From 10923164ad1b156ef2ae8ea9169033250501b8a0 Mon Sep 17 00:00:00 2001 From: Julian Cuni Date: Tue, 23 Jun 2026 18:37:52 +0200 Subject: [PATCH] fix(compose): pass COOKIE_SECURE, WS_ALLOWED_ORIGINS, EVENT_SIGNING_KEY, VISION_ENABLED MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The base compose only forwarded DATABASE_URL/VISION_URL/JWT_SECRET, so a booth deploy was missing the vars that actually make it usable on the plain-HTTP LAN: - COOKIE_SECURE (default 0) — without it auth cookies are HTTPS-only and operators CANNOT log in over http. The #1 booth-deploy footgun. - WS_ALLOWED_ORIGINS — the live-feed WS rejects the browser Origin without it. - EVENT_SIGNING_KEY — dedicated ledger key (falls back to JWT_SECRET if empty). - VISION_ENABLED=1 — the server's ANPR master switch. All driven from .env; verified via `docker compose config` that the seven vars resolve. Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V --- docker-compose.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docker-compose.yml b/docker-compose.yml index cf3f479..e9b7279 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -15,8 +15,19 @@ services: DATABASE_URL: /data/parking.sqlite # Reach the vision service over the private compose network by service name. VISION_URL: http://vision:8089 + VISION_ENABLED: ${VISION_ENABLED:-1} # JWT signing secret MUST be provided at deploy (no insecure default — see auth.ts). JWT_SECRET: ${JWT_SECRET:?set JWT_SECRET in the env/.env} + # Dedicated ledger-signing key. Falls back to JWT_SECRET (with a warning) if empty; + # set a distinct one in prod. See apps/server/.env.example + local-jwt-auth. + EVENT_SIGNING_KEY: ${EVENT_SIGNING_KEY:-} + # CRITICAL on the plain-HTTP booth LAN: cookies are Secure (HTTPS-only) by DEFAULT, + # so without COOKIE_SECURE=0 the auth cookie is never sent over http and operators + # CANNOT LOG IN. Leave unset only behind TLS. See disk-os-hardening "deploy-time runbook". + COOKIE_SECURE: ${COOKIE_SECURE:-0} + # The booth WS live feed checks the browser Origin — must list the address operators + # actually hit (e.g. http://:3000), or the live feed is rejected. + WS_ALLOWED_ORIGINS: ${WS_ALLOWED_ORIGINS:-} volumes: - parking-data:/data depends_on: