chore(release): public-release readiness fixes for 1.1.16
- Fix MIT LICENSE copyright placeholder - Remove private flag and correct GitHub repository URL in package.json - Bump version to 1.1.16 - Genericize committed config defaults (example.com/localhost) - Harden global error handler against information leakage - Generate random initial password for proxyadmin2 bootstrap account - Correct docs to describe CONF_SECRETS instead of symlink behavior Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
+6
-5
@@ -75,11 +75,12 @@ $EDITOR config/proxy-secrets.js # set oidc.clientId/clientSecret, ldap.bindP
|
||||
docker compose up -d --build
|
||||
```
|
||||
|
||||
`docker-entrypoint.sh` symlinks `/config/proxy-secrets.js` → `/app/conf/secrets.js`
|
||||
so `@simpleworkjs/conf` reads it. No `app_*` env is passed — `app_*` env would
|
||||
override the file (env beats secrets.js in `@simpleworkjs/conf`), so the file is
|
||||
kept authoritative. `RESOLVER` / `REAL_IP_FROM` / `NODE_ENV` / `NODE_PORT` are
|
||||
OpenResty-runtime / process env, not `app_*` config, so they stay in the compose.
|
||||
`docker-entrypoint.sh` sets `CONF_SECRETS=/config/proxy-secrets.js` so
|
||||
`@simpleworkjs/conf` reads it directly. No `app_*` env is passed — `app_*` env
|
||||
would override the file (env beats secrets.js in `@simpleworkjs/conf`), so the
|
||||
file is kept authoritative. `RESOLVER` / `REAL_IP_FROM` / `NODE_ENV` /
|
||||
`NODE_PORT` are OpenResty-runtime / process env, not `app_*` config, so they
|
||||
stay in the compose.
|
||||
|
||||
> Running the unified `theta-env` stack? Its `setup.sh` generates
|
||||
> `./config/proxy-secrets.js` (+ `./config/sso-secrets.js`) for you and
|
||||
|
||||
Reference in New Issue
Block a user