and config if present
|
||||
for f in start.sh stop.sh restart.sh backup.sh config.json update.sh; do
|
||||
for f in start.sh stop.sh restart.sh backup.sh restore.sh config.json update.sh; do
|
||||
if [ -f "$f" ]; then
|
||||
cp "$f" "release-bundle/$(basename "$f")"
|
||||
fi
|
||||
|
||||
+54
-19
@@ -289,7 +289,7 @@ SCHEDULER_INTERVAL = cfg.SCHEDULER_INTERVAL_MIN
|
||||
SSL_CERT = cfg.SSL_CERT
|
||||
SSL_KEY = cfg.SSL_KEY
|
||||
|
||||
LIBRARY_ITEM_TYPES = ('book', 'cd', 'dvd', 'other', 'schoolbook', 'Buch', 'Schulbuch', 'schulbuch')
|
||||
LIBRARY_ITEM_TYPES = ('book', 'cd', 'dvd', 'schoolbook', 'Buch', 'Schulbuch', 'schulbuch')
|
||||
INVOICE_CURRENCY = 'EUR'
|
||||
|
||||
NOTIFICATION_STATUS_CACHE_TTL = max(3, int(os.getenv('INVENTAR_NOTIFICATION_STATUS_CACHE_TTL', '8')))
|
||||
@@ -3212,7 +3212,7 @@ def api_library_items():
|
||||
ausleihungen_db = db['ausleihungen']
|
||||
|
||||
query = {
|
||||
'ItemType': {'$in': ['book', 'cd', 'dvd', 'other', 'schoolbook', 'schulbuch', 'Buch', 'Schulbuch']},
|
||||
'ItemType': {'$in': ['book', 'cd', 'dvd', 'schoolbook', 'schulbuch', 'Buch', 'Schulbuch']},
|
||||
'IsGroupedSubItem': {'$ne': True},
|
||||
'Deleted': {'$ne': True}
|
||||
}
|
||||
@@ -3338,7 +3338,7 @@ def api_library_items():
|
||||
client = MongoClient(cfg.MONGODB_HOST, cfg.MONGODB_PORT)
|
||||
db = client[cfg.MONGODB_DB]
|
||||
student_cards = db['student_cards']
|
||||
card = student_cards.find_one({'_id': ObjectId(borrow_id)})
|
||||
card = student_cards.find_one({'_id': ObjectId(borrower)}) if borrower else None
|
||||
card = _decrypt_student_card_doc(card)
|
||||
client.close()
|
||||
borrower = card['SchülerName']
|
||||
@@ -8154,10 +8154,26 @@ def admin_audit_dashboard():
|
||||
|
||||
# DEC_START: Decrypt the sensitive fields for display
|
||||
for row in audit_rows:
|
||||
if "payload" in row:
|
||||
# decrypt_document_fields acts in-place
|
||||
decrypt_document_fields(row["payload"], SENSITIVE_AUDIT_FIELDS)
|
||||
# DEC_END
|
||||
payload_raw = row.get("payload")
|
||||
|
||||
if payload_raw and isinstance(payload_raw, str):
|
||||
try:
|
||||
# Safely evaluate the python-like dict string, providing context for ObjectId
|
||||
safe_context = {"ObjectId": ObjectId, "None": None, "True": True, "False": False}
|
||||
payload_dict = eval(payload_raw, {"__builtins__": {}}, safe_context)
|
||||
|
||||
if isinstance(payload_dict, dict):
|
||||
# Decrypt the sensitive keys inside the extracted dictionary
|
||||
decrypt_document_fields(payload_dict, SENSITIVE_AUDIT_FIELDS)
|
||||
|
||||
# Replace the raw string with the clean dictionary for the Jinja template
|
||||
row["payload"] = payload_dict
|
||||
except Exception as parse_err:
|
||||
app.logger.error(f"Failed to parse audit payload string for index {row.get('chain_index')}: {parse_err}")
|
||||
|
||||
elif payload_raw and isinstance(payload_raw, dict):
|
||||
# Fallback in case some newer log rows are already stored as proper dictionaries
|
||||
decrypt_document_fields(payload_raw, SENSITIVE_AUDIT_FIELDS)
|
||||
|
||||
return render_template(
|
||||
'admin_audit.html',
|
||||
@@ -8204,11 +8220,26 @@ def admin_audit_export_pdf_official():
|
||||
|
||||
audit_rows = list(db['audit_log'].find({}).sort('chain_index', -1).limit(limit))
|
||||
|
||||
# DEC_START: Decrypt sensitive fields for the PDF report
|
||||
for row in audit_rows:
|
||||
if "payload" in row:
|
||||
decrypt_document_fields(row["payload"], SENSITIVE_AUDIT_FIELDS)
|
||||
# DEC_END
|
||||
payload_raw = row.get("payload")
|
||||
|
||||
if payload_raw and isinstance(payload_raw, str):
|
||||
try:
|
||||
# Safely evaluate the python-like dict string with custom token support
|
||||
safe_context = {"ObjectId": ObjectId, "None": None, "True": True, "False": False}
|
||||
payload_dict = eval(payload_raw, {"__builtins__": {}}, safe_context)
|
||||
|
||||
if isinstance(payload_dict, dict):
|
||||
# Decrypt the dictionary fields in-place
|
||||
decrypt_document_fields(payload_dict, SENSITIVE_AUDIT_FIELDS)
|
||||
# Replace string with the clean dictionary so the PDF generator can read it
|
||||
row["payload"] = payload_dict
|
||||
except Exception as parse_err:
|
||||
app.logger.error(f"Failed to parse audit payload string for PDF export at index {row.get('chain_index')}: {parse_err}")
|
||||
|
||||
elif payload_raw and isinstance(payload_raw, dict):
|
||||
# Fallback for standard dict payloads
|
||||
decrypt_document_fields(payload_raw, SENSITIVE_AUDIT_FIELDS)
|
||||
|
||||
# Get school information from settings or use defaults
|
||||
school_info = _get_school_info_for_export()
|
||||
@@ -10373,13 +10404,8 @@ def admin_damaged_items():
|
||||
flash('Administratorrechte erforderlich.', 'error')
|
||||
return redirect(url_for('login'))
|
||||
|
||||
'''
|
||||
permissions = _get_current_user_permissions()
|
||||
if not _action_access_allowed(permissions, 'can_manage_settings'):
|
||||
flash('Sie haben keine Berechtigung, die Schulstammdaten zu ändern.', 'error')
|
||||
if cfg.MODULES.is_enabled('library'):
|
||||
return redirect(url_for('library_admin'))
|
||||
'''
|
||||
# Import the decryption handler if it's not already at the top of the file
|
||||
from modules.inventarsystem.data_protection import decrypt_text
|
||||
|
||||
client = None
|
||||
try:
|
||||
@@ -10419,9 +10445,18 @@ def admin_damaged_items():
|
||||
{'Item': item_id, 'Status': {'$in': ['active', 'planned']}},
|
||||
{'_id': 1, 'User': 1, 'Status': 1, 'End': 1}
|
||||
)
|
||||
|
||||
# Decrypt the borrower inside the active loan tracking object
|
||||
if active_borrow and active_borrow.get('User'):
|
||||
active_borrow['User'] = decrypt_text(active_borrow['User'])
|
||||
|
||||
reports = item_doc.get('DamageReports', []) or []
|
||||
latest_report = reports[0] if reports else {}
|
||||
|
||||
# Decrypt the static snapshot borrower field on the item itself
|
||||
raw_user = item_doc.get('User', '')
|
||||
decrypted_user = decrypt_text(raw_user) if raw_user else ''
|
||||
|
||||
damaged_rows.append({
|
||||
'id': item_id,
|
||||
'name': item_doc.get('Name', ''),
|
||||
@@ -10431,7 +10466,7 @@ def admin_damaged_items():
|
||||
'isbn': item_doc.get('ISBN', ''),
|
||||
