diff --git a/apps/note-mark/1.0.2/.env.sample b/apps/note-mark/1.0.2/.env.sample new file mode 100644 index 000000000..88b2cc9b8 --- /dev/null +++ b/apps/note-mark/1.0.2/.env.sample @@ -0,0 +1,13 @@ +CONTAINER_NAME=note-mark +PANEL_APP_BIND_ADDRESS=127.0.0.1 +PANEL_APP_PORT_HTTP=8080 +NOTE_MARK_PUBLIC_URL=http://127.0.0.1:8080 +APP_DATA_DIR=./data +NOTE_MARK_SECRET_SEED=generate +NOTE_MARK_AUTH_SECRET= +ENABLE_INTERNAL_SIGNUP=true +ENABLE_INTERNAL_LOGIN=true +ENABLE_ANONYMOUS_USER_SEARCH=true +FILE_SIZE_LIMIT=12M +LOGGING_LEVEL=info +TZ=Asia/Shanghai diff --git a/apps/note-mark/1.0.2/data.yml b/apps/note-mark/1.0.2/data.yml new file mode 100644 index 000000000..06671ad2e --- /dev/null +++ b/apps/note-mark/1.0.2/data.yml @@ -0,0 +1,127 @@ +additionalProperties: + formFields: + - default: 127.0.0.1 + edit: true + envKey: PANEL_APP_BIND_ADDRESS + labelEn: Bind Address + labelZh: 绑定地址 + label: {en: Bind Address, zh: 绑定地址, zh-Hant: 綁定位址, ja: バインドアドレス, ko: 바인드 주소, ru: Адрес привязки, ms: Alamat ikatan, pt-br: Endereco de vinculacao} + required: true + type: text + - default: 8080 + edit: true + envKey: PANEL_APP_PORT_HTTP + labelEn: HTTP Port + labelZh: HTTP 端口 + label: {en: HTTP Port, zh: HTTP 端口, zh-Hant: HTTP 連接埠, ja: HTTP ポート, ko: HTTP 포트, ru: HTTP-порт, ms: Port HTTP, pt-br: Porta HTTP} + required: true + rule: paramPort + type: number + - default: http://127.0.0.1:8080 + edit: true + envKey: NOTE_MARK_PUBLIC_URL + labelEn: Public URL + labelZh: 公开访问 URL + label: {en: Public URL, zh: 公开访问 URL, zh-Hant: 公開存取 URL, ja: 公開 URL, ko: 공개 URL, ru: Публичный URL, ms: URL awam, pt-br: URL publica} + required: true + rule: paramExtUrl + type: text + - default: ./data + edit: true + envKey: APP_DATA_DIR + labelEn: Data Directory + labelZh: 数据目录 + label: {en: Data Directory, zh: 数据目录, zh-Hant: 資料目錄, ja: データディレクトリ, ko: 데이터 디렉터리, ru: Каталог данных, ms: Direktori data, pt-br: Diretorio de dados} + required: true + type: text + - default: "" + edit: true + envKey: NOTE_MARK_SECRET_SEED + labelEn: Authentication Secret Seed + labelZh: 认证密钥种子 + label: {en: Authentication Secret Seed, zh: 认证密钥种子, zh-Hant: 驗證密鑰種子, ja: 認証シークレットシード, ko: 인증 비밀 시드, ru: Начальное значение секрета аутентификации, ms: Benih rahsia pengesahan, pt-br: Semente do segredo de autenticacao} + random: true + required: true + rule: paramComplexity + type: password + - default: "" + disabled: true + edit: false + envKey: NOTE_MARK_AUTH_SECRET + labelEn: Authentication Secret (Derived) + labelZh: 认证密钥(自动派生) + label: {en: Authentication Secret (Derived), zh: 认证密钥(自动派生), zh-Hant: 驗證密鑰(自動衍生), ja: 認証シークレット(自動導出), ko: 인증 비밀 키(자동 파생), ru: Секрет аутентификации (производный), ms: Rahsia pengesahan (diterbitkan), pt-br: Segredo de autenticacao (derivado)} + required: false + type: password + - default: "true" + edit: true + envKey: ENABLE_INTERNAL_SIGNUP + labelEn: Enable Internal Signup + labelZh: 启用内部注册 + label: {en: Enable Internal Signup, zh: 启用内部注册, zh-Hant: 啟用內部註冊, ja: 内部登録を有効化, ko: 내부 가입 활성화, ru: Включить внутреннюю регистрацию, ms: Dayakan pendaftaran dalaman, pt-br: Ativar cadastro interno} + required: true + type: select + values: + - label: Enabled + value: "true" + - label: Disabled + value: "false" + - default: "true" + edit: true + envKey: ENABLE_INTERNAL_LOGIN + labelEn: Enable Internal Login + labelZh: 启用内部登录 + label: {en: Enable Internal Login, zh: 启用内部登录, zh-Hant: 啟用內部登入, ja: 内部ログインを有効化, ko: 내부 로그인 활성화, ru: Включить внутренний вход, ms: Dayakan log masuk dalaman, pt-br: Ativar login interno} + required: true + type: select + values: + - label: Enabled + value: "true" + - label: Disabled + value: "false" + - default: "true" + edit: true + envKey: ENABLE_ANONYMOUS_USER_SEARCH + labelEn: Enable Anonymous User Search + labelZh: 启用匿名用户搜索 + label: {en: Enable Anonymous User Search, zh: 启用匿名用户搜索, zh-Hant: 啟用匿名使用者搜尋, ja: 匿名ユーザー検索を有効化, ko: 익명 사용자 검색 활성화, ru: Включить анонимный поиск пользователей, ms: Dayakan carian pengguna tanpa nama, pt-br: Ativar busca anonima de usuarios} + required: true + type: select + values: + - label: Enabled + value: "true" + - label: Disabled + value: "false" + - default: 12M + edit: true + envKey: FILE_SIZE_LIMIT + labelEn: File Size Limit + labelZh: 文件大小限制 + label: {en: File Size Limit, zh: 文件大小限制, zh-Hant: 檔案大小限制, ja: ファイルサイズ上限, ko: 파일 크기 제한, ru: Ограничение размера файла, ms: Had saiz fail, pt-br: Limite de tamanho de arquivo} + required: true + type: text + - default: info + edit: true + envKey: LOGGING_LEVEL + labelEn: Log Level + labelZh: 日志级别 + label: {en: Log Level, zh: 日志级别, zh-Hant: 日誌等級, ja: ログレベル, ko: 로그 수준, ru: Уровень журналирования, ms: Tahap log, pt-br: Nivel de log} + required: true + type: select + values: + - label: Debug + value: debug + - label: Info + value: info + - label: Warn + value: warn + - label: Error + value: error + - default: Asia/Shanghai + edit: true + envKey: TZ + labelEn: Time Zone + labelZh: 时区 + label: {en: Time Zone, zh: 时区, zh-Hant: 時區, ja: タイムゾーン, ko: 시간대, ru: Часовой пояс, ms: Zon waktu, pt-br: Fuso horario} + required: true + type: text diff --git a/apps/note-mark/1.0.2/docker-compose.yml b/apps/note-mark/1.0.2/docker-compose.yml new file mode 100644 index 000000000..99d93ba18 --- /dev/null +++ b/apps/note-mark/1.0.2/docker-compose.yml @@ -0,0 +1,37 @@ +services: + note-mark: + image: "ghcr.io/enchant97/note-mark:1.0.2" + container_name: ${CONTAINER_NAME} + restart: unless-stopped + networks: + - 1panel-network + ports: + - "${PANEL_APP_BIND_ADDRESS}:${PANEL_APP_PORT_HTTP}:8080" + environment: + - AUTH_TOKEN__SECRET=${NOTE_MARK_AUTH_SECRET} + - PUBLIC_URL=${NOTE_MARK_PUBLIC_URL} + - DATA_PATH=/data + - BIND__HOST=0.0.0.0 + - BIND__PORT=8080 + - ENABLE_INTERNAL_SIGNUP=${ENABLE_INTERNAL_SIGNUP} + - ENABLE_INTERNAL_LOGIN=${ENABLE_INTERNAL_LOGIN} + - ENABLE_ANONYMOUS_USER_SEARCH=${ENABLE_ANONYMOUS_USER_SEARCH} + - FILE_SIZE_LIMIT=${FILE_SIZE_LIMIT} + - LOGGING__LEVEL=${LOGGING_LEVEL} + - LOGGING__ENABLE_JSON=true + - TZ=${TZ} + volumes: + - "${APP_DATA_DIR}:/data" + read_only: true + tmpfs: + - /tmp:rw,nosuid,nodev,noexec,size=32m,mode=1777 + cap_drop: + - ALL + security_opt: + - no-new-privileges:true + labels: + createdBy: "Apps" + +networks: + 1panel-network: + external: true diff --git a/apps/note-mark/1.0.2/scripts/init.sh b/apps/note-mark/1.0.2/scripts/init.sh new file mode 100755 index 000000000..5c5983d65 --- /dev/null +++ b/apps/note-mark/1.0.2/scripts/init.sh @@ -0,0 +1,156 @@ +#!