mirror of
https://github.com/migatu/conjurer.git
synced 2026-07-21 01:02:10 +00:00
33ec1c0e35
The Python half of the short-lived share links lived in the repo; the Apache config and the cron entries that make it work were hand-placed on the host, so the feature could not be rebuilt from a checkout. This adds the missing half. Scripts (defaults unchanged, so existing bare-metal cron keeps working): * scan_shares.py / revoke_shares.py take their paths from CONJURER_SHARE_* instead of hardcoding the Pi layout, and create their parent dirs; * the revoke TTL is now CONJURER_SHARE_TTL_SECONDS. Its --help claimed "2min" while the code used a hardcoded 3600 - the help text now reports the real, configured value. New share service: * docker/Dockerfile.share - Apache + the two jobs, reusing the same scripts rather than forking copies; * docker/share-vhost.conf.tpl - the previously undocumented Apache half. Three settings are load-bearing and commented as such: +FollowSymLinks (the shares ARE symlinks), -Indexes (a listing would expose every live token), and a deny rule for dotfiles (revoke_shares.py keeps .downloads.json - a map of every live token - inside the served directory); * docker/entrypoint.share.sh - renders the vhost, seeds the index on first run, then runs scanner/revoker in sleep loops beside Apache (no cron, so their output shows up in docker logs); * compose + env example, incl. the two volumes that MUST be shared with the musician (it creates the links and reads the index). docs/deployment/FILE_SHARING.md documents the mechanism, both deployment routes (docker and existing host Apache), the Discord command, why each Apache setting matters, verification commands, and the known limitations - notably that a link nobody ever downloads is never revoked, since the TTL starts at first download. Verified: scanner and revoker exercised end-to-end against temp dirs (index built; token recorded from a combined-format log line and the symlink unlinked). Compose file not validated - no docker on this machine. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
32 lines
1.2 KiB
Bash
32 lines
1.2 KiB
Bash
# Copy to docker/env/musician.env and fill in.
|
|
|
|
CONJURER_MUSICIAN_HOST=0.0.0.0
|
|
CONJURER_MUSICIAN_PORT=5000
|
|
|
|
# Same shared secret as the bot (empty = auth disabled).
|
|
CONJURER_API_KEY=
|
|
|
|
# Where to POST "now playing" / prepped-track updates (the bot's comm layer).
|
|
CONJURER_MAIN_BOT=http://BOT_VM_IP:5000
|
|
|
|
# The mp3 library (mounted volume).
|
|
CONJURER_MUSIC_FOLDER=/music
|
|
|
|
# Runtime paths (mounted volume) — playlists/logs the service writes.
|
|
CONJURER_MUSICIAN_BASE=/data
|
|
CONJURER_LOGSTORE=/data/logs
|
|
|
|
# --- File sharing (optional; see docs/deployment/FILE_SHARING.md) --------
|
|
# The musician SEARCHES the index and CREATES the symlinks; the share container
|
|
# builds the index, serves the links and revokes them. Both must therefore point
|
|
# at the same two host paths — mount them into this container as well:
|
|
# - /srv/share/db:/srv/share/db
|
|
# - /srv/share/links:/var/www/html/share
|
|
# Leave these unset to keep the feature off (the endpoints then just find
|
|
# nothing).
|
|
# CONJURER_SHARE_DB=/srv/share/db/share_scan.json
|
|
# CONJURER_SHARE_DIR=/var/www/html/share
|
|
# Public URL prefix handed back to Discord; host half must match the share
|
|
# container's CONJURER_SHARE_SERVER_NAME.
|
|
# CONJURER_SHARE_BASE_URL=https://czernobog.pl/share
|