mirror of
https://codeberg.org/PostERG/xamxam.git
synced 2026-09-25 01:53:03 +02:00
fix(deploy): restore www-data ownership after deploy-code to prevent HTTP 500
This commit is contained in:
Executable
+66
@@ -0,0 +1,66 @@
|
||||
#!/bin/bash
|
||||
# Fix XAMXAM file ownership + permissions on the production host.
|
||||
#
|
||||
# php-fpm runs as www-data, so the whole app tree must be group-owned by
|
||||
# www-data:xamxam with setgid dirs (2775) and 664 files — otherwise www-data
|
||||
# cannot create the SQLite WAL/journal side-cars in storage/ (→ HTTP 500) nor
|
||||
# write cache/tmp/log dirs.
|
||||
#
|
||||
# This is the ownership half of scripts/deploy-server.sh, factored out so
|
||||
# `just deploy-code` can restore correct ownership after an rsync resync
|
||||
# (plain `rsync -az` as a non-root user preserves the calling user's owner,
|
||||
# not www-data:xamxam).
|
||||
#
|
||||
# Usage: sudo bash /tmp/fix-permissions.sh
|
||||
#
|
||||
# Wired into the justfile as `deploy-permissions` (run at the end of
|
||||
# `deploy-code`, and as a dependency of `deploy`).
|
||||
|
||||
set -e
|
||||
|
||||
RED='\033[0;31m'; GREEN='\033[0;32m'; YELLOW='\033[1;33m'; NC='\033[0m'
|
||||
ok() { printf "${GREEN}✓${NC} %s\n" "$*"; }
|
||||
ok "Fixing permissions"
|
||||
|
||||
[ "$EUID" -eq 0 ] || { printf "${RED}✗${NC} Run as root (sudo)\n" >&2; exit 1; }
|
||||
|
||||
APP_DIR="/var/www/xamxam"
|
||||
|
||||
chown -R www-data:xamxam "$APP_DIR/"
|
||||
ok "Ownership: www-data:xamxam"
|
||||
|
||||
find "$APP_DIR" -type d -exec chmod 2775 {} \;
|
||||
ok "Directories: 2775 (setgid)"
|
||||
|
||||
find "$APP_DIR" -type f -exec chmod 664 {} \;
|
||||
ok "Files: 664"
|
||||
|
||||
if [ -d "$APP_DIR/storage" ]; then
|
||||
chmod 2775 "$APP_DIR/storage"
|
||||
# SQLite + WAL/SHM side-cars must be writable by www-data
|
||||
find "$APP_DIR/storage" -name "*.db" -exec chmod 660 {} \;
|
||||
find "$APP_DIR/storage" -name "*.db-wal" -exec chmod 660 {} \;
|
||||
find "$APP_DIR/storage" -name "*.db-shm" -exec chmod 660 {} \;
|
||||
ok "Storage: 2775, databases (+WAL/SHM): 660"
|
||||
fi
|
||||
|
||||
# .env config is a secret — extra-restrictive regardless of the 664 sweep
|
||||
if [ -f "$APP_DIR/.env" ]; then
|
||||
chmod 640 "$APP_DIR/.env"
|
||||
ok ".env: 640"
|
||||
fi
|
||||
|
||||
# App var/ dirs (cache/logs/tmp) must stay writable by php-fpm
|
||||
mkdir -p "$APP_DIR/var/{cache,logs,tmp}"
|
||||
chown -R www-data:xamxam "$APP_DIR/var"
|
||||
chmod -R 2775 "$APP_DIR/var"
|
||||
ok "var/ dirs: www-data:xamxam (2775)"
|
||||
|
||||
# Cache + PHP upload temp (create so first request doesn't race)
|
||||
mkdir -p "$APP_DIR/storage/cache/rate_limit"
|
||||
chown -R www-data:xamxam "$APP_DIR/storage/cache"
|
||||
chmod -R 2775 "$APP_DIR/storage/cache"
|
||||
mkdir -p "$APP_DIR/storage/tmp/php-uploads"
|
||||
chown www-data:xamxam "$APP_DIR/storage/tmp/php-uploads"
|
||||
chmod 2775 "$APP_DIR/storage/tmp/php-uploads"
|
||||
ok "Cache + upload tmp dirs ready"
|
||||
Reference in New Issue
Block a user