From 5a7537f449767cce2b2efcbe547254b208a05fc5 Mon Sep 17 00:00:00 2001 From: Aran Roig Date: Fri, 2 Oct 2026 00:00:27 +0200 Subject: [PATCH] Test? --- AGENTS.md | 5 +++++ docker-compose.yml | 6 ++++++ 2 files changed, 11 insertions(+) diff --git a/AGENTS.md b/AGENTS.md index 88786b3..2c7905c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -29,6 +29,11 @@ Seed sample articles: `npm run seed` in `backend/`. Environment: `backend/.env` (`PORT=5000`, `MONGO_URI=mongodb://127.0.0.1:27017/mathew`, `JWT_SECRET` — signs session tokens, `AUTH_TOKEN_TTL` — how long one lasts, default `7d`; see `.env.example`). Without `JWT_SECRET` the API warns and uses an insecure dev key. +Production (`docker-compose.yml`) runs MongoDB as its own `mongo` service (volume `mongo-data`) +and passes the backend a `MONGO_URI` by service name; `JWT_SECRET` interpolates from +`/var/www/app/.env` on the deploy host (create it once — the public site must not sign sessions +with the dev key). The stack's nginx resolves `backend`/`frontend` through Docker's DNS per +request, so container recreates cannot leave it on a stale IP. Frontend API URL comes from `NUXT_PUBLIC_API_BASE` (default `http://localhost:5000`, read via `runtimeConfig.public.apiBase`). The frontend image builds it empty: the browser then calls `/api` on its own origin, which nginx routes to diff --git a/docker-compose.yml b/docker-compose.yml index dc6d981..ded6632 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -23,6 +23,12 @@ services: # 127.0.0.1 is itself — with the default URI the API crashed on connect # and nginx answered 502. Mongo is a service of this stack now. MONGO_URI: mongodb://mongo:27017/mathew + # Interpolated from /var/www/app/.env on the deploy host (never + # committed, never overwritten by the pipeline's scp). Create it once: + # echo "JWT_SECRET=$(openssl rand -hex 32)" >> /var/www/app/.env + # Left unset, the backend falls back to the dev key in the repo — + # anyone could then forge sessions against the public site. + JWT_SECRET: ${JWT_SECRET:-} depends_on: mongo: condition: service_healthy