#!/bin/bash # capture-dsh-token.sh — start dsh-web, capture its token, update nginx # Run on CT112 (tankodhs.sysloggh.net) # This script: # 1. Restarts the dsh-web service # 2. Captures the token URL from the journal # 3. Extracts the token value # 4. Writes the token to /etc/dsh-web/launch-token # 5. Creates an nginx config that exposes a /dsh-web-login endpoint # 6. Reloads nginx set -euo pipefail umask 077 # Kill any existing dsh-web instance first systemctl stop dsh-web 2>/dev/null || true sleep 2 # Record the time we started the service (for --since filter) START_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)" # Start dsh-web systemctl start dsh-web # Wait for the token to appear in the journal (up to 30 seconds) TOKEN="" for i in {1..30}; do TOKEN=$(journalctl -u dsh-web.service --since "$START_TIME" --output=cat 2>/dev/null | grep -m1 "dsh web: http://" | grep -oP "(?<=dsh web: )(https?://[^ ]+)" | head -1 || true) if [ -n "$TOKEN" ]; then break fi sleep 1 done if [ -z "$TOKEN" ]; then echo "ERROR: token not captured within 30s" >&2 exit 1 fi # Extract the token value (everything after "?token=") TOKEN_VALUE=$(echo "$TOKEN" | grep -oP "(?<=token=)[^ ]+") # Reject tokens that could break nginx config or the request URI if ! printf '%s' "$TOKEN_VALUE" | grep -qE '^[A-Za-z0-9._~+/=%:@-]+$'; then echo "ERROR: token contains unsupported characters" >&2 exit 1 fi # Write the token to a restricted file mkdir -p /etc/dsh-web printf '%s\n' "$TOKEN_VALUE" > /etc/dsh-web/launch-token chmod 600 /etc/dsh-web/launch-token echo "Captured dsh-web launch token" # Create the nginx config with the token (using printf to control expansion) NGINX_ENABLED="/etc/nginx/sites-enabled/dsh.token" NGINX_STAGE_DIR="/etc/nginx/sites-available" mkdir -p "$NGINX_STAGE_DIR" TMP_CONFIG="$(mktemp "$NGINX_STAGE_DIR/dsh.token.XXXXXX")" BACKUP="" if [ -f "$NGINX_ENABLED" ]; then BACKUP="$(mktemp "$NGINX_STAGE_DIR/dsh.token.bak.XXXXXX")" cp -p "$NGINX_ENABLED" "$BACKUP" fi { printf "server {\n" printf " listen 127.0.0.1:8081;\n" printf " server_name _;\n" printf " \n" printf " location = /dsh-web-login {\n" printf " proxy_pass http://127.0.0.1:3080/?token=%s;\n" "$TOKEN_VALUE" printf " proxy_http_version 1.1;\n" printf " proxy_set_header Host 127.0.0.1:3080;\n" printf " proxy_set_header X-Real-IP \$remote_addr;\n" printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n" printf " }\n" printf " \n" printf " location / {\n" printf " proxy_pass http://127.0.0.1:3080;\n" printf " proxy_http_version 1.1;\n" printf " proxy_set_header Host 127.0.0.1:3080;\n" printf " proxy_set_header X-Real-IP \$remote_addr;\n" printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n" printf " }\n" printf "}\n" } > "$TMP_CONFIG" chmod 600 "$TMP_CONFIG" mv "$TMP_CONFIG" "$NGINX_ENABLED" CONFIG_APPLIED=1 restore_on_exit() { if [ "$CONFIG_APPLIED" -eq 1 ]; then if [ -n "$BACKUP" ]; then if cp -p "$BACKUP" "$NGINX_ENABLED" 2>/dev/null; then rm -f "$BACKUP"; fi else rm -f "$NGINX_ENABLED" fi fi } trap restore_on_exit EXIT if nginx -t; then /usr/sbin/nginx -s reload CONFIG_APPLIED=0 if [ -n "$BACKUP" ]; then rm -f "$BACKUP"; fi echo "Token captured and nginx reloaded" else echo "ERROR: nginx config test failed; rolling back" >&2 exit 1 fi