'condition': item_doc.get('Condition', ''),
|
||||
'available': bool(item_doc.get('Verfuegbar', False)),
|
||||
'borrow_user': item_doc.get('User', ''),
|
||||
'borrow_user': decrypted_user,
|
||||
'damage_count': len(reports),
|
||||
'damage_reports': reports,
|
||||
'latest_damage_description': latest_report.get('description', ''),
|
||||
|
||||
@@ -4,7 +4,7 @@ set -euo pipefail
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
COMPOSE_FILE="docker-compose-multitenant.yml"
|
||||
|
||||
# Verzeichnisse
|
||||
# Directories
|
||||
INVOICE_ARCHIVE_DIR="${INVOICE_ARCHIVE_DIR:-/var/backups/invoice-archive}"
|
||||
FULL_BACKUP_DIR="${FULL_BACKUP_DIR:-/var/backups/inventarsystem}"
|
||||
LOG_DIR="$SCRIPT_DIR/logs"
|
||||
@@ -29,31 +29,12 @@ EOF
|
||||
parse_args() {
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
--invoice-archive-dir)
|
||||
INVOICE_ARCHIVE_DIR="$2"
|
||||
shift 2
|
||||
;;
|
||||
--invoice-keep-days)
|
||||
KEEP_DAYS="$2"
|
||||
shift 2
|
||||
;;
|
||||
--mode)
|
||||
MODE="$2"
|
||||
shift 2
|
||||
;;
|
||||
--base-name)
|
||||
BASE_NAME="$2"
|
||||
shift 2
|
||||
;;
|
||||
-h|--help)
|
||||
usage
|
||||
exit 0
|
||||
;;
|
||||
*)
|
||||
echo "Error: unknown option '$1'" >&2
|
||||
usage
|
||||
exit 2
|
||||
;;
|
||||
--invoice-archive-dir) INVOICE_ARCHIVE_DIR="$2"; shift 2 ;;
|
||||
--invoice-keep-days) KEEP_DAYS="$2"; shift 2 ;;
|
||||
--mode) MODE="$2"; shift 2 ;;
|
||||
--base-name) BASE_NAME="$2"; shift 2 ;;
|
||||
-h|--help) usage; exit 0 ;;
|
||||
*) echo "Error: unknown option '$1'" >&2; usage; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
}
|
||||
@@ -67,73 +48,50 @@ cleanup_old_archives() {
|
||||
if [[ -n "$KEEP_DAYS" ]]; then
|
||||
find "$INVOICE_ARCHIVE_DIR" -maxdepth 1 -type f -mtime +"$KEEP_DAYS" -print -delete 2>/dev/null || true
|
||||
fi
|
||||
# Behalte die kompletten DB-Backups für 30 Tage
|
||||
find "$FULL_BACKUP_DIR" -maxdepth 1 -type f -mtime +30 -print -delete 2>/dev/null || true
|
||||
# Cleanup old bundled backups (older than 30 days)
|
||||
find "$FULL_BACKUP_DIR" -maxdepth 1 -type f -name "full_backup_*.tar.gz" -mtime +30 -print -delete 2>/dev/null || true
|
||||
}
|
||||
|
||||
docker_backup() {
|
||||
if ! command -v docker >/dev/null 2>&1; then
|
||||
return 1
|
||||
fi
|
||||
if ! docker compose -f "$COMPOSE_FILE" ps -q app >/dev/null 2>&1; then
|
||||
return 1
|
||||
fi
|
||||
if ! command -v docker >/dev/null 2>&1; then return 1; fi
|
||||
|
||||
local timestamp="$(date +'%Y-%m-%d_%H-%M-%S')"
|
||||
local staging_dir="/tmp/backup_stage_$timestamp"
|
||||
|
||||
echo "[$(date +'%T')] Starting unified system backup..."
|
||||
mkdir -p "$staging_dir"
|
||||
|
||||
local timestamp
|
||||
timestamp="$(date +'%Y-%m-%d_%H-%M-%S')"
|
||||
|
||||
echo "[$(date +'%T')] Starte VOLLSTAENDIGES System-Backup..."
|
||||
|
||||
# 1. MongoDB Full Dump (Alles: Ausleihen, User, Inventar, etc.)
|
||||
# 1. MongoDB Dump (into staging)
|
||||
if docker compose -f "$COMPOSE_FILE" ps -q mongodb >/dev/null 2>&1; then
|
||||
echo "[$(date +'%T')] Erstelle Datenbank-Dump (MongoDB)..."
