fix(compose): pass COOKIE_SECURE, WS_ALLOWED_ORIGINS, EVENT_SIGNING_KEY, VISION_ENABLED
The base compose only forwarded DATABASE_URL/VISION_URL/JWT_SECRET, so a booth deploy was missing the vars that actually make it usable on the plain-HTTP LAN: - COOKIE_SECURE (default 0) — without it auth cookies are HTTPS-only and operators CANNOT log in over http. The #1 booth-deploy footgun. - WS_ALLOWED_ORIGINS — the live-feed WS rejects the browser Origin without it. - EVENT_SIGNING_KEY — dedicated ledger key (falls back to JWT_SECRET if empty). - VISION_ENABLED=1 — the server's ANPR master switch. All driven from .env; verified via `docker compose config` that the seven vars resolve. Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
This commit is contained in:
@@ -15,8 +15,19 @@ services:
|
||||
DATABASE_URL: /data/parking.sqlite
|
||||
# Reach the vision service over the private compose network by service name.
|
||||
VISION_URL: http://vision:8089
|
||||
VISION_ENABLED: ${VISION_ENABLED:-1}
|
||||
# JWT signing secret MUST be provided at deploy (no insecure default — see auth.ts).
|
||||
JWT_SECRET: ${JWT_SECRET:?set JWT_SECRET in the env/.env}
|
||||
# Dedicated ledger-signing key. Falls back to JWT_SECRET (with a warning) if empty;
|
||||
# set a distinct one in prod. See apps/server/.env.example + local-jwt-auth.
|
||||
EVENT_SIGNING_KEY: ${EVENT_SIGNING_KEY:-}
|
||||
# CRITICAL on the plain-HTTP booth LAN: cookies are Secure (HTTPS-only) by DEFAULT,
|
||||
# so without COOKIE_SECURE=0 the auth cookie is never sent over http and operators
|
||||
# CANNOT LOG IN. Leave unset only behind TLS. See disk-os-hardening "deploy-time runbook".
|
||||
COOKIE_SECURE: ${COOKIE_SECURE:-0}
|
||||
# The booth WS live feed checks the browser Origin — must list the address operators
|
||||
# actually hit (e.g. http://<booth-ip>:3000), or the live feed is rejected.
|
||||
WS_ALLOWED_ORIGINS: ${WS_ALLOWED_ORIGINS:-}
|
||||
volumes:
|
||||
- parking-data:/data
|
||||
depends_on:
|
||||
|
||||
Reference in New Issue
Block a user