nextcloud: give the admin password a real _FILE variant, not an env-file
The mesh's own check caught it: an env-file-loaded secret still reaches the process environment, readable via docker inspect and /proc (hq 04-ISSUES/041) -- the same class of exposure the file-based delivery exists to avoid. Added MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE support to the client, matching the pattern the minio client already uses, and mounted the sealed admin secret directly rather than writing it into an env-file.
This commit is contained in:
@@ -52,8 +52,13 @@ export class NextcloudClient {
|
||||
const container = cfg.container ?? env.MESH_NEXTCLOUD_CONTAINER ?? "nextcloud";
|
||||
const ocsUrl = cfg.url ?? env.MESH_NEXTCLOUD_URL ?? `http://127.0.0.1:${env.NEXTCLOUD_PORT ?? "80"}`;
|
||||
const adminUser = cfg.user ?? env.MESH_NEXTCLOUD_ADMIN_USER ?? "admin";
|
||||
const adminPassword = cfg.password ?? env.MESH_NEXTCLOUD_ADMIN_PASSWORD;
|
||||
if (!adminPassword) throw new Error("no Nextcloud admin password — set MESH_NEXTCLOUD_ADMIN_PASSWORD");
|
||||
const passwordFile = env.MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE;
|
||||
const adminPassword = cfg.password ?? env.MESH_NEXTCLOUD_ADMIN_PASSWORD
|
||||
?? (passwordFile ? readFileSync(passwordFile, "utf8").trim() : undefined);
|
||||
if (!adminPassword) {
|
||||
throw new Error("no Nextcloud admin password — set MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE " +
|
||||
"(or MESH_NEXTCLOUD_ADMIN_PASSWORD)");
|
||||
}
|
||||
return new NextcloudClient(container, ocsUrl.replace(/\/$/, ""), adminUser, adminPassword);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user