|
||||
docker compose -f "$COMPOSE_FILE" exec -T mongodb mongodump --archive --gzip > "$FULL_BACKUP_DIR/full_db_${timestamp}.archive.gz"
|
||||
else
|
||||
echo "Warnung: MongoDB-Container nicht gefunden. Überspringe DB-Dump."
|
||||
echo "[$(date +'%T')] Dumping Database..."
|
||||
docker compose -f "$COMPOSE_FILE" exec -T mongodb mongodump --archive --gzip > "$staging_dir/db.archive.gz"
|
||||
fi
|
||||
|
||||
# 2. Logs sichern
|
||||
# 2. Archive Assets (into staging)
|
||||
if [ -d "./Web/uploads" ]; then
|
||||
echo "[$(date +'%T')] Archiving assets..."
|
||||
tar -czf "$staging_dir/assets.tar.gz" -C . Web/uploads Web/thumbnails Web/previews 2>/dev/null || true
|
||||
fi
|
||||
|
||||
# 3. Archive Logs (into staging)
|
||||
if [ -d "$LOG_DIR" ]; then
|
||||
echo "[$(date +'%T')] Sichere Logs..."
|
||||
tar -czf "$FULL_BACKUP_DIR/logs_${timestamp}.tar.gz" -C "$(dirname "$LOG_DIR")" "$(basename "$LOG_DIR")"
|
||||
echo "[$(date +'%T')] Archiving logs..."
|
||||
tar -czf "$staging_dir/logs.tar.gz" -C "$(dirname "$LOG_DIR")" "$(basename "$LOG_DIR")"
|
||||
fi
|
||||
|
||||
# 3. Invoice Export (für Kompatibilität mit dem alten Format)
|
||||
local app_container
|
||||
app_container="$(docker compose -f "$COMPOSE_FILE" ps -q app | tr -d '[:space:]')"
|
||||
if [[ -n "$app_container" ]]; then
|
||||
local output_dir="/tmp/invoice_archive_${timestamp}"
|
||||
local remote_base="${output_dir}/${BASE_NAME}"
|
||||
|
||||
docker compose -f "$COMPOSE_FILE" exec -T app mkdir -p "$output_dir"
|
||||
|
||||
docker compose -f "$COMPOSE_FILE" exec -T app python3 /app/Web/modules/inventarsystem/backup_invoices.py \
|
||||
--archive-dir "$output_dir" \
|
||||
--base-name "$BASE_NAME" >/dev/null 2>&1 || true
|
||||
|
||||
if docker compose -f "$COMPOSE_FILE" exec -T app test -f "${remote_base}.jsonl"; then
|
||||
docker cp "$app_container":"${remote_base}.jsonl" "$INVOICE_ARCHIVE_DIR/"
|
||||
docker cp "$app_container":"${remote_base}.csv" "$INVOICE_ARCHIVE_DIR/"
|
||||
docker cp "$app_container":"${remote_base}.meta.json" "$INVOICE_ARCHIVE_DIR/"
|
||||
else
|
||||
echo "[$(date +'%T')] Info: Keine Rechnungsdaten gefunden."
|
||||
fi
|
||||
|
||||
docker compose -f "$COMPOSE_FILE" exec -T app rm -rf "$output_dir"
|
||||
fi
|
||||
|
||||
echo "[$(date +'%T')] Backup erfolgreich abgeschlossen!"
|
||||
echo "Dateien gespeichert in: $FULL_BACKUP_DIR"
|
||||
# 4. Bundle everything into one file
|
||||
echo "[$(date +'%T')] Bundling archive..."
|
||||
tar -czf "$FULL_BACKUP_DIR/full_backup_$timestamp.tar.gz" -C "$staging_dir" .
