Files
prose-contracts/scripts/capture-dsh-token.sh
T
abiba-bot b2a259fa23 fix: add dsh-web restart-persistent authentication
- Add capture-dsh-token.sh script that captures the dsh-web launch token
- Add login endpoint (/dsh-web-login on :8081) that mints 30-day auth cookie
- Document the authentication flow in zulip-health.prose.md (Platform B4)
- Cookie is authority-bound to 127.0.0.1:3080 with 30-day expiry
- After first login, subsequent requests use the cookie — no token required
2026-09-11 14:56:57 +00:00

78 lines
2.4 KiB
Bash
Executable File

#!/bin/bash
# capture-dsh-token.sh — start dsh-web, capture its token, update nginx
# Run on CT112 (tankodhs.sysloggh.net)
# This script:
# 1. Restarts the dsh-web service
# 2. Captures the token URL from the journal
# 3. Extracts the token value
# 4. Writes the token to /etc/dsh-web/launch-token
# 5. Creates an nginx config that exposes a /dsh-web-login endpoint
# 6. Reloads nginx
set -euo pipefail
# Kill any existing dsh-web instance first
systemctl stop dsh-web 2>/dev/null || true
sleep 2
# Record the time we started the service (for --since filter)
START_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
# Start dsh-web
systemctl start dsh-web
# Wait for the token to appear in the journal (up to 30 seconds)
TOKEN=""
for i in {1..30}; do
TOKEN=$(journalctl -u dsh-web.service --since "$START_TIME" --output=cat 2>/dev/null | grep -m1 "dsh web: http://" | grep -oP "(?<=dsh web: )(https?://[^ ]+)" | head -1 || true)
if [ -n "$TOKEN" ]; then
break
fi
sleep 1
done
if [ -z "$TOKEN" ]; then
echo "ERROR: token not captured within 30s" >&2
exit 1
fi
# Extract the token value (everything after "?token=")
TOKEN_VALUE=$(echo "$TOKEN" | grep -oP "(?<=token=)[^ ]+")
# Write the token to a file
mkdir -p /etc/dsh-web
echo "$TOKEN_VALUE" > /etc/dsh-web/launch-token
echo "Captured token: $TOKEN_VALUE"
# Create the nginx config with the token (using printf to control expansion)
{
printf "server {\n"
printf " listen 8081;\n"
printf " server_name _;\n"
printf " \n"
printf " location /dsh-web-login {\n"
printf " proxy_pass http://127.0.0.1:3080/?token=%s;\n" "$TOKEN_VALUE"
printf " proxy_http_version 1.1;\n"
printf " proxy_set_header Host 127.0.0.1:3080;\n"
printf " proxy_set_header X-Real-IP \$remote_addr;\n"
printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n"
printf " }\n"
printf " \n"
printf " location / {\n"
printf " proxy_pass http://127.0.0.1:3080;\n"
printf " proxy_http_version 1.1;\n"
printf " proxy_set_header Host 127.0.0.1:3080;\n"
printf " proxy_set_header X-Real-IP \$remote_addr;\n"
printf " proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;\n"
printf " }\n"
printf "}\n"
} > /etc/nginx/sites-enabled/dsh.token
# Reload nginx
nginx -t && /usr/sbin/nginx -s reload || {
echo "ERROR: failed to reload nginx" >&2
exit 1
}
echo "Token captured and nginx reloaded"