|
|
|
@@ -9,13 +9,13 @@ setup_ldap_source() {
|
|
|
|
|
|
|
|
|
|
# Get the existing LDAP source status. This allows the user to disable LDAP
|
|
|
|
|
# Note that this method is deprecated since this app now supports optionalSso
|
|
|
|
|
ldap_status=$(mysql -u"${MYSQL_USERNAME}" -p"${MYSQL_PASSWORD}" -h mysql --database="${MYSQL_DATABASE}" -N -B -e "select is_actived from login_source WHERE name='cloudron';")
|
|
|
|
|
ldap_status=$(mysql -u"${CLOUDRON_MYSQL_USERNAME}" -p"${CLOUDRON_MYSQL_PASSWORD}" -h mysql --database="${CLOUDRON_MYSQL_DATABASE}" -N -B -e "select is_actived from login_source WHERE name='cloudron';")
|
|
|
|
|
[[ -z "${ldap_status}" ]] && ldap_status="1"
|
|
|
|
|
|
|
|
|
|
now=$(date +%s)
|
|
|
|
|
|
|
|
|
|
if mysql -u"${MYSQL_USERNAME}" -p"${MYSQL_PASSWORD}" -h mysql --database="${MYSQL_DATABASE}" \
|
|
|
|
|
-e "REPLACE INTO login_source (id, type, name, is_actived, cfg, created_unix, updated_unix) VALUES (1,2,'cloudron',${ldap_status},'{\"Name\":\"cloudron\",\"Host\":\"${LDAP_SERVER}\",\"Port\":${LDAP_PORT},\"UseSSL\":false,\"SkipVerify\":true,\"BindDN\":\"${LDAP_BIND_DN}\",\"BindPassword\":\"${LDAP_BIND_PASSWORD}\",\"UserBase\":\"${LDAP_USERS_BASE_DN}\",\"AttributeUsername\":\"username\",\"AttributeName\":\"displayname\",\"AttributeSurname\":\"\",\"AttributeMail\":\"mail\",\"Filter\":\"(\\\\u007C(mail=%[1]s)(username=%[1]s))\"}','${now}','${now}');"; then
|
|
|
|
|
if mysql -u"${CLOUDRON_MYSQL_USERNAME}" -p"${CLOUDRON_MYSQL_PASSWORD}" -h mysql --database="${CLOUDRON_MYSQL_DATABASE}" \
|
|
|
|
|
-e "REPLACE INTO login_source (id, type, name, is_actived, cfg, created_unix, updated_unix) VALUES (1,2,'cloudron',${ldap_status},'{\"Name\":\"cloudron\",\"Host\":\"${CLOUDRON_LDAP_SERVER}\",\"Port\":${CLOUDRON_LDAP_PORT},\"UseSSL\":false,\"SkipVerify\":true,\"BindDN\":\"${CLOUDRON_LDAP_BIND_DN}\",\"BindPassword\":\"${CLOUDRON_LDAP_BIND_PASSWORD}\",\"UserBase\":\"${CLOUDRON_LDAP_USERS_BASE_DN}\",\"AttributeUsername\":\"username\",\"AttributeName\":\"displayname\",\"AttributeSurname\":\"\",\"AttributeMail\":\"mail\",\"Filter\":\"(\\\\u007C(mail=%[1]s)(username=%[1]s))\"}','${now}','${now}');"; then
|
|
|
|
|
echo "==> LDAP Authentication was setup with activation status ${ldap_status}"
|
|
|
|
|
else
|
|
|
|
|
echo "==> Failed to setup LDAP authentication"
|
|
|
|
@@ -45,11 +45,11 @@ setup_auth() {
|
|
|
|
|
|
|
|
|
|
echo "==> Gitea is up, setting up auth"
|
|
|
|
|
|
|
|
|
|
if [[ -n "${LDAP_SERVER:-}" ]]; then
|
|
|
|
|
if [[ -n "${CLOUDRON_LDAP_SERVER:-}" ]]; then
|
|
|
|
|
setup_ldap_source
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
user_count=$(mysql -u"${MYSQL_USERNAME}" -p"${MYSQL_PASSWORD}" -h mysql --database="${MYSQL_DATABASE}" -N -B -e "SELECT count(*) FROM user;")
|
|
|
|
|
user_count=$(mysql -u"${CLOUDRON_MYSQL_USERNAME}" -p"${CLOUDRON_MYSQL_PASSWORD}" -h mysql --database="${CLOUDRON_MYSQL_DATABASE}" -N -B -e "SELECT count(*) FROM user;")
|
|
|
|
|
# be careful, not to create root user for existing LDAP based installs
|
|
|
|
|
if [[ "${user_count}" == "0" ]]; then
|
|
|
|
|
echo "==> Setting up root user for first run"
|
|
|
|
@@ -94,13 +94,13 @@ crudini --merge "/run/gitea/app.ini" < "/app/data/app.ini"
|
|
|
|
|
|
|
|
|
|
# override important values
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database DB_TYPE mysql
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database HOST "${MYSQL_HOST}:${MYSQL_PORT}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database NAME "${MYSQL_DATABASE}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database USER "${MYSQL_USERNAME}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database PASSWD "${MYSQL_PASSWORD}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database HOST "${CLOUDRON_MYSQL_HOST}:${CLOUDRON_MYSQL_PORT}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database NAME "${CLOUDRON_MYSQL_DATABASE}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database USER "${CLOUDRON_MYSQL_USERNAME}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database PASSWD "${CLOUDRON_MYSQL_PASSWORD}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" database SSL_MODE "disable"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server PROTOCOL "http"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server DOMAIN "${APP_DOMAIN}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server DOMAIN "${CLOUDRON_APP_DOMAIN}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server ROOT_URL "https://%(DOMAIN)s/"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server HTTP_ADDR ""
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server HTTP_PORT "3000"
|
|
|
|
@@ -109,10 +109,10 @@ crudini --set "/run/gitea/app.ini" server SSH_PORT "${SSH_PORT}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" server APP_DATA_PATH "/app/data/appdata"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" repository ROOT "/app/data/repository"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" repository.upload TEMP_PATH "/run/gitea/tmp/uploads"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer HOST "${MAIL_SMTP_SERVER}:${MAIL_SMTPS_PORT}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer USER "${MAIL_SMTP_USERNAME}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer PASSWD "${MAIL_SMTP_PASSWORD}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer FROM "${MAIL_FROM}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer HOST "${CLOUDRON_MAIL_SMTP_SERVER}:${CLOUDRON_MAIL_SMTPS_PORT}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer USER "${CLOUDRON_MAIL_SMTP_USERNAME}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer PASSWD "${CLOUDRON_MAIL_SMTP_PASSWORD}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer FROM "${CLOUDRON_MAIL_FROM}"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" mailer SKIP_VERIFY "true"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" security INSTALL_LOCK "true"
|
|
|
|
|
crudini --set "/run/gitea/app.ini" log MODE "console"
|
|
|
|
|