Compare commits

...

3 Commits
main ... main

8 changed files with 790 additions and 836 deletions

3
.gitignore vendored
View File

@ -13,3 +13,6 @@
# Keep the root pb_migrations folder tracked (empty placeholder for production)
!/pb_migrations/.gitkeep
.yarn

Binary file not shown.

View File

@ -1,6 +1,19 @@
import PocketBase from 'pocketbase';
const rawUrl = import.meta.env.VITE_POCKETBASE_URL ?? '';
// VITE_ vars are inlined at BUILD time, not runtime. If the image is built
// without --build-arg VITE_POCKETBASE_URL, this is empty and the SDK silently
// resolves requests against `https://` — producing `https://api/collections/...`
// which fails as a DNS error that looks like CORS. Fail loudly instead.
const rawUrl = import.meta.env.VITE_POCKETBASE_URL;
if (!rawUrl) {
throw new Error(
'VITE_POCKETBASE_URL is not set. It must be passed as a --build-arg when ' +
'building the Docker image — setting it at runtime has no effect, because ' +
'Vite inlines VITE_ variables into the bundle at build time.',
);
}
// Ensure URL always has a protocol so PocketBase SDK treats it as absolute
const pbUrl = rawUrl.startsWith('http') ? rawUrl : `https://${rawUrl}`;

View File

@ -89,7 +89,7 @@ export default function Login() {
<div className="inline-flex w-14 h-14 bg-black border border-neutral-800 rounded-2xl items-center justify-center shadow-lg shadow-black mb-4">
<span className="text-orange-500 font-extrabold text-3xl pl-1 select-none">t.</span>
</div>
<h1 className="text-2xl font-bold tracking-tight text-white uppercase">AR Management</h1>
<h1 className="text-2xl font-bold tracking-tight text-white uppercase">AR_Management</h1>
<p className="mt-1 text-neutral-500 text-xs uppercase tracking-wider">
Authorized Access Only
</p>

View File

@ -1,11 +1,28 @@
#!/bin/bash
set -e
set -euo pipefail
REGISTRY="registry.digitalocean.com/thob-blr1"
SHA=$(git rev-parse --short=10 HEAD)
# Load .env if present, so VITE_* don't have to be exported by hand.
if [ -f .env ]; then
echo "Loading build vars from .env"
set -a
# shellcheck disable=SC1091
. ./.env
set +a
fi
# VITE_ vars are inlined into the client bundle at BUILD time. If they are empty
# here, the app ships with a broken PocketBase URL (https://api/...) that fails
# in the browser as a DNS error resembling CORS. Refuse to build.
: "${VITE_POCKETBASE_URL:?VITE_POCKETBASE_URL is not set — export it or add it to .env}"
: "${VITE_FRONTEND_URL:?VITE_FRONTEND_URL is not set — export it or add it to .env}"
echo "Building commit: $SHA"
echo " VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL"
echo " VITE_FRONTEND_URL=$VITE_FRONTEND_URL"
# Login
doctl registry login
@ -14,13 +31,25 @@ doctl registry login
echo "Building AR App..."
docker buildx build \
--platform linux/amd64 \
--build-arg VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL \
--build-arg VITE_FRONTEND_URL=$VITE_FRONTEND_URL \
--build-arg "VITE_POCKETBASE_URL=$VITE_POCKETBASE_URL" \
--build-arg "VITE_FRONTEND_URL=$VITE_FRONTEND_URL" \
-f Dockerfile \
--load \
-t $REGISTRY/ar:$SHA \
-t $REGISTRY/ar:latest .
docker push $REGISTRY/ar:$SHA
docker push $REGISTRY/ar:latest
-t "$REGISTRY/ar:$SHA" \
-t "$REGISTRY/ar:latest" .
echo "✅ All images built and pushed successfully"
# Verify the URL actually made it into the client bundle before pushing.
echo "Verifying baked-in PocketBase URL..."
PB_HOST=$(echo "$VITE_POCKETBASE_URL" | sed -e 's#^https\?://##' -e 's#/.*$##')
if ! docker run --rm --entrypoint sh "$REGISTRY/ar:$SHA" \
-c "grep -rq '$PB_HOST' /app/build/client"; then
echo "❌ Build verification failed: '$PB_HOST' not found in the client bundle."
echo " The image was NOT pushed."
exit 1
fi
echo "✅ Verified: $PB_HOST is baked into the client bundle"
docker push "$REGISTRY/ar:$SHA"
docker push "$REGISTRY/ar:latest"
echo "✅ All images built and pushed successfully (tag: $SHA)"

View File

@ -79,9 +79,10 @@ services:
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
expose:
- "3000"
# NOTE: VITE_* vars are inlined into the client bundle at BUILD time by Vite.
# Setting them here has NO effect on the pulled image — they must be passed
# as --build-arg in build-and-push.sh. Only server-side vars belong below.
environment:
- VITE_POCKETBASE_URL=${VITE_POCKETBASE_URL:-https://pb.ar.thob.studio}
- VITE_FRONTEND_URL=${VITE_FRONTEND_URL:-https://ar.thob.studio}
- INTERNAL_POCKETBASE_URL=http://ar-pb:8090
depends_on:
- pocketbase
@ -89,6 +90,9 @@ services:
- traefik
labels:
- "wud.watch=true"
# Required: the :latest tag doesn't change, so wud must compare digests
# to notice a new image was pushed to the same tag.
- "wud.watch.digest=true"
- "traefik.enable=true"
- "traefik.docker.network=traefik"
- "traefik.http.routers.ar-app.rule=Host(`ar.thob.studio`)"
@ -121,4 +125,4 @@ services:
- "traefik.http.routers.ar-pb.tls=true"
- "traefik.http.routers.ar-pb.tls.certresolver=letsencrypt"
- "traefik.http.routers.ar-pb.service=ar-pb"
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"
- "traefik.http.services.ar-pb.loadbalancer.server.port=8090"

