Disable legacy HTTP image hooks by default

This commit is contained in:
2026-08-06 11:25:39 +00:00
parent f04b81c606
commit 87cc2977d5
5 changed files with 36 additions and 2 deletions
+1
View File
@@ -2,6 +2,7 @@
/hook/logs.txt
/hook/list.json
/hook/HashKey.php
/hook/legacy-enabled
/hook/inventory.v2.json
/.env
/secrets/*
+7
View File
@@ -77,6 +77,13 @@ Use branch filter `master`. Disable the old PHP webhook before enabling the new
writer. The legacy PHP files remain in `hook/` for an explicit rollback, but
PHP and Node must never mutate the checkout concurrently.
Legacy HTTP mutation is disabled by default. An emergency PHP rollback must
first stop `image-hook`, then create the ignored `hook/legacy-enabled` sentinel
in the legacy checkout before restoring its Caddy/Gitea route. Remove the
sentinel before Node is started again. CLI execution of `hook/git_pull.php`
from the `hook/` directory remains available for local recovery without
exposing the HTTP endpoint.
### Start and verify
```sh
+8 -1
View File
@@ -2,6 +2,13 @@
namespace sammo\img_service;
header('Content-Type: application/json');
if (!file_exists(__DIR__.'/legacy-enabled')) {
http_response_code(410);
die(json_encode([
'result'=>false,
'reason'=>'legacy key installation disabled',
]));
}
$json_response = [
@@ -33,4 +40,4 @@ file_put_contents(__DIR__.'/HashKey.php', $keyFile);
$json_response['result'] = true;
$json_response['reason'] = 'success';
die(json_encode($json_response));
die(json_encode($json_response));
+11 -1
View File
@@ -1,6 +1,16 @@
<?php
namespace sammo\img_service;
if (php_sapi_name() !== 'cli' && !file_exists(__DIR__.'/legacy-enabled')) {
header('Content-Type: application/json');
http_response_code(410);
die(json_encode([
'result'=>false,
'reason'=>'legacy pull disabled',
'version'=>null,
]));
}
include(__DIR__.'/HashKey.php');
function hashPassword($salt, $password)
@@ -106,4 +116,4 @@ file_put_contents('list.json', json_encode($img_list));
$json_response['result'] = true;
$json_response['reason'] = 'success';
$json_response['version'] = getVersion();
die(json_encode($json_response));
die(json_encode($json_response));
+9
View File
@@ -2,6 +2,15 @@
namespace sammo\img_service;
header('Content-Type: application/json');
if (!file_exists(__DIR__.'/legacy-enabled')) {
http_response_code(410);
die(json_encode([
'result'=>false,
'reason'=>'legacy hook disabled',
]));
}
include(__DIR__.'/gogs_key.php');