SendSecret: Erstimport und Umstellung auf Tag-Deployment
Wrapper-Frontend vor cryptgeon: der Browser verschluesselt lokal, per Mail geht nur der Link raus. Fuer das Deployment nach den Konventionen aus DEPLOY.md hergerichtet: - docker-compose.yml mit festem Projekt- und Container-Namen, kein ports-Mapping, Healthcheck als Deploy-Gate. cryptgeon und redis liegen im internen Netz, nur app haengt im Web-Netz. - cryptgeon von latest auf 2.9.3 gepinnt. Das ist derselbe Stand, den latest bisher geliefert hat; 2.6.2 existiert nicht. - /healthz in server.js, vor dem Catch-all-Proxy registriert. - Dockerfile auf npm ci mit Lockfile und non-root umgestellt. - .gitea/workflows/deploy.yml: Build und Syntaxpruefung vor dem Deploy, .env aus dem Repo-Secret DOTENV. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
33
app/build.js
Normal file
33
app/build.js
Normal file
@@ -0,0 +1,33 @@
|
||||
'use strict'
|
||||
|
||||
const { build } = require('esbuild')
|
||||
const { mkdirSync } = require('fs')
|
||||
|
||||
mkdirSync('public', { recursive: true })
|
||||
|
||||
// occulto uses require('crypto') internally; shim it to the browser Web Crypto API
|
||||
const cryptoBrowserShim = {
|
||||
name: 'crypto-browser-shim',
|
||||
setup(b) {
|
||||
b.onResolve({ filter: /^crypto$/ }, () => ({
|
||||
path: 'crypto',
|
||||
namespace: 'crypto-browser-shim',
|
||||
}))
|
||||
b.onLoad({ filter: /.*/, namespace: 'crypto-browser-shim' }, () => ({
|
||||
contents: 'module.exports = { webcrypto: globalThis.crypto }',
|
||||
}))
|
||||
},
|
||||
}
|
||||
|
||||
build({
|
||||
entryPoints: ['src/customer.js', 'src/link.js'],
|
||||
bundle: true,
|
||||
outdir: 'public',
|
||||
format: 'iife',
|
||||
target: ['es2020'],
|
||||
minify: true,
|
||||
platform: 'browser',
|
||||
plugins: [cryptoBrowserShim],
|
||||
})
|
||||
.then(() => console.log('✓ Bundles built: public/customer.js, public/link.js'))
|
||||
.catch((err) => { console.error(err); process.exit(1) })
|
||||
Reference in New Issue
Block a user