Replace the Schulcloud token without a restart
A token lasts 30 days and only a browser login yields one — the account is federated, so the server cannot mint it. Replacing it meant editing .env and recreating the container, every month. `schulcloud token set` (a hidden prompt, or piped input) and a /token page both send it to PUT /api/token. The server checks it with Schulcloud first — well-formed, unexpired, still logged in, the same account — then swaps it into the config every request reads, restarts the keepalive and saves it in STATE_DIR, a new volume, with mode 0600. At startup the newer of the saved token and TSC_JWT_COOKIE wins, unless they belong to different accounts. A refused paste changes nothing, and the token is never logged. The keepalive's pings carry a generation, so a 401 for the old token that arrives after a swap cannot stop the new cycle. `schulcloud token`, whoami and the log report the expiry and warn a week ahead. Found on the way: a host that is off for more than two hours loses the session however long the token has left — this machine lost it overnight — which is what the always-on Pi is for. 174 tests. Smoke 72/72 on the local instance, and a real swap verified end to end there. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -37,13 +37,16 @@ services:
|
||||
PORT: 8080
|
||||
BIND_HOST: 0.0.0.0
|
||||
MIRROR_DIR: /data/mirror
|
||||
STATE_DIR: /data/state
|
||||
depends_on:
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
# The mirror is the one thing this server writes; everything else stays
|
||||
# read-only, so it gets its own volume rather than loosening read_only.
|
||||
# The mirror and a replaced Schulcloud token are the only things this
|
||||
# server writes; everything else stays read-only, so each gets its own
|
||||
# volume rather than loosening read_only.
|
||||
- mirror:/data/mirror
|
||||
- state:/data/state
|
||||
# No ports are published to the host: Caddy reaches the container over the
|
||||
# shared Docker network, so the only way in from the internet is through
|
||||
# Caddy's TLS and this server's bearer check.
|
||||
@@ -67,6 +70,7 @@ services:
|
||||
volumes:
|
||||
pgdata:
|
||||
mirror:
|
||||
state:
|
||||
|
||||
networks:
|
||||
caddy:
|
||||
|
||||
Reference in New Issue
Block a user