13
package-lock.json generated
View File

@ -70,7 +70,6 @@
"integrity": "sha512-e7jT4DxYvIDLk1ZHmU/m/mB19rex9sv0c2ftBtjSBv+kVM/902eh0fINUzD7UwLLNR+jU585GxUJ8/EBfAM5fw==",
"dev": true,
"license": "MIT",
"peer": true,
"dependencies": {
"@babel/code-frame": "^7.27.1",
"@babel/generator": "^7.28.5",
@ -1447,7 +1446,6 @@
"resolved": "https://registry.npmjs.org/@react-router/serve/-/serve-7.10.0.tgz",
"integrity": "sha512-tgdbw1lmDkzF3gCMj//iNklgUrYHUxz35rj0sbyLeti8K2gVsNxaZWyt5omanFgkeZ7WYfi0wzLHviqxl228eA==",
"license": "MIT",
"peer": true,
"dependencies": {
"@mjackson/node-fetch-server": "^0.2.0",
"@react-router/express": "7.10.0",
@ -2101,7 +2099,6 @@
"integrity": "sha512-MWtvHrGZLFttgeEj28VXHxpmwYbor/ATPYbBfSFZEIRK0ecCFLl2Qo55z52Hss+UV9CRN7trSeq1zbgx7YDWWg==",
"devOptional": true,
"license": "MIT",
"peer": true,
"dependencies": {
"csstype": "^3.2.2"
}
@ -2112,7 +2109,6 @@
"integrity": "sha512-jp2L/eY6fn+KgVVQAOqYItbF0VY/YApe5Mz2F0aykSO8gx31bYCZyvSeYxCHKvzHG5eZjc+zyaS5BrBWya2+kQ==",
"devOptional": true,
"license": "MIT",
"peer": true,
"peerDependencies": {
"@types/react": "^19.2.0"
}
@ -2325,7 +2321,6 @@
}
],
"license": "MIT",
"peer": true,
"dependencies": {
"baseline-browser-mapping": "^2.8.25",
"caniuse-lite": "^1.0.30001754",
@ -2853,7 +2848,6 @@
"resolved": "https://registry.npmjs.org/express/-/express-4.22.1.tgz",
"integrity": "sha512-F2X8g9P1X7uCPZMA3MVf9wcTqlyNp7IhH5qPCI0izhaOIYXaW9L535tGA3qmjRzpH+bZczqq7hVKxTR4NWnu+g==",
"license": "MIT",
"peer": true,
"dependencies": {
"accepts": "~1.3.8",
"array-flatten": "1.1.1",
@ -3869,7 +3863,6 @@
"integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==",
"dev": true,
"license": "MIT",
"peer": true,
"engines": {
"node": ">=12"
},
@ -4030,7 +4023,6 @@
"resolved": "https://registry.npmjs.org/react/-/react-19.2.0.tgz",
"integrity": "sha512-tmbWg6W31tQLeB5cdIBOicJDJRR2KzXsV7uSK9iNfLWQ5bIZfxuPEHp7M8wiHyHnn0DD1i7w3Zmin0FtkrwoCQ==",
"license": "MIT",
"peer": true,
"engines": {
"node": ">=0.10.0"
}
@ -4040,7 +4032,6 @@
"resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.2.0.tgz",
"integrity": "sha512-UlbRu4cAiGaIewkPyiRGJk0imDN2T3JjieT6spoL2UeSf5od4n5LB/mQ4ejmxhCFT1tYe8IvaFulzynWovsEFQ==",
"license": "MIT",
"peer": true,
"dependencies": {
"scheduler": "^0.27.0"
},
@ -4053,7 +4044,6 @@
"resolved": "https://registry.npmjs.org/react-hook-form/-/react-hook-form-7.82.0.tgz",
"integrity": "sha512-Zw/uFZ2dO+02GHlBn7JFGn8kZJ7LdM33B/0BXOovzFay+CMhf94JMw5BVu+F1tVkUKjNvBuaE3fz5BJhga10Tg==",
"license": "MIT",
"peer": true,
"engines": {
"node": ">=18.0.0"
},
@ -4127,7 +4117,6 @@
"resolved": "https://registry.npmjs.org/react-router/-/react-router-7.10.0.tgz",
"integrity": "sha512-FVyCOH4IZ0eDDRycODfUqoN8ZSR2LbTvtx6RPsBgzvJ8xAXlMZNCrOFpu+jb8QbtZnpAd/cEki2pwE848pNGxw==",
"license": "MIT",
"peer": true,
"dependencies": {
"cookie": "^1.0.1",
"set-cookie-parser": "^2.6.0"
@ -4715,7 +4704,6 @@
"integrity": "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==",
"devOptional": true,
"license": "Apache-2.0",
"peer": true,
"bin": {
"tsc": "bin/tsc",
"tsserver": "bin/tsserver"
@ -4853,7 +4841,6 @@
"integrity": "sha512-tI2l/nFHC5rLh7+5+o7QjKjSR04ivXDF4jcgV0f/bTQ+OJiITy5S6gaynVsEM+7RqzufMnVbIon6Sr5x1SDYaQ==",
"dev": true,
"license": "MIT",
"peer": true,
"dependencies": {
"esbuild": "^0.25.0",
"fdir": "^6.5.0",

1538
yarn.lock

File diff suppressed because it is too large Load Diff