mirror of
https://github.com/YunoHost-Apps/cryptpad_ynh.git
synced 2024-09-03 18:26:14 +02:00
256 lines
9.3 KiB
Bash
256 lines
9.3 KiB
Bash
#!/bin/bash
|
|
|
|
#=================================================
|
|
# GENERIC START
|
|
#=================================================
|
|
# IMPORT GENERIC HELPERS
|
|
#=================================================
|
|
|
|
source _common.sh
|
|
source /usr/share/yunohost/helpers
|
|
|
|
#=================================================
|
|
# MANAGE SCRIPT FAILURE
|
|
#=================================================
|
|
|
|
ynh_clean_setup () {
|
|
ynh_clean_check_starting
|
|
}
|
|
# Exit if an error occurs during the execution of the script
|
|
ynh_abort_if_errors
|
|
|
|
#=================================================
|
|
# RETRIEVE ARGUMENTS FROM THE MANIFEST
|
|
#=================================================
|
|
|
|
domain=$YNH_APP_ARG_DOMAIN
|
|
path_url="/"
|
|
is_public=$YNH_APP_ARG_IS_PUBLIC
|
|
admin=$YNH_APP_ARG_ADMIN
|
|
email=$(ynh_user_get_info --username=$admin --key=mail)
|
|
|
|
app=$YNH_APP_INSTANCE_NAME
|
|
|
|
#=================================================
|
|
# CHECK IF THE APP CAN BE INSTALLED WITH THESE ARGS
|
|
#=================================================
|
|
ynh_script_progression --message="Validating installation parameters..." --weight=1
|
|
|
|
final_path=/var/www/$app
|
|
test ! -e "$final_path" || ynh_die --message="This path already contains a folder"
|
|
|
|
# Register (book) web path
|
|
ynh_webpath_register --app=$app --domain=$domain --path_url=$path_url
|
|
|
|
#=================================================
|
|
# STORE SETTINGS FROM MANIFEST
|
|
#=================================================
|
|
ynh_script_progression --message="Storing installation settings..."
|
|
|
|
ynh_app_setting_set --app=$app --key=domain --value=$domain
|
|
ynh_app_setting_set --app=$app --key=path --value=$path_url
|
|
ynh_app_setting_set --app=$app --key=admin --value=$admin
|
|
|
|
#=================================================
|
|
# STANDARD MODIFICATIONS
|
|
#=================================================
|
|
# FIND AND OPEN A PORT
|
|
#=================================================
|
|
ynh_script_progression --message="Finding an available port..." --weight=1
|
|
|
|
# Find an available port
|
|
port=$(ynh_find_port --port=3000)
|
|
ynh_app_setting_set --app=$app --key=port --value=$port
|
|
|
|
# Find an available port
|
|
porti=$(ynh_find_port --port=$(($port + 1)))
|
|
ynh_app_setting_set --app=$app --key=porti --value=$porti
|
|
|
|
#=================================================
|
|
# CREATE A SANDBOX DOMAIN
|
|
#=================================================
|
|
|
|
# if the main domain for the app is a root domain, we create a correct sandbox subdomain
|
|
if [ $domain == *"."* ]; then
|
|
sandboxdomain=sandbox.$domain
|
|
fi
|
|
# if the main domain for the app is already a sub-domain, we create a correct sandbox domain
|
|
if [ $domain == *"."*"."* ]; then
|
|
sandboxdomain=sandbox-$domain
|
|
fi
|
|
# if the main domain for the app is a .local root domain, we create a correct sandbox subdomain
|
|
if [ $domain == *".local" ]; then
|
|
sandboxdomain=sandbox-$domain
|
|
fi
|
|
|
|
ynh_script_progression --message="Setting up sandobx domain $sandboxdomain..." --weight=1
|
|
|
|
# We don't test that in CI
|
|
if ! [ ${PACKAGE_CHECK_EXEC:-0} -eq 1 ]; then
|
|
yunohost domain add $sandboxdomain
|
|
yunohost domain config set $sandboxdomain -a "mail_in=0&mail_out=0"
|
|
fi
|
|
|
|
#=================================================
|
|
# INSTALL DEPENDENCIES
|
|
#=================================================
|
|
ynh_script_progression --message="Installing dependencies..." --weight=20
|
|
|
|
ynh_exec_warn_less ynh_install_nodejs --nodejs_version=$nodejs_version
|
|
|
|
#=================================================
|
|
# CREATE DEDICATED USER
|
|
#=================================================
|
|
ynh_script_progression --message="Configuring system user..." --weight=1
|
|
|
|
# Create a system user
|
|
ynh_system_user_create --username=$app --home_dir="$final_path"
|
|
|
|
#=================================================
|
|
# DOWNLOAD, CHECK AND UNPACK SOURCE
|
|
#=================================================
|
|
ynh_script_progression --message="Setting up source files..." --weight=10
|
|
|
|
ynh_app_setting_set --app=$app --key=final_path --value=$final_path
|
|
# Download, check integrity, uncompress and patch the source from app.src
|
|
ynh_setup_source --dest_dir="$final_path"
|
|
|
|
chmod 750 "$final_path"
|
|
chmod -R o-rwx "$final_path"
|
|
chown -R $app:$app "$final_path"
|
|
|
|
#=================================================
|
|
# NGINX CONFIGURATION
|
|
#=================================================
|
|
ynh_script_progression --message="Configuring NGINX web server..." --weight=1
|
|
|
|
# Create a dedicated NGINX config
|
|
ynh_add_nginx_config
|
|
|
|
#=================================================
|
|
# ADD A CONFIGURATION
|
|
#=================================================
|
|
ynh_script_progression --message="Adding a configuration file..."
