113 lines
3.4 KiB
Bash
Executable File
113 lines
3.4 KiB
Bash
Executable File
#!/bin/bash
|
|
# capture-dsh-token.sh — start dsh-web, capture its token, update nginx
|
|
# Run on CT112 (tankodhs.sysloggh.net)
|
|
# This script:
|
|
# 1. Restarts the dsh-web service
|
|
# 2. Captures the token URL from the journal
|
|
# 3. Extracts the token value
|
|
# 4. Writes the token to /etc/dsh-web/launch-token
|
|
# 5. Creates an nginx config that exposes a /dsh-web-login endpoint
|
|
# 6. Reloads nginx
|
|
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
# Kill any existing dsh-web instance first
|
|
systemctl stop dsh-web 2>/dev/null || true
|
|
sleep 2
|
|
|
|
# Record the time we started the service (for --since filter)
|
|
START_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
|
|
|
# Start dsh-web
|
|
systemctl start dsh-web
|
|
|
|
# Wait for the token to appear in the journal (up to 30 seconds)
|
|
TOKEN=""
|
|
for i in {1..30}; do
|
|
TOKEN=$(journalctl -u dsh-web.service --since "$START_TIME" --output=cat 2>/dev/null | grep -m1 "dsh web: http://" | grep -oP "(?<=dsh web: )(https?://[^ ]+)" | head -1 || true)
|
|
if [ -n "$TOKEN" ]; then
|
|
break
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
if [ -z "$TOKEN" ]; then
|
|
echo "ERROR: token not captured within 30s" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Extract the token value (everything after "?token=")
|
|
TOKEN_VALUE=$(echo "$TOKEN" | grep -oP "(?<=token=)[^ ]+")
|
|
|
|
# Reject tokens that could break nginx config or the request URI
|
|
if ! printf '%s' "$TOKEN_VALUE" | grep -qE '^[A-Za-z0-9._~+/=%:@-]+$'; then
|
|
echo "ERROR: token contains unsupported characters" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Write the token to a restricted file
|
|
mkdir -p /etc/dsh-web
|
|
printf '%s\n' "$TOKEN_VALUE" > /etc/dsh-web/launch-token
|
|
chmod 600 /etc/dsh-web/launch-token
|
|
echo "Captured dsh-web launch token"
|
|
|
|
# Create the nginx config with the token (using printf to control expansion)
|
|
NGINX_ENABLED="/etc/nginx/sites-enabled/dsh.token"
|
|
NGINX_STAGE_DIR="/etc/nginx/sites-available"
|
|
mkdir -p "$NGINX_STAGE_DIR"
|
|
|
|
TMP_CONFIG="$(mktemp "$NGINX_STAGE_DIR/dsh.token.XXXXXX")"
|
|
BACKUP=""
|
|
if [ -f "$NGINX_ENABLED" ]; then
|
|
BACKUP="$(mktemp "$NGINX_STAGE_DIR/dsh.token.bak.XXXXXX")"
|
|
cp -p "$NGINX_ENABLED" "$BACKUP"
|
|
fi
|
|
|
|
{
|
|
printf "server {\n"
|
|
printf " listen 127.0.0.1:8081;\n"
|
|
printf " server_name _;\n"
|
|
printf " \n"
|
|
printf " location = /dsh-web-login {\n"
|
|
printf " proxy_pass http://127.0.0.1:3080/?token=%s;\n" "$TOKEN_VALUE"
|
|
printf " proxy_http_version 1.1;\n"
|
|
printf " proxy_set_header Host 127.0.0.1:3080;\n"
|
|
printf " proxy_set_header X-Real-IP \$remote_addr;\n"
|
|
printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n"
|
|
printf " }\n"
|
|
printf " \n"
|
|
printf " location / {\n"
|
|
printf " proxy_pass http://127.0.0.1:3080;\n"
|
|
printf " proxy_http_version 1.1;\n"
|
|
printf " proxy_set_header Host 127.0.0.1:3080;\n"
|
|
printf " proxy_set_header X-Real-IP \$remote_addr;\n"
|
|
printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n"
|
|
printf " }\n"
|
|
printf "}\n"
|
|
} > "$TMP_CONFIG"
|
|
chmod 600 "$TMP_CONFIG"
|
|
|
|
mv "$TMP_CONFIG" "$NGINX_ENABLED"
|
|
CONFIG_APPLIED=1
|
|
restore_on_exit() {
|
|
if [ "$CONFIG_APPLIED" -eq 1 ]; then
|
|
if [ -n "$BACKUP" ]; then
|
|
if cp -p "$BACKUP" "$NGINX_ENABLED" 2>/dev/null; then rm -f "$BACKUP"; fi
|
|
else
|
|
rm -f "$NGINX_ENABLED"
|
|
fi
|
|
fi
|
|
}
|
|
trap restore_on_exit EXIT
|
|
|
|
if nginx -t; then
|
|
/usr/sbin/nginx -s reload
|
|
CONFIG_APPLIED=0
|
|
if [ -n "$BACKUP" ]; then rm -f "$BACKUP"; fi
|
|
echo "Token captured and nginx reloaded"
|
|
else
|
|
echo "ERROR: nginx config test failed; rolling back" >&2
|
|
exit 1
|
|
fi
|