Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| b16ad56b98 | |||
| d2c21bc519 | |||
| 4461644cb6 |
+6
-3
@@ -542,7 +542,8 @@ def _enforce_module_access():
|
||||
msg = {
|
||||
'library': "Bibliotheks-Modul ist deaktiviert.",
|
||||
'inventory': "Inventar-Modul ist deaktiviert.",
|
||||
'student_cards': "Schülerausweis-Modul ist deaktiviert."
|
||||
'student_cards': "Schülerausweis-Modul ist deaktiviert.",
|
||||
'terminplaner': "Termin-Modul ist deaktiviert."
|
||||
}.get(name, f"{name.capitalize()}-Modul ist deaktiviert.")
|
||||
|
||||
if request.path.startswith('/api/') or request.is_json:
|
||||
@@ -554,6 +555,8 @@ def _enforce_module_access():
|
||||
return redirect(url_for('home_admin'))
|
||||
elif name != 'library' and cfg.MODULES.is_enabled('library'):
|
||||
return redirect('/library')
|
||||
elif name != 'terminplaner' and cfg.MODULES.is_enabled('terminplaner'):
|
||||
return redirect('/terminplaner')
|
||||
|
||||
return redirect(url_for('my_borrowed_items'))
|
||||
|
||||
@@ -706,7 +709,7 @@ def _action_access_allowed(permissions, action_key):
|
||||
def _permission_denied_fallback_endpoint(permissions, current_endpoint=None):
|
||||
username = session.get('username')
|
||||
|
||||
for candidate in ('home_admin', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
|
||||
for candidate in ('home_admin', 'library_view', 'terminplaner', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
|
||||
if current_endpoint and candidate == current_endpoint:
|
||||
continue
|
||||
if _page_access_allowed(permissions, candidate):
|
||||
@@ -13163,7 +13166,7 @@ def get_optimal_image_quality(img, target_size_kb=80):
|
||||
|
||||
@app.route('/health')
|
||||
def health_check():
|
||||
return 'OK', 200
|
||||
return jsonify({"status": "healthy"}), 200
|
||||
|
||||
|
||||
@app.route('/api/push/subscribe', methods=['POST'])
|
||||
|
||||
+32
-11
@@ -430,6 +430,7 @@ PY
|
||||
initialize_tenant_database() {
|
||||
local tenant_id="$1"
|
||||
local mode="$2"
|
||||
local admin_password="${3:-admin123}"
|
||||
|
||||
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
|
||||
if [ -z "$APP_CONTAINER" ]; then
|
||||
@@ -438,7 +439,8 @@ initialize_tenant_database() {
|
||||
return 0
|
||||
fi
|
||||
|
||||
docker exec -i "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
|
||||
# Fix: We inject the password securely via a temporary environment variable (-e ADMIN_PASS)
|
||||
docker exec -i -e ADMIN_PASS="$admin_password" "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
|
||||
import sys, os, re, datetime, hashlib
|
||||
sys.path.insert(0, "/app")
|
||||
sys.path.insert(0, "/app/Web")
|
||||
@@ -449,6 +451,13 @@ import Web.modules.database.user as us
|
||||
|
||||
tenant_id = sys.argv[1].lower()
|
||||
mode = sys.argv[2]
|
||||
|
||||
# Fix: Read the password directly from the environment variable instead of sys.argv
|
||||
admin_password = os.environ.get("ADMIN_PASS", "admin123")
|
||||
# Failsafe in case of empty string
|
||||
if not admin_password.strip():
|
||||
admin_password = "admin123"
|
||||
|
||||
sanitized = "".join(c for c in tenant_id if c.isalnum() or c == "_")
|
||||
db_name = f"inventar_{sanitized}" if sanitized else settings.MONGODB_DB
|
||||
|
||||
@@ -458,7 +467,7 @@ users = db["users"]
|
||||
permission_defaults = us.build_default_permission_payload("full_access")
|
||||
admin_doc = {
|
||||
"Username": "admin",
|
||||
"Password": us.hashing("admin123"),
|
||||
"Password": us.hashing(admin_password),
|
||||
"Admin": True,
|
||||
"active_ausleihung": None,
|
||||
"name": dp.encrypt_text("admin"),
|
||||
@@ -488,7 +497,7 @@ if mode == "trial":
|
||||
|
||||
client.close()
|
||||
|
||||
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / admin123")
|
||||
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / {admin_password}")
|
||||
PY
|
||||
}
|
||||
|
||||
@@ -812,12 +821,26 @@ case "$COMMAND" in
|
||||
exit 1
|
||||
fi
|
||||
|
||||
PORT_ARG="${3:-}"
|
||||
if [ -n "$PORT_ARG" ]; then
|
||||
if ! printf '%s\n' "$PORT_ARG" | grep -qE '^[0-9]+$'; then
|
||||
echo "Error: Port must be a numeric value."
|
||||
exit 1
|
||||
ARG3="${3:-}"
|
||||
ARG4="${4:-}"
|
||||
|
||||
PORT_ARG=""
|
||||
PASSWORD_ARG="admin123"
|
||||
|
||||
# Check if the 3rd argument is numeric (Port) or text (Password)
|
||||
if [ -n "$ARG3" ]; then
|
||||
if printf '%s\n' "$ARG3" | grep -qE '^[0-9]+$'; then
|
||||
PORT_ARG="$ARG3"
|
||||
if [ -n "$ARG4" ]; then
|
||||
PASSWORD_ARG="$ARG4"
|
||||
fi
|
||||
else
|
||||
# If ARG3 is not numeric, treat it as the password without setting a port
|
||||
PASSWORD_ARG="$ARG3"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -n "$PORT_ARG" ]; then
|
||||
register_tenant_port "$TENANT_ID" "$PORT_ARG"
|
||||
update_runtime_ports "$PORT_ARG"
|
||||
sync_tenant_port_map
|
||||
@@ -829,11 +852,9 @@ case "$COMMAND" in
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
|
||||
echo "Adding new tenant '$TENANT_ID'..."
|
||||
echo "Initializing database for $TENANT_ID..."
|
||||
initialize_tenant_database "$TENANT_ID" "standard"
|
||||
initialize_tenant_database "$TENANT_ID" "standard" "$PASSWORD_ARG"
|
||||
echo "Tenant '$TENANT_ID' successfully added. Ready to use."
|
||||
;;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user