All checks were successful
CI / Build container images (push) Has been skipped
CI / Lint, typecheck, test (push) Successful in 2m57s
CI / Import/export fidelity gate (push) Successful in 46s
CD / Build and push images (push) Successful in 3m16s
CD / Deploy to Test (push) Successful in 8s
CI / Auth e2e pack (push) Successful in 4m8s
CD / Smoke tests against Test (push) Successful in 1m9s
CD / Promote to Int (push) Successful in 10s
Implements the security core of the plugin system: code-plugin surfaces run in opaque-origin iframes (sandbox="allow-scripts", never allow-same-origin) with a capability-filtered RPC bridge. - api: serve a per-plugin sandbox frame document at /plugins/:id/:version/frame with a CSP that pins every load to the plugin's own asset path (built from APP_BASE_URL, not the request Host, so a Host-rewriting proxy cannot break it) and forbids network access (connect-src 'none'). Plugin assets get Access-Control-Allow-Origin: * so the null-origin frame can load its own module bundle. - web: sandbox-host creates the frame, wires the SDK host bridge over a source-filtered postMessage transport, drives render under a 5 s deadline (hung/failed plugin -> placeholder, never a frozen page), and tears down on unmount. PluginFrame/PluginPreviewPage surface it; the built-in ui.resize handler clamps plugin-requested heights. - plugin-sdk: host bridge reports gate violations via onViolation and registers a gated handler for every v1 method, so an undeclared capability is rejected with capability_not_permitted (not unknown_method). - tests: SDK gate unit test; web sandbox unit tests (opaque origin, source filtering, timeout); and the e2e security pack with a permanent malicious fixture plugin proving no escape (DOM/cookies/storage/fetch/ undeclared capability all blocked) plus well-behaved and hung cases. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
30 lines
1.3 KiB
Docker
30 lines
1.3 KiB
Docker
# Build context is the repository root (workspace build):
|
|
# docker build -f apps/web/Dockerfile .
|
|
|
|
FROM node:22.15-alpine AS build
|
|
ARG APP_VERSION=0.0.0-dev
|
|
WORKDIR /repo
|
|
RUN npm install -g pnpm@11
|
|
COPY pnpm-workspace.yaml pnpm-lock.yaml package.json tsconfig.base.json ./
|
|
COPY packages/shared ./packages/shared
|
|
COPY packages/plugin-sdk ./packages/plugin-sdk
|
|
COPY apps/web ./apps/web
|
|
COPY deploy/fonts ./deploy/fonts
|
|
# Build the workspace deps (shared + plugin-sdk), then download the catalog
|
|
# fonts into the web app (ADR 0016: self-hosted, baked into the image — never
|
|
# fetched from a visitor's browser), then build. The font step fails the image
|
|
# build if a family lacks license info.
|
|
RUN pnpm install --frozen-lockfile --filter @dorfteich/web... \
|
|
&& pnpm --filter @dorfteich/shared build \
|
|
&& pnpm --filter @dorfteich/plugin-sdk build \
|
|
&& node deploy/fonts/build-fonts.mjs \
|
|
&& VITE_APP_VERSION=${APP_VERSION} pnpm --filter @dorfteich/web build
|
|
|
|
# nginx-unprivileged runs as uid 101 and listens on 8080 — no root needed.
|
|
FROM nginxinc/nginx-unprivileged:1.27-alpine
|
|
COPY apps/web/nginx.conf /etc/nginx/conf.d/default.conf
|
|
COPY --from=build /repo/apps/web/dist /usr/share/nginx/html
|
|
EXPOSE 8080
|
|
HEALTHCHECK --interval=30s --timeout=3s --retries=3 \
|
|
CMD wget -q -O /dev/null http://127.0.0.1:8080/healthz || exit 1
|