mirror of
https://github.com/warmbly/warmbly.git
synced 2026-10-04 08:02:01 +00:00
* fix: let a granted plan unlock the dashboard, since the client decided paid from the Stripe status a managed subscription never touches, and replace the Turnstile size Cloudflare removed so the widget renders and can issue a token at all * feat: tell people on a preview deployment that it is a public beta, once in a dialog and thereafter as a header pill they can reopen, driven by a config value rather than a hostname so one image stays reusable, and bind both Turnstile modals through onLoad because the component is not forwardRef and execution=execute never fires without the widget instance * fix: keep the beta pill outside the desktop-only header group so the notice stays reopenable on a phone, and say in the docs that the value is baked into config.js at container start rather than read per load
39 lines
1.6 KiB
Bash
39 lines
1.6 KiB
Bash
#!/bin/sh
|
|
# Render the runtime config from container env so a single built image serves
|
|
# any deployment. Runs before nginx starts (nginx /docker-entrypoint.d hook).
|
|
#
|
|
# WARMBLY_CONFIG_OUT moves where it writes, which is how a static host that
|
|
# has no container start renders the same file at build time. One definition
|
|
# of the key set, so the two paths cannot drift apart.
|
|
set -eu
|
|
|
|
CONFIG_OUT="${WARMBLY_CONFIG_OUT:-/usr/share/nginx/html/config.js}"
|
|
mkdir -p "$(dirname "$CONFIG_OUT")"
|
|
|
|
# Values are written into JavaScript string literals, so a double quote, a
|
|
# backslash or a line break in one would end the literal early and take the
|
|
# whole config with it, leaving the app with no API_URL at all. Escape rather
|
|
# than trust whatever ended up in .env.
|
|
js() {
|
|
printf '%s' "$1" | sed -e 's/\\/\\\\/g' -e 's/"/\\"/g' | tr -d '\r\n'
|
|
}
|
|
|
|
cat > "$CONFIG_OUT" <<EOF
|
|
window.__WARMBLY_ENV__ = {
|
|
API_URL: "$(js "${WARMBLY_API_URL:-}")",
|
|
APP_URL: "$(js "${WARMBLY_APP_URL:-}")",
|
|
TURNSTILE_KEY: "$(js "${WARMBLY_TURNSTILE_KEY:-}")",
|
|
BETA_NOTICE: "$(js "${WARMBLY_BETA_NOTICE:-}")",
|
|
SENTRY_DSN: "$(js "${WARMBLY_SENTRY_DSN:-}")",
|
|
SENTRY_ENVIRONMENT: "$(js "${WARMBLY_SENTRY_ENVIRONMENT:-}")",
|
|
POSTHOG_KEY: "$(js "${WARMBLY_POSTHOG_KEY:-}")",
|
|
POSTHOG_HOST: "$(js "${WARMBLY_POSTHOG_HOST:-}")",
|
|
POSTHOG_UI_HOST: "$(js "${WARMBLY_POSTHOG_UI_HOST:-}")",
|
|
POSTHOG_ERROR_TRACKING: "$(js "${WARMBLY_POSTHOG_ERROR_TRACKING:-}")"
|
|
};
|
|
EOF
|
|
|
|
# The redirect truncates in place and keeps whatever mode the built file had, so
|
|
# a restrictive umask or checkout leaves nginx serving 403 for the whole config.
|
|
chmod 644 "$CONFIG_OUT"
|