|
||||
|
||||
# 5. Cleanup staging
|
||||
rm -rf "$staging_dir"
|
||||
|
||||
echo "[$(date +'%T')] Backup complete: $FULL_BACKUP_DIR/full_backup_$timestamp.tar.gz"
|
||||
return 0
|
||||
}
|
||||
|
||||
main() {
|
||||
parse_args "$@"
|
||||
|
||||
if [[ -z "$BASE_NAME" ]]; then
|
||||
BASE_NAME="invoices-$(date +'%Y-%m-%d_%H-%M-%S')"
|
||||
fi
|
||||
|
||||
ensure_directory
|
||||
|
||||
case "$MODE" in
|
||||
@@ -142,7 +100,7 @@ main() {
|
||||
cleanup_old_archives
|
||||
return 0
|
||||
fi
|
||||
echo "Error: Docker Backup fehlgeschlagen." >&2
|
||||
echo "Error: Docker backup failed." >&2
|
||||
return 1
|
||||
;;
|
||||
*)
|
||||
|
||||
+1
-1
@@ -27,7 +27,7 @@
|
||||
"username": "",
|
||||
"password": "",
|
||||
"from_address": "",
|
||||
"default_sender_name": "Invario Inventurprogramm",
|
||||
"default_sender_name": "Invario Inventarprogramm",
|
||||
"timeout_seconds": 30
|
||||
},
|
||||
"images": {
|
||||
|
||||
Executable
+58
@@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
BACKUP_DIR="/var/backups/inventarsystem"
|
||||
COMPOSE_FILE="docker-compose-multitenant.yml"
|
||||
|
||||
# 1. Find the latest backup bundle
|
||||
LATEST_BACKUP=$(ls -t "$BACKUP_DIR"/full_backup_*.tar.gz | head -n1 2>/dev/null || true)
|
||||
|
||||
if [[ -z "$LATEST_BACKUP" ]]; then
|
||||
echo "Error: No backup bundle found in $BACKUP_DIR"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "--- RESTORE PROCEDURE ---"
|
||||
echo "Found latest bundle: $(basename "$LATEST_BACKUP")"
|
||||
read -p "WARNING: This will OVERWRITE your current database and assets! Continue? (y/N) " confirm
|
||||
[[ "$confirm" != "y" ]] && exit 1
|
||||
|
||||
# 2. Extract the bundle to a temporary location
|
||||
RESTORE_TMP="/tmp/restore_$(date +%s)"
|
||||
mkdir -p "$RESTORE_TMP"
|
||||
echo "Extracting bundle..."
|
||||
tar -xzf "$LATEST_BACKUP" -C "$RESTORE_TMP"
|
||||
|
||||
# 3. Stop application
|
||||
echo "Stopping application..."
|
||||
docker compose -f "$COMPOSE_FILE" stop app
|
||||
|
||||
# 4. Restore Database
|
||||
if [ -f "$RESTORE_TMP/db.archive.gz" ]; then
|
||||
echo "Restoring MongoDB..."
|
||||
zcat "$RESTORE_TMP/db.archive.gz" | docker compose -f "$COMPOSE_FILE" exec -T mongodb mongorestore --archive --gzip --drop
|
||||
else
|
||||
echo "Warning: Database archive not found in bundle."
|
||||
fi
|
||||
|
||||
# 5. Restore Assets
|
||||
if [ -f "$RESTORE_TMP/assets.tar.gz" ]; then
|
||||
echo "Restoring Assets (Uploads/Thumbnails/Previews)..."
|
||||
tar -xzf "$RESTORE_TMP/assets.tar.gz" -C .
|
||||
else
|
||||
echo "Warning: Asset archive not found in bundle."
|
||||
fi
|
||||
|
||||
# 6. Restore Logs (Optional)
|
||||
if [ -f "$RESTORE_TMP/logs.tar.gz" ]; then
|
||||
echo "Restoring Logs..."
|
||||
tar -xzf "$RESTORE_TMP/logs.tar.gz" -C .
|
||||
fi
|
||||
|
||||
# 7. Start application
|
||||
echo "Restarting application..."
|
||||
docker compose -f "$COMPOSE_FILE" start app
|
||||
|
||||
# 8. Cleanup
|
||||
rm -rf "$RESTORE_TMP"
|
||||
echo "Restore complete!"
|
||||
Reference in New Issue
Block a user