8cadacb553
gates / gates (push) Successful in 26s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
36 lines
3.0 KiB
Bash
36 lines
3.0 KiB
Bash
# Part C (decision 49) on a demo box: before / the household's press / after. No account is created: the "open"
|
|
# proof is the app answering its OWN validation (an invalid sign-up). Controller password on STDIN, never printed.
|
|
set -u
|
|
IFS= read -r PW
|
|
D=$(grep -hoE 'Host\(`felhom\.[a-z0-9.-]+`\)' /opt/docker/stacks/traefik/dynamic/controller.yml | head -1 | sed 's/Host(`felhom\.//;s/`)//')
|
|
[ -n "$D" ] || { echo "no domain found — stopping, nothing changed"; exit 1; }
|
|
APPS="$*"; J=/tmp/pc49.$$; CH="felhom.$D"
|
|
echo "domain $D; apps $APPS; $(date -u +%FT%TZ)"
|
|
probe() { # $1 app $2 phase
|
|
case $1 in
|
|
opengist) H="gist.$D"
|
|
f=$(curl -sk -H "Host: $H" https://127.0.0.1/-/register | grep -c 'name="username"')
|
|
c=$(curl -sk -o /tmp/pc.b -w '%{http_code}' -H "Host: $H" -H 'Content-Type: application/x-www-form-urlencoded' -X POST -d 'username=&password=' https://127.0.0.1/-/register)
|
|
echo " [$2] opengist: sign-up form served=$f | an invalid sign-up (empty name) -> $c $(grep -q 'sign-up is closed\|nem lehet regisztr' /tmp/pc.b && echo BLOCKED || echo 'the app answered')"
|
|
echo " [$2] opengist: login page -> $(curl -sk -o /dev/null -w '%{http_code}' -H "Host: $H" https://127.0.0.1/-/login)";;
|
|
adventurelog) H="travel.$D"
|
|
d=$(docker exec felhom-controller curl -s -m 5 http://adventurelog:80/auth/is-registration-disabled/ | grep -o '"is_disabled":[a-z]*')
|
|
c=$(curl -sk -o /tmp/pc.b -w '%{http_code}' -H "Host: $H" -H "Origin: https://$H" -H 'x-sveltekit-action: true' -H 'Content-Type: application/x-www-form-urlencoded' -X POST -d 'username=&email=&password1=a&password2=b' https://127.0.0.1/signup)
|
|
echo " [$2] adventurelog: its own switch $d | an invalid sign-up (mismatched) -> $c $(grep -q 'sign-up is closed\|nem lehet regisztr' /tmp/pc.b && echo BLOCKED || echo 'the app answered')"
|
|
echo " [$2] adventurelog: login page -> $(curl -sk -o /dev/null -w '%{http_code}' -H "Host: $H" https://127.0.0.1/login)";;
|
|
esac; rm -f /tmp/pc.b; }
|
|
for a in $APPS; do probe $a BEFORE; done
|
|
# the household's press, through the dashboard (the product's own endpoint)
|
|
curl -sk -c $J -b $J -H "Host: $CH" -o /dev/null --data-urlencode "password=$PW" https://127.0.0.1/login
|
|
CSRF=$(curl -sk -c $J -b $J -H "Host: $CH" -L https://127.0.0.1/ | grep -o '<meta name="csrf-token" content="[^"]*"' | sed 's/.*content="//;s/"$//')
|
|
for a in $APPS; do
|
|
pg=$(curl -sk -b $J -H "Host: $CH" https://127.0.0.1/apps/$a | grep -c 'id="close-signup-card"')
|
|
r=$(curl -sk -b $J -H "Host: $CH" -H "X-CSRF-Token: $CSRF" -H 'Content-Type: application/json' -X POST https://127.0.0.1/apps/$a/close-signup)
|
|
echo " PRESS $a: the card was on the page=$pg -> $r"
|
|
done
|
|
sleep 20
|
|
for a in $APPS; do probe $a AFTER; done
|
|
for a in $APPS; do echo " $a app.yaml: $(grep -A6 '^setup_gate:' /opt/docker/stacks/$a/app.yaml | grep -oE 'state: [a-z]+|opened_by: [a-z-]+' | tr '\n' ' ') after_setup: $(awk '/^after_setup:/{f=1;next} f&&/^[a-z]/{f=0} f' /opt/docker/stacks/$a/app.yaml | tr -s ' ' | tr '\n' ' ' | cut -c1-200)"; done
|
|
echo " files: $(ls /opt/docker/stacks/traefik/dynamic | tr '\n' ' ')"
|
|
rm -f $J; unset PW
|