diff --git a/.gitignore b/.gitignore index 8ef8722..d034db3 100644 --- a/.gitignore +++ b/.gitignore @@ -2,6 +2,7 @@ /hook/logs.txt /hook/list.json /hook/HashKey.php +/hook/legacy-enabled /hook/inventory.v2.json /.env /secrets/* diff --git a/README.md b/README.md index c55defd..a3ff063 100644 --- a/README.md +++ b/README.md @@ -77,6 +77,13 @@ Use branch filter `master`. Disable the old PHP webhook before enabling the new writer. The legacy PHP files remain in `hook/` for an explicit rollback, but PHP and Node must never mutate the checkout concurrently. +Legacy HTTP mutation is disabled by default. An emergency PHP rollback must +first stop `image-hook`, then create the ignored `hook/legacy-enabled` sentinel +in the legacy checkout before restoring its Caddy/Gitea route. Remove the +sentinel before Node is started again. CLI execution of `hook/git_pull.php` +from the `hook/` directory remains available for local recovery without +exposing the HTTP endpoint. + ### Start and verify ```sh diff --git a/hook/InstallKey.php b/hook/InstallKey.php index d252065..1e278c3 100644 --- a/hook/InstallKey.php +++ b/hook/InstallKey.php @@ -2,6 +2,13 @@ namespace sammo\img_service; header('Content-Type: application/json'); +if (!file_exists(__DIR__.'/legacy-enabled')) { + http_response_code(410); + die(json_encode([ + 'result'=>false, + 'reason'=>'legacy key installation disabled', + ])); +} $json_response = [ @@ -33,4 +40,4 @@ file_put_contents(__DIR__.'/HashKey.php', $keyFile); $json_response['result'] = true; $json_response['reason'] = 'success'; -die(json_encode($json_response)); \ No newline at end of file +die(json_encode($json_response)); diff --git a/hook/git_pull.php b/hook/git_pull.php index 5137be9..e93a9fb 100644 --- a/hook/git_pull.php +++ b/hook/git_pull.php @@ -1,6 +1,16 @@ false, + 'reason'=>'legacy pull disabled', + 'version'=>null, + ])); +} + include(__DIR__.'/HashKey.php'); function hashPassword($salt, $password) @@ -106,4 +116,4 @@ file_put_contents('list.json', json_encode($img_list)); $json_response['result'] = true; $json_response['reason'] = 'success'; $json_response['version'] = getVersion(); -die(json_encode($json_response)); \ No newline at end of file +die(json_encode($json_response)); diff --git a/hook/hook.php b/hook/hook.php index 78a6e28..5cf2ff5 100644 --- a/hook/hook.php +++ b/hook/hook.php @@ -2,6 +2,15 @@ namespace sammo\img_service; +header('Content-Type: application/json'); +if (!file_exists(__DIR__.'/legacy-enabled')) { + http_response_code(410); + die(json_encode([ + 'result'=>false, + 'reason'=>'legacy hook disabled', + ])); +} + include(__DIR__.'/gogs_key.php');