/usr/bin/env bash +set -euo pipefail + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" +APP_ROOT_DIR="$(dirname "$ROOT_DIR")" +ENV_FILE="${ENV_FILE:-${ROOT_DIR}/.env}" + +fail() { + printf '%s\n' "$1" >&2 + exit 1 +} + +strip_matching_quotes() { + local value="$1" + + if [[ ${#value} -ge 2 ]]; then + if [[ "${value:0:1}" == '"' && "${value: -1}" == '"' ]]; then + value="${value:1:${#value}-2}" + elif [[ "${value:0:1}" == "'" && "${value: -1}" == "'" ]]; then + value="${value:1:${#value}-2}" + fi + fi + printf '%s\n' "$value" +} + +read_env_value() { + local key="$1" + local value="" + + if [[ -f "$ENV_FILE" ]]; then + value="$(grep -E "^${key}=" "$ENV_FILE" | tail -n 1 | cut -d '=' -f 2- || true)" + fi + value="${value%$'\r'}" + strip_matching_quotes "$value" +} + +set_env_value() { + local key="$1" + local value="$2" + local temp_file + + temp_file="$(mktemp "${ENV_FILE}.tmp.XXXXXX")" + awk -v key="$key" -v value="$value" ' + BEGIN { updated = 0 } + $0 ~ ("^" key "=") { + if (!updated) { + print key "=" value + updated = 1 + } + next + } + { print } + END { + if (!updated) print key "=" value + } + ' "$ENV_FILE" >"$temp_file" + chmod 600 "$temp_file" + mv -f -- "$temp_file" "$ENV_FILE" +} + +path_is_dotenv_safe() { + local value="$1" + + case "$value" in + *$'\n'* | *$'\r'* | *\\* | *'$'* | *'#'* | *'"'* | *"'"*) return 1 ;; + *) return 0 ;; + esac +} + +seed_is_safe() { + [[ ${#1} -ge 32 && "$1" =~ ^[A-Za-z0-9._~-]+$ ]] +} + +generate_seed() { + od -An -N 32 -tx1 /dev/urandom | tr -d ' \n' +} + +[[ -f "$ENV_FILE" ]] || fail "Environment file not found: ${ENV_FILE}" +chmod 600 "$ENV_FILE" + +if [[ ${APP_DATA_DIR+x} ]]; then + DATA_DIR_RAW="$APP_DATA_DIR" +else + DATA_DIR_RAW="$(read_env_value APP_DATA_DIR)" +fi +DATA_DIR_RAW="$(strip_matching_quotes "${DATA_DIR_RAW:-./data}")" + +[[ -n "$DATA_DIR_RAW" ]] || fail "APP_DATA_DIR must not be empty" +path_is_dotenv_safe "$DATA_DIR_RAW" || fail "APP_DATA_DIR contains unsupported dotenv characters" + +if [[ "$DATA_DIR_RAW" = /* ]]; then + [[ ! -L "$DATA_DIR_RAW" ]] || fail "APP_DATA_DIR must not be a symbolic link" + DATA_DIR_ABS="$(realpath -m -- "$DATA_DIR_RAW")" + [[ "$DATA_DIR_ABS" != "/" ]] || fail "APP_DATA_DIR must not be the filesystem root" +else + CONTAINER_NAME_VALUE="$(read_env_value CONTAINER_NAME)" + [[ "$CONTAINER_NAME_VALUE" =~ ^[A-Za-z0-9._-]+$ ]] || \ + fail "CONTAINER_NAME contains unsupported characters" + + RETAINED_ROOT="${APP_ROOT_DIR}/retained-data" + [[ ! -L "$RETAINED_ROOT" ]] || fail "The retained data root must not be a symbolic link" + RETAINED_INSTANCE_ROOT="${RETAINED_ROOT}/${CONTAINER_NAME_VALUE}" + DATA_DIR_PATH="${RETAINED_INSTANCE_ROOT}/${DATA_DIR_RAW#./}" + [[ ! -L "$DATA_DIR_PATH" ]] || fail "APP_DATA_DIR must not be a symbolic link" + RETAINED_INSTANCE_ABS="$(realpath -m -- "$RETAINED_INSTANCE_ROOT")" + DATA_DIR_ABS="$(realpath -m -- "$DATA_DIR_PATH")" + case "$DATA_DIR_ABS" in + "${RETAINED_INSTANCE_ABS}"/*) ;; + *) fail "Relative APP_DATA_DIR must remain inside the isolated retained-data directory" ;; + esac + + set_env_value APP_DATA_DIR "\"${DATA_DIR_ABS}\"" +fi + +if [[ -e "$DATA_DIR_ABS" && ! -d "$DATA_DIR_ABS" ]]; then + fail "APP_DATA_DIR must be a directory" +fi +if [[ ! -e "$DATA_DIR_ABS" ]]; then + install -d -m 0750 -- "$DATA_DIR_ABS" +fi + +PUBLIC_URL="$(read_env_value NOTE_MARK_PUBLIC_URL)" +[[ "$PUBLIC_URL" =~ ^https?://[A-Za-z0-9._~:/?%\&=+@-]+$ ]] || \ + fail "NOTE_MARK_PUBLIC_URL must be a complete HTTP or HTTPS URL" +[[ "$PUBLIC_URL" != */ ]] || fail "NOTE_MARK_PUBLIC_URL must not end in a trailing slash" + +for key in ENABLE_INTERNAL_SIGNUP ENABLE_INTERNAL_LOGIN ENABLE_ANONYMOUS_USER_SEARCH; do + value="$(read_env_value "$key")" + [[ "$value" == "true" || "$value" == "false" ]] || fail "${key} must be true or false" +done + +FILE_LIMIT="$(read_env_value FILE_SIZE_LIMIT)" +[[ "$FILE_LIMIT" =~ ^[1-9][0-9]*(B|K|KB|M|MB|G|GB)?$ ]] || \ + fail "FILE_SIZE_LIMIT must be a positive byte-size value such as 12M" + +LOG_LEVEL="$(read_env_value LOGGING_LEVEL)" +case "$LOG_LEVEL" in + debug | info | warn | warning | error) ;; + *) fail "LOGGING_LEVEL must be debug, info, warn, warning, or error" ;; +esac + +TIME_ZONE="$(read_env_value TZ)" +[[ "$TIME_ZONE" =~ ^[A-Za-z0-9_+./-]+$ ]] || fail "TZ contains unsupported characters" + +SECRET_SEED="$(read_env_value NOTE_MARK_SECRET_SEED)" +if ! seed_is_safe "$SECRET_SEED"; then + printf '%s\n' 'NOTE_MARK_SECRET_SEED is missing, too short, or not dotenv-safe; replacing it with a generated value.' >&2 + SECRET_SEED="$(generate_seed)" + set_env_value NOTE_MARK_SECRET_SEED "$SECRET_SEED" +fi + +SECRET_DIGEST="$(printf '%s' "$SECRET_SEED" | sha256sum | awk '{print $1}')" +AUTH_SECRET="$(printf '%s' "$SECRET_DIGEST" | base64 | tr -d '\n')" +[[ "$(printf '%s' "$AUTH_SECRET" | base64 -d | wc -c)" -ge 32 ]] || \ + fail "Failed to derive a valid authentication secret" +set_env_value NOTE_MARK_AUTH_SECRET "$AUTH_SECRET" diff --git a/apps/note-mark/1.0.2/scripts/uninstall.sh b/apps/note-mark/1.0.2/scripts/uninstall.sh new file mode 100755 index 000000000..f39b2801c --- /dev/null +++ b/apps/note-mark/1.0.2/scripts/uninstall.sh @@ -0,0 +1,5 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Persistent Note Mark data is intentionally retained for backup or reinstall. +exit 0 diff --git a/apps/note-mark/1.0.2/scripts/upgrade.sh b/apps/note-mark/1.0.2/scripts/upgrade.sh new file mode 100755 index 000000000..5ec28d784 --- /dev/null +++ b/apps/note-mark/1.0.2/scripts/upgrade.sh @@ -0,0 +1,5 @@ +#!/usr/bin/env bash +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd -P)" +exec "$SCRIPT_DIR/init.sh" diff --git a/apps/note-mark/README.md b/apps/note-mark/README.md new file mode 100644 index 000000000..4e5117abf --- /dev/null +++ b/apps/note-mark/README.md @@ -0,0 +1,31 @@ +# Note Mark + +## 产品介绍 + +Note Mark 是一款轻量、快速的自托管 Markdown 笔记应用,提供适配移动端的 Web 界面,并使用普通文件和目录保存笔记与附件。 + +## 主要功能 + +- 支持 GitHub Flavored Markdown、实时编辑和渲染视图 +- 支持友好链接、笔记分享以及附件上传 +- 支持多用户注册与登录,并可按需关闭内部注册或匿名用户搜索 +- 使用 SQLite 保存账号信息,使用标准 Markdown 文件保存笔记内容 + +## 访问说明 + +应用默认仅绑定到 `127.0.0.1`,建议通过同机 HTTPS 反向代理访问。公开访问地址必须填写为完整的 HTTP 或 HTTPS URL,且末尾不能带 `/`。相对数据目录会在安装时自动解析到应用级 `retained-data` 目录,并按容器名隔离,因此卸载实例后仍会保留;绝对路径则保持不变。备份时应完整保存最终配置的数据目录,其中包含数据库、笔记和附件。 + +认证签名密钥由安装时的随机 seed 确定性派生。修改 seed 会使现有登录会话失效,请仅在明确需要轮换认证密钥时修改。 + +## Introduction + +Note Mark is a lightweight, fast, and responsive self-hosted Markdown notes application. It stores notes and assets as ordinary files and keeps account data in SQLite. + +## Features + +- GitHub Flavored Markdown with live editing and rendered views +- Friendly note URLs, sharing, and asset uploads +- Internal multi-user signup and login with configurable anonymous user search +- Mobile-friendly web interface and portable file-based note storage + +The package binds to `127.0.0.1` by default. Publish it through a same-host HTTPS reverse proxy and set the public URL to the exact external address without a trailing slash. Relative data paths are resolved into a per-container directory under the app-level `retained-data` directory so that uninstalling an instance preserves its data; absolute paths remain unchanged. Back up the complete resolved data directory before upgrades. diff --git a/apps/note-mark/data.yml b/apps/note-mark/data.yml new file mode 100644 index 000000000..1d5255be8 --- /dev/null +++ b/apps/note-mark/data.yml @@ -0,0 +1,33 @@ +name: Note Mark +tags: + - Website + - Tool +title: 轻量快速的自托管 Markdown 笔记应用 +description: 轻量快速的自托管 Markdown 笔记应用 +additionalProperties: + key: note-mark + name: Note Mark + tags: + - Website + - Tool + shortDescZh: 轻量快速的自托管 Markdown 笔记应用 + shortDescEn: Lightweight and fast self-hosted Markdown notes + description: + en: A lightweight, fast, and responsive self-hosted Markdown notes application. + zh: 一款轻量、快速且响应式的自托管 Markdown 笔记应用。 + zh-Hant: 一款輕量、快速且響應式的自架 Markdown 筆記應用程式。 + ja: 軽量で高速、レスポンシブなセルフホスト型 Markdown ノートアプリです。 + ko: 가볍고 빠르며 반응형인 자체 호스팅 Markdown 노트 애플리케이션입니다. + ru: Легкое, быстрое и адаптивное приложение для самостоятельного размещения заметок Markdown. + ms: Aplikasi nota Markdown hos kendiri yang ringan, pantas dan responsif. + pt-br: Aplicativo leve, rapido e responsivo de notas Markdown auto-hospedado. + type: website + crossVersionUpdate: true + limit: 0 + recommend: 0 + website: https://notemark.docs.enchantedcode.co.uk + github: https://github.com/enchant97/note-mark + document: https://notemark.docs.enchantedcode.co.uk/docs/setup/install/ + architectures: + - amd64 + - arm64 diff --git a/apps/note-mark/logo.png b/apps/note-mark/logo.png new file mode 100644 index 000000000..90e64ea39 Binary files /dev/null and b/apps/note-mark/logo.png differ