|
|
|
|
ynh_add_config --template="../conf/config.js" --destination="$final_path/config/config.js"
|
|
|
|
chmod 600 "$final_path/config/config.js"
|
|
chown $app "$final_path/config/config.js"
|
|
|
|
#=================================================
|
|
# SETUP SYSTEMD
|
|
#=================================================
|
|
ynh_script_progression --message="Configuring a systemd service..." --weight=1
|
|
|
|
env_path="$PATH"
|
|
# Create a dedicated systemd config
|
|
ynh_add_systemd_config
|
|
|
|
#=================================================
|
|
# INSTALL CRYPTPAD
|
|
#=================================================
|
|
ynh_script_progression --message="Building $app... (this will take some time and resources!)" --weight=60
|
|
|
|
pushd "$final_path"
|
|
ynh_use_nodejs
|
|
ynh_exec_warn_less npm install --allow-root
|
|
ynh_exec_warn_less npm install -g bower
|
|
ynh_exec_warn_less bower install --allow-root
|
|
ynh_exec_warn_less bower update --allow-root
|
|
ynh_exec_warn_less npm run build
|
|
popd
|
|
|
|
#=================================================
|
|
# GENERIC FINALIZATION
|
|
#=================================================
|
|
# INTEGRATE SERVICE IN YUNOHOST
|
|
#=================================================
|
|
ynh_script_progression --message="Integrating service in YunoHost..." --weight=1
|
|
|
|
yunohost service add $app --description="Zero Knowledge realtime collaborative editor" --log="/var/log/$app/$app.log"
|
|
|
|
#=================================================
|
|
# START SYSTEMD SERVICE
|
|
#=================================================
|
|
ynh_script_progression --message="Starting a systemd service..." --weight=2
|
|
|
|
# Start a systemd service
|
|
ynh_systemd_action --service_name=$app --action="start" --log_path="systemd" --line_match="server available"
|
|
|
|
#=================================================
|
|
# SETUP SSOWAT
|
|
#=================================================
|
|
ynh_script_progression --message="Configuring permissions..." --weight=1
|
|
|
|
# Make app public if necessary
|
|
if [ $is_public -eq 1 ]
|
|
then
|
|
ynh_permission_update --permission="main" --add="visitors"
|
|
fi
|
|
|
|
# We authorize access to sandbox domain
|
|
# We don't test that in CI
|
|
if ! [ ${PACKAGE_CHECK_EXEC:-0} -eq 1 ]; then
|
|
ynh_permission_url --permission="main" --add_url=re:$sandboxdomain --auth_header=true
|
|
# there is a bug in core that add a slash at the end of domain in ssowat conf for uris var
|
|
# we use jq to correct /etc/ssowat/conf.json
|
|
#uri2=$sandboxdomain
|
|
#touch /etc/ssowat/conf.json.persistent
|
|
#cat /etc/ssowat/conf.json | jq --arg uri2 "$uri2" '(.permissions[] | select(.label=="CryptPad") | .uris[1]) |=$uri2' >> /etc/ssowat/conf.json.persistent
|
|
fi
|
|
|
|
#=================================================
|
|
# APPLY FOLDER RIGHTS
|
|
#=================================================
|
|
chgrp -R www-data $final_path
|
|
|
|
#=================================================
|
|
# COPY NGINX CONF IN SANDBOX DOMAIN
|
|
#=================================================
|
|
# We don't test that in CI
|
|
if ! [ ${PACKAGE_CHECK_EXEC:-0} -eq 1 ]; then
|
|
ynh_add_config --template="/etc/nginx/conf.d/$domain.d/cryptpad.conf" --destination="/etc/nginx/conf.d/$sandboxdomain.d/cryptpad.conf"
|
|
fi
|
|
|
|
#=================================================
|
|
# RELOAD YUNOHOST-API to refresh web admin domains after domain creation (normal?)
|
|
#=================================================
|
|
ynh_systemd_action --service_name=yunohost-api --action=reload
|
|
|
|
#=================================================
|
|
# RELOAD NGINX
|
|
#=================================================
|
|
ynh_script_progression --message="Reloading NGINX web server..." --weight=1
|
|
|
|
ynh_systemd_action --service_name=nginx --action=reload
|
|
|
|
#=================================================
|
|
# SEND A README FOR THE ADMIN
|
|
#=================================================
|
|
ynh_script_progression --message="Sending a readme for the admin..." --weight=1
|
|
|
|
message="CryptPad was successfully installed :)
|
|
|
|
We have added a sandbox domain for you but you still need to configure your DNS and generate Let's Encrypt Certificates for it.
|
|
|
|
Then you can please open your $app domain: https://$domain$path_url
|
|
Once CryptPad is installed, create an account via the Sign Up button on the home page which will take you to the Register page.
|
|
To make this account an instance administrator:
|
|
|
|
1. Copy the public key found in User Menu (avatar at the top right) > Settings > Account > Public Signing Key
|
|
2. Paste this key in /var/www/cryptpad/config/config.js in the following array (uncomment and replace the placeholder):
|
|
|
|
adminKeys: [
|
|
"[cryptpad-user1@my.awesome.website/YZgXQxKR0Rcb6r6CmxHPdAGLVludrAF2lEnkbx1vVOo=]",
|
|
],
|
|
|
|
|
|
If you are facing an issue or want to improve this app, please open a new issue in this project: https://github.com/YunoHost-Apps/cryptpad_ynh"
|
|
|
|
ynh_send_readme_to_admin "$message"
|
|
|
|
#=================================================
|
|
# END OF SCRIPT
|
|
#=================================================
|
|
|
|
ynh_script_progression --message="Installation of $app completed" --last
|