Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ The runtime handles development plumbing only:
- configure the default Git identity
- provide Shopware CLI as the standard extension validation/build tool
- mirror public sales-channel domains onto the internal `http://shop` origin for authenticated-gateway-free browser smoke tests
- configure Shopware to trust forwarded client metadata only from the Coolify reverse proxy
- configure GitHub App credentials for HTTPS Git operations
- clone repositories listed in `DEV_PLUGINS` into `custom/plugins`
- leave existing Git working copies untouched on restart
Expand Down
13 changes: 0 additions & 13 deletions compose.coolify.example.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -71,9 +71,6 @@ services:
- vscode_server:/var/www/.vscode-server
- codex_home:/var/www/.codex

configs:
- source: shopware_reverse_proxy
target: /var/www/html/config/packages/z-framework.yaml

labels:
- 'coolify.traefik.middlewares=authentik-forward-auth@file'
Expand All @@ -86,16 +83,6 @@ services:
- 'sshpiper.docker_sshd_cmd=/bin/bash'


configs:
shopware_reverse_proxy:
content: |
framework:
trusted_proxies: 'REMOTE_ADDR'
trusted_headers:
- 'x-forwarded-proto'
- 'x-forwarded-port'


volumes:
dev_runtime:
shopware_html:
Expand Down
45 changes: 45 additions & 0 deletions scripts/dev-provision.sh
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,51 @@ if ! id developer >/dev/null 2>&1; then
exit 1
fi

# Trust only the Coolify reverse proxy for forwarded request metadata.
# Using Symfony's REMOTE_ADDR shortcut together with X-Forwarded-For would
# also trust direct requests from other containers on the project network.
proxy_host="${SHOPWARE_TRUSTED_PROXY_HOST:-coolify-proxy}"
trusted_proxy_file=/var/www/html/config/packages/z-framework.yaml
mapfile -t proxy_ips < <(
getent ahosts "$proxy_host" 2>/dev/null \
| awk '$2 == "STREAM" && !seen[$1]++ { print $1 }'
)

if (( ${#proxy_ips[@]} > 0 )); then
proxy_config_tmp="$(mktemp)"

{
printf '%s\n' 'framework:' ' trusted_proxies:'

for proxy_ip in "${proxy_ips[@]}"; do
printf " - '%s'\n" "$proxy_ip"
done

printf '%s\n' \
' trusted_headers:' \
" - 'x-forwarded-for'" \
" - 'x-forwarded-proto'" \
" - 'x-forwarded-port'"
} >"$proxy_config_tmp"

if [[ ! -f "$trusted_proxy_file" ]] || ! cmp -s "$proxy_config_tmp" "$trusted_proxy_file"; then
sudo install -d -m 0755 "$(dirname "$trusted_proxy_file")"
sudo install -m 0644 "$proxy_config_tmp" "$trusted_proxy_file"

if ! (
cd /var/www/html
bin/console cache:clear
); then
printf '%s\n' 'Warning: Shopware cache clear after trusted proxy configuration failed.' >&2
fi
fi

rm -f "$proxy_config_tmp"
else
printf 'Warning: trusted proxy host "%s" could not be resolved; forwarded client IP headers remain untrusted.\n' \
"$proxy_host" >&2
fi

# Persistent remote-development state is mounted here by the Coolify template.
# Fresh named volumes are root-owned, so make their mount points writable by
# Dockware's developer user while preserving any existing contents.
Expand Down
Loading