Compare commits

...

3 Commits

Author SHA1 Message Date
Aiirondev_dev b16ad56b98 New password option fo the tenant adding and heatlth check
Release Inventarsystem / release-docker (push) Successful in 3m16s
2026-08-27 11:31:07 +02:00
Aiirondev_dev d2c21bc519 New password option fo the tenant adding and heatlth check
Release Inventarsystem / release-docker (push) Successful in 3m9s
2026-08-26 22:55:56 +02:00
Aiirondev_dev 4461644cb6 New password option fo the tenant adding
Release Inventarsystem / release-docker (push) Successful in 3m22s
2026-08-25 19:47:29 +02:00
2 changed files with 38 additions and 14 deletions
+6 -3
View File
@@ -542,7 +542,8 @@ def _enforce_module_access():
msg = {
'library': "Bibliotheks-Modul ist deaktiviert.",
'inventory': "Inventar-Modul ist deaktiviert.",
'student_cards': "Schülerausweis-Modul ist deaktiviert."
'student_cards': "Schülerausweis-Modul ist deaktiviert.",
'terminplaner': "Termin-Modul ist deaktiviert."
}.get(name, f"{name.capitalize()}-Modul ist deaktiviert.")
if request.path.startswith('/api/') or request.is_json:
@@ -554,6 +555,8 @@ def _enforce_module_access():
return redirect(url_for('home_admin'))
elif name != 'library' and cfg.MODULES.is_enabled('library'):
return redirect('/library')
elif name != 'terminplaner' and cfg.MODULES.is_enabled('terminplaner'):
return redirect('/terminplaner')
return redirect(url_for('my_borrowed_items'))
@@ -706,7 +709,7 @@ def _action_access_allowed(permissions, action_key):
def _permission_denied_fallback_endpoint(permissions, current_endpoint=None):
username = session.get('username')
for candidate in ('home_admin', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
for candidate in ('home_admin', 'library_view', 'terminplaner', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
if current_endpoint and candidate == current_endpoint:
continue
if _page_access_allowed(permissions, candidate):
@@ -13163,7 +13166,7 @@ def get_optimal_image_quality(img, target_size_kb=80):
@app.route('/health')
def health_check():
return 'OK', 200
return jsonify({"status": "healthy"}), 200
@app.route('/api/push/subscribe', methods=['POST'])
+32 -11
View File
@@ -430,6 +430,7 @@ PY
initialize_tenant_database() {
local tenant_id="$1"
local mode="$2"
local admin_password="${3:-admin123}"
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
if [ -z "$APP_CONTAINER" ]; then
@@ -438,7 +439,8 @@ initialize_tenant_database() {
return 0
fi
docker exec -i "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
# Fix: We inject the password securely via a temporary environment variable (-e ADMIN_PASS)
docker exec -i -e ADMIN_PASS="$admin_password" "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
import sys, os, re, datetime, hashlib
sys.path.insert(0, "/app")
sys.path.insert(0, "/app/Web")
@@ -449,6 +451,13 @@ import Web.modules.database.user as us
tenant_id = sys.argv[1].lower()
mode = sys.argv[2]
# Fix: Read the password directly from the environment variable instead of sys.argv
admin_password = os.environ.get("ADMIN_PASS", "admin123")
# Failsafe in case of empty string
if not admin_password.strip():
admin_password = "admin123"
sanitized = "".join(c for c in tenant_id if c.isalnum() or c == "_")
db_name = f"inventar_{sanitized}" if sanitized else settings.MONGODB_DB
@@ -458,7 +467,7 @@ users = db["users"]
permission_defaults = us.build_default_permission_payload("full_access")
admin_doc = {
"Username": "admin",
"Password": us.hashing("admin123"),
"Password": us.hashing(admin_password),
"Admin": True,
"active_ausleihung": None,
"name": dp.encrypt_text("admin"),
@@ -488,7 +497,7 @@ if mode == "trial":
client.close()
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / admin123")
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / {admin_password}")
PY
}
@@ -812,12 +821,26 @@ case "$COMMAND" in
exit 1
fi
PORT_ARG="${3:-}"
if [ -n "$PORT_ARG" ]; then
if ! printf '%s\n' "$PORT_ARG" | grep -qE '^[0-9]+$'; then
echo "Error: Port must be a numeric value."
exit 1
ARG3="${3:-}"
ARG4="${4:-}"
PORT_ARG=""
PASSWORD_ARG="admin123"
# Check if the 3rd argument is numeric (Port) or text (Password)
if [ -n "$ARG3" ]; then
if printf '%s\n' "$ARG3" | grep -qE '^[0-9]+$'; then
PORT_ARG="$ARG3"
if [ -n "$ARG4" ]; then
PASSWORD_ARG="$ARG4"
fi
else
# If ARG3 is not numeric, treat it as the password without setting a port
PASSWORD_ARG="$ARG3"
fi
fi
if [ -n "$PORT_ARG" ]; then
register_tenant_port "$TENANT_ID" "$PORT_ARG"
update_runtime_ports "$PORT_ARG"
sync_tenant_port_map
@@ -829,11 +852,9 @@ case "$COMMAND" in
fi
fi
echo "Adding new tenant '$TENANT_ID'..."
echo "Initializing database for $TENANT_ID..."
initialize_tenant_database "$TENANT_ID" "standard"
initialize_tenant_database "$TENANT_ID" "standard" "$PASSWORD_ARG"
echo "Tenant '$TENANT_ID' successfully added. Ready to use."
;;