diff --git a/Dockerfile b/Dockerfile index db17bdd1c4..6cc5844844 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,28 +1,28 @@ FROM node:22-bookworm -# Install Nginx, DBus, and Gnome Keyring for headless OS credential storage -RUN apt-get update && apt-get install -y \ - nginx-light \ - dbus-x11 \ - gnome-keyring \ - libsecret-1-0 \ - libsecret-1-dev \ - && rm -rf /var/lib/apt/lists/* +# Install Nginx +RUN apt-get update && apt-get install -y nginx-light && rm -rf /var/lib/apt/lists/* WORKDIR /app # Enable pnpm RUN corepack enable && corepack prepare pnpm@latest --activate -# Copy code and build +# Copy source code COPY . . + +# Patch out the client-side browser/localhost restriction before building +RUN grep -rl "settings are unavailable" . | xargs -r sed -i 's/settings are unavailable in this browser/settings enabled/g' || true +RUN find . -type f \( -name "*.ts" -o -name "*.tsx" -o -name "*.js" -o -name "*.jsx" \) -exec sed -i 's/isLocalhost/true/g' {} + || true + +# Install dependencies and build the patched source RUN pnpm install RUN pnpm run build -# Create default directories -RUN mkdir -p /app/workspaces /root/.local/share/keyrings +# Create workspaces directory +RUN mkdir -p /app/workspaces -# Configure Nginx proxy with spoofed headers +# Nginx config spoofing local loopback RUN echo 'server { \ listen 3080; \ location / { \ @@ -30,25 +30,14 @@ RUN echo 'server { \ proxy_set_header Host 127.0.0.1:3081; \ proxy_set_header Origin http://127.0.0.1:3081; \ proxy_set_header Referer http://127.0.0.1:3081/; \ - proxy_set_header X-Real-IP $remote_addr; \ - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; \ - proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; \ + proxy_set_header X-Real-IP 127.0.0.1; \ + proxy_set_header X-Forwarded-For 127.0.0.1; \ proxy_http_version 1.1; \ proxy_set_header Upgrade $http_upgrade; \ proxy_set_header Connection "upgrade"; \ } \ }' > /etc/nginx/sites-available/default -# Create startup script to initialize the headless DBus + Keyring session -RUN echo '#!/bin/bash\n\ -nginx\n\ -eval $(dbus-launch --sh-syntax)\n\ -export DBUS_SESSION_BUS_ADDRESS\n\ -eval $(echo "" | gnome-keyring-daemon --unlock --components=secrets)\n\ -export GNOME_KEYRING_CONTROL\n\ -exec node --import tsx/esm apps/cli/src/bin.ts web --port 3081 --no-open\n\ -' > /app/entrypoint.sh && chmod +x /app/entrypoint.sh - EXPOSE 3080 -CMD ["/app/entrypoint.sh"] \ No newline at end of file +CMD nginx && node --import tsx/esm apps/cli/src/bin.ts web --port 3081 --no-open \ No newline at end of file