fix(bootstrap): keep the operator's auth sources across re-runs
write_felis_toml regenerates felis.host.toml and felis.pod.toml with a wholesale `cat >`, and the [[auth_source]] list was a literal LittleSkin block in that heredoc. Re-running the installer, which is also what `felis setup` does, threw away any edit to the list: a root the operator added stopped admitting logins, and a root they removed came back. The generated comment invited exactly that edit. Carry the tables forward the way [smtp] already is: read every [[auth_source]] table from the existing felis.host.toml (falling back to felis.pod.toml) and emit the LittleSkin default only when there is no earlier file at all. An earlier file with no tables stays empty, because that is a Mojang-only server rather than a missing value; felis-api now treats an empty list that way. The file header and the comment above the list now say what survives a re-run, and point at felis.host.toml, which is what the next run reads. bootstrap_test.sh extracts the new function from bootstrap.sh and checks the fresh-install default, an operator's own table carried without the default or the following section, an empty list staying empty, and the indented form the setup TUI writes. It passes under dash with gawk and with mawk; forcing the function to always return the default fails five of the new cases.
This commit is contained in:
2 files changed
+76
-8
No files matched your search
+29
-8
@@ -1935,15 +1935,38 @@ persisted_smtp_block() {
|
||||
printf '%s' "$SMTP_BLOCK"
|
||||
}
|
||||
|
||||
# persisted_auth_source_blocks echoes the [[auth_source]] tables an earlier run left
|
||||
# behind, or the LittleSkin default when there is no earlier felis.toml at all. The
|
||||
# list is the operator's: it is the only way to add or drop a Yggdrasil root on a full
|
||||
# install, and nothing in this script's inputs derives it. Without the carry-forward a
|
||||
# re-run would put LittleSkin back after the operator removed it and silently drop any
|
||||
# root they added. An earlier file with no tables stays that way — that is a Mojang-only
|
||||
# server, not a missing value. Same first-readable-file rule as persisted_smtp_block.
|
||||
persisted_auth_source_blocks() {
|
||||
local f
|
||||
for f in "${STATE_DIR}/felis.host.toml" "${STATE_DIR}/felis.pod.toml"; do
|
||||
[ -r "$f" ] || continue
|
||||
# Every [[auth_source]] table, up to (not including) the next other section header.
|
||||
awk '/^[[:space:]]*\[\[auth_source\]\]/ { f=1 }
|
||||
f && /^[[:space:]]*\[/ && !/^[[:space:]]*\[\[auth_source\]\]/ { f=0 }
|
||||
f { print }' "$f"
|
||||
return 0
|
||||
done
|
||||
printf '%s\n' '[[auth_source]]' 'tag = "littleskin"' 'prefix = "LS"' \
|
||||
'url = "https://littleskin.cn/api/yggdrasil/sessionserver/session/minecraft/hasJoined"'
|
||||
}
|
||||
|
||||
write_felis_toml() {
|
||||
local target="$1" db_host="$2" smtp_block
|
||||
local target="$1" db_host="$2" smtp_block auth_source_blocks
|
||||
smtp_block="$(persisted_smtp_block)"
|
||||
if [ -n "$smtp_block" ]; then
|
||||
log "carrying forward the configured [smtp] relay"
|
||||
smtp_block="${smtp_block}"$'\n' # keep a blank line before the next section
|
||||
fi
|
||||
auth_source_blocks="$(persisted_auth_source_blocks)"
|
||||
cat > "$target" <<EOF
|
||||
# Generated by deploy/bootstrap.sh — do not edit by hand; rerun the installer.
|
||||
# Generated by deploy/bootstrap.sh; rerun the installer to regenerate. Hand edits are
|
||||
# overwritten, except [smtp] and [[auth_source]], which carry forward.
|
||||
[server]
|
||||
listen = "0.0.0.0:8080"
|
||||
root_domain = "${FELIS_ROOT_DOMAIN}"
|
||||
@@ -1976,12 +1999,10 @@ panel_hostname = "console.${FELIS_ROOT_DOMAIN}"
|
||||
${smtp_block}
|
||||
# Third-party Yggdrasil sources federated by the hasJoined multiplexer. Mojang is
|
||||
# always the code-owned identity anchor (premium-first), prepended in Go; sources here
|
||||
# append as namespace-rewritten guests. Shipping LittleSkin by default lets Mojang and
|
||||
# LittleSkin both log in out of the box. Delete this block for a Mojang-only server.
|
||||
[[auth_source]]
|
||||
tag = "littleskin"
|
||||
prefix = "LS"
|
||||
url = "https://littleskin.cn/api/yggdrasil/sessionserver/session/minecraft/hasJoined"
|
||||
# append as namespace-rewritten guests. A fresh install federates LittleSkin. Edit the
|
||||
# list in ${STATE_DIR}/felis.host.toml and rerun the installer; re-runs keep it as it
|
||||
# is, and with no [[auth_source]] at all the server is Mojang-only.
|
||||
${auth_source_blocks}
|
||||
EOF
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user