Files
appfactory-portal/app/config.py
T
JiriUhlir 7dffff17c7 Odstranil jsem hardcoded IP fallbacky z portálového Python kódu:
DEFAULT_APPFACTORY_HOST = "192.168.66.130" je pryč z config.py (line 10).
DEFAULT_GITEA_URL = "http://192.168.66.130:3000" je pryč z auth.py (line 24).
Doplněné chování:
APPFACTORY_HOST se odvozuje přes helper: env APPFACTORY_HOST, potom APPFACTORY_PORTAL_PUBLIC_URL, potom request host.
Gitea browser redirect používá jen explicitní veřejnou URL z GITEA_URL nebo GITEA_ROOT_URL.
Server-side Gitea token/userinfo requesty používají GITEA_URL, potom GITEA_ROOT_URL, jinak interní Docker URL http://appfactory-gitea:3000.
Gitea login tlačítko se zobrazí jen při kompletní konfiguraci: public URL, client id, client secret a redirect URI.
Přímý Gitea login bez kompletní konfigurace vrací čitelnou chybu.
2026-06-08 11:38:57 +02:00

123 lines
3.6 KiB
Python

DEPLOY_SCRIPT = "/tools/deploy-app.sh"
DELETE_APP_SCRIPT = "/tools/delete-app.sh"
BACKUP_SCRIPT = "/tools/backup-appfactory.sh"
GENERATE_COMPOSE_SCRIPT = "/tools/generate-apps-compose.sh"
CATALOG_FILE = "/opt/appfactory/apps/catalog.yml"
APPFACTORY_ENV = "/opt/appfactory/config/appfactory.env"
DEFAULT_BACKUP_DIR = "/opt/appfactory/backups"
DEFAULT_GITEA_ORG = "appfactory"
INTERNAL_GITEA_URL = "http://appfactory-gitea:3000"
PORTAL_PREFIX = "/portal"
def read_env_value(key: str, default: str = "") -> str:
try:
with open(APPFACTORY_ENV, "r", encoding="utf-8") as f:
for line in f:
line = line.strip()
if line.startswith(f"{key}="):
return line.split("=", 1)[1].strip().strip('"')
except Exception:
pass
return default
def read_env_bool(key: str, default: bool = False) -> bool:
value = read_env_value(key, "")
if value == "":
return default
return value.strip().lower() in {"1", "true", "yes", "on"}
def get_portal_public_url() -> str:
public_url = read_env_value("APPFACTORY_PORTAL_PUBLIC_URL", "").rstrip("/")
if public_url:
return public_url
domain = read_env_value("APPFACTORY_PORTAL_DOMAIN", "").strip()
if read_env_bool("APPFACTORY_ENABLE_HTTPS") and domain:
return f"https://{domain}"
return ""
def get_google_redirect_uri() -> str:
redirect_uri = read_env_value("GOOGLE_REDIRECT_URI", "").strip()
if redirect_uri:
return redirect_uri
public_url = get_portal_public_url()
if public_url:
return f"{public_url}/auth/google/callback"
return ""
def get_gitea_public_url() -> str:
return (read_env_value("GITEA_URL", "") or read_env_value("GITEA_ROOT_URL", "")).rstrip("/")
def get_gitea_server_url() -> str:
return get_gitea_public_url() or INTERNAL_GITEA_URL
def get_gitea_redirect_uri() -> str:
redirect_uri = read_env_value("GITEA_OAUTH_REDIRECT_URI", "").strip()
if redirect_uri:
return redirect_uri
public_url = get_portal_public_url()
if public_url:
return f"{public_url}/auth/gitea/callback"
return ""
def is_gitea_oauth_button_enabled() -> bool:
return bool(
get_gitea_public_url()
and read_env_value("GITEA_OAUTH_CLIENT_ID", "")
and read_env_value("GITEA_OAUTH_CLIENT_SECRET", "")
and get_gitea_redirect_uri()
)
def get_appfactory_host(request_host: str = "") -> str:
configured_host = read_env_value("APPFACTORY_HOST", "").strip()
if configured_host:
return configured_host
public_url = get_portal_public_url()
if public_url:
return public_url.split("://", 1)[-1].split("/", 1)[0].split(":", 1)[0]
return (request_host or "").split(":", 1)[0]
def get_auth_domain_readiness() -> dict[str, bool]:
google_enabled = read_env_bool("GOOGLE_OAUTH_ENABLED")
google_client_id = read_env_value("GOOGLE_CLIENT_ID", "")
google_client_secret = read_env_value("GOOGLE_CLIENT_SECRET", "")
google_redirect_uri = get_google_redirect_uri()
return {
"portal_public_url_configured": bool(get_portal_public_url()),
"google_oauth_enabled": google_enabled,
"google_oauth_configured": bool(google_client_id and google_client_secret and google_redirect_uri),
"google_redirect_uri_configured": bool(google_redirect_uri),
"https_enabled": read_env_bool("APPFACTORY_ENABLE_HTTPS"),
}
def is_google_oauth_button_enabled() -> bool:
return bool(
read_env_bool("GOOGLE_OAUTH_ENABLED")
and read_env_value("GOOGLE_CLIENT_ID", "")
and read_env_value("GOOGLE_CLIENT_SECRET", "")
)