CR1: the lightbox comment button POSTed to /upload/{id}/comment (singular);
no such route exists, so every UI-submitted comment 404'd and was lost.
Fixed to /comments (plural). The prior e2e passed because its seed helper
POSTs the API directly — added comment-ui.spec.ts which drives the real
component so this can't regress silently again.
CR2: export archives (Gallery.zip / Memories.zip / HTML viewer) were written
under media_path, which is a public ServeDir — so GET /media/exports/
Gallery.zip served the entire event (every photo, caption, comment,
uploader name) to any anonymous visitor at a guessable URL, bypassing the
ticket + release gate. Moved exports to a separate EXPORT_PATH (=/exports)
on its own volume (Dockerfile chown, compose volume, gated handler reads
the new path). export-leak.spec.ts asserts /media/exports/Gallery.zip → 404.
Riders (git can't split hunks): LightboxModal also gains H3 live-eviction on
comment-deleted/upload-deleted; config.rs also wires compression_concurrency
from boot config (medium).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
38 lines
1.1 KiB
Docker
38 lines
1.1 KiB
Docker
# --- Build stage ---
|
|
FROM rust:1.88-alpine AS builder
|
|
|
|
RUN apk add --no-cache musl-dev pkgconfig openssl-dev
|
|
|
|
WORKDIR /app
|
|
COPY Cargo.toml Cargo.lock* ./
|
|
# Pre-fetch deps with a dummy build for layer caching
|
|
RUN mkdir src && echo "fn main(){}" > src/main.rs && \
|
|
cargo build --release && \
|
|
rm -rf src
|
|
|
|
COPY src ./src
|
|
COPY static ./static
|
|
COPY migrations ./migrations
|
|
RUN touch src/main.rs && cargo build --release
|
|
|
|
# --- Runtime stage ---
|
|
FROM alpine:3.21
|
|
|
|
RUN apk add --no-cache ca-certificates ffmpeg
|
|
|
|
# Run as a non-root user. Pre-create and chown the media + export mount paths so
|
|
# the fresh named volumes inherit the non-root ownership (Docker seeds an empty
|
|
# named volume from the image directory, preserving its uid/gid) and uploads +
|
|
# export archives can be written. Exports live OUTSIDE /media on purpose so the
|
|
# public media ServeDir can't reach them.
|
|
RUN addgroup -S app && adduser -S app -G app
|
|
|
|
WORKDIR /app
|
|
COPY --from=builder /app/target/release/eventsnap-backend ./
|
|
|
|
RUN mkdir -p /media /exports && chown -R app:app /app /media /exports
|
|
USER app
|
|
|
|
EXPOSE 3000
|
|
CMD ["./eventsnap-backend"]
|