Docker-Images bauen und veröffentlichen / build (, omsorgCore/Dockerfile, omsorgcore) (push) Successful in 3s
Docker-Images bauen und veröffentlichen / build (, omsorgWeb/Dockerfile, omsorgweb) (push) Successful in 4s
Docker-Images bauen und veröffentlichen / build (, omsorgapp/Dockerfile, omsorgapp) (push) Successful in 3s
The root .htaccess forces HTTPS via `RewriteCond %{HTTPS} !=on`. Behind a
reverse proxy that terminates TLS and forwards to Apache over plain HTTP,
%{HTTPS} is always "off" - verified via mod_rewrite trace logging that
this is NOT spoofable via SetEnvIf or a RewriteRule E-flag, despite that
being commonly recommended; %{HTTPS} reflects only the actual TLS
connection to Apache. Every request was therefore redirected to https://,
which the proxy forwarded back over HTTP, looping forever (browser: "the
page isn't redirecting properly").
Fix: .htaccess's redirect condition also accepts a trusted
X-Forwarded-Proto: https header as evidence the request is already
HTTPS. omsorgWeb/docker/000-default.conf additionally sets HTTPS=on in
the request environment when that header is present, so mod_headers'
`env=HTTPS` condition (HSTS header) still fires correctly - this part
doesn't affect mod_rewrite's %{HTTPS} but is unrelated to the redirect fix.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
47 lines
2.5 KiB
Docker
47 lines
2.5 KiB
Docker
# Build-Kontext ist der Repo-Root (siehe .gitea/workflows/docker-build.yml und docker-compose.yml) -
|
|
# nötig, um zusätzlich zu omsorgWeb/ auch die Root-.htaccess (liegt bewusst außerhalb von
|
|
# omsorgWeb/, siehe README.txt "upload directory contents to htdocs") mit ins Image zu kopieren.
|
|
FROM php:8.2-apache
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends libcurl4-openssl-dev libonig-dev \
|
|
&& docker-php-ext-install pdo_mysql mbstring curl \
|
|
&& a2enmod rewrite headers \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Debians Standard-apache2.conf setzt AllowOverride None für /var/www/ - ohne dieses Drop-in
|
|
# würden alle .htaccess-Regeln der App stillschweigend ignoriert (siehe Datei-Kommentar).
|
|
COPY omsorgWeb/docker/allow-htaccess.conf /etc/apache2/conf-available/allow-htaccess.conf
|
|
RUN a2enconf allow-htaccess
|
|
|
|
# Ersetzt die mitgelieferte Default-vhost (identisch, nur mit einer zusätzlichen Rewrite-Regel,
|
|
# die den TLS-terminierenden Host-nginx davor erkennt - sonst redirected die root-.htaccess
|
|
# endlos, siehe Datei-Kommentar. Muss im <VirtualHost>-Block selbst stehen, ein conf-enabled-Drop-in
|
|
# außerhalb davon wird nicht mit der .htaccess desselben Pfads zusammengeführt.)
|
|
COPY omsorgWeb/docker/000-default.conf /etc/apache2/sites-enabled/000-default.conf
|
|
|
|
COPY omsorgWeb/ /var/www/html/
|
|
COPY .htaccess /var/www/html/.htaccess
|
|
|
|
RUN chmod +x /var/www/html/docker/docker-entrypoint.sh \
|
|
# Schreibbare Verzeichnisse für Datei-Uploads zur Laufzeit (siehe docker-compose.yml-Volumes).
|
|
# Existieren im Repo NICHT zwingend (Root-.gitignore schließt sie komplett aus - lokal hatten
|
|
# sie bei mir Testdateien, ein frischer CI-Checkout hat sie gar nicht) - deshalb erst anlegen,
|
|
# dann Besitzer auf den Apache-User setzen, damit PHP dort schreiben kann.
|
|
&& mkdir -p \
|
|
/var/www/html/mitarbeiter-app-legacy/uploads \
|
|
/var/www/html/mitarbeiter-app-legacy/downloads \
|
|
/var/www/html/mitarbeiter-app-legacy/fortbildung-materials \
|
|
/var/www/html/mitarbeiter-app-legacy/assets/avatars \
|
|
/var/www/html/mitarbeiter-app-legacy/data \
|
|
&& chown -R www-data:www-data \
|
|
/var/www/html/mitarbeiter-app-legacy/uploads \
|
|
/var/www/html/mitarbeiter-app-legacy/downloads \
|
|
/var/www/html/mitarbeiter-app-legacy/fortbildung-materials \
|
|
/var/www/html/mitarbeiter-app-legacy/assets/avatars \
|
|
/var/www/html/mitarbeiter-app-legacy/data
|
|
|
|
EXPOSE 80
|
|
|
|
ENTRYPOINT ["/var/www/html/docker/docker-entrypoint.sh"]
|