392 lines
17 KiB
Bash
Executable File
392 lines
17 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
|
|
domain=${1:-}
|
|
target=${2:-"$ROOT/.env"}
|
|
|
|
if [[ -z "$domain" ]]; then
|
|
echo "Usage: $0 DOMAIN [OUTPUT_FILE]" >&2
|
|
exit 1
|
|
fi
|
|
|
|
require_single_line_env_value() {
|
|
local value_name=$1
|
|
local value=$2
|
|
|
|
if [[ "$value" == *$'\n'* ]]; then
|
|
echo "$value_name must not contain control characters because .env stores one value per line." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if printf '%s' "$value" | LC_ALL=C grep -q '[[:cntrl:]]'; then
|
|
echo "$value_name must not contain control characters because .env stores one value per line." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ "$value" == ' '* || "$value" == *' ' ||
|
|
"$value" == \"* || "$value" == \'* || "$value" == *' #'* ]]; then
|
|
echo "$value_name cannot be represented safely as an unquoted Compose .env value." >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
if [[ ! "$domain" =~ ^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?(\.[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?)+$ ]]; then
|
|
echo "DOMAIN must be a lowercase ASCII DNS hostname without a scheme, port, or path." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ "$target" != /* ]]; then
|
|
target="$ROOT/$target"
|
|
fi
|
|
|
|
for command in awk docker git grep mktemp openssl stat; do
|
|
command -v "$command" >/dev/null 2>&1 || {
|
|
echo "Required command is unavailable: $command" >&2
|
|
exit 1
|
|
}
|
|
done
|
|
|
|
[[ -S /var/run/docker.sock ]] || {
|
|
echo "/var/run/docker.sock is unavailable; run this on the target Docker host." >&2
|
|
exit 1
|
|
}
|
|
|
|
[[ ! -e "$target" ]] || {
|
|
echo "Refusing to overwrite existing test environment: $target" >&2
|
|
exit 1
|
|
}
|
|
|
|
target_dir=$(dirname -- "$target")
|
|
[[ -d "$target_dir" ]] || {
|
|
echo "Output directory does not exist: $target_dir" >&2
|
|
exit 1
|
|
}
|
|
|
|
compose_project_name=${TEST_COMPOSE_PROJECT_NAME:-who_need_help_test}
|
|
public_edge_network=${TEST_PUBLIC_EDGE_NETWORK:-who_need_help_public_edge}
|
|
public_upstream_name=${TEST_PUBLIC_UPSTREAM_NAME:-who-need-help-test}
|
|
http_bind_address=${TEST_HTTP_BIND_ADDRESS:-127.0.0.1}
|
|
http_port=${TEST_HTTP_PORT:-4011}
|
|
mailpit_bind_address=${TEST_MAILPIT_BIND_ADDRESS:-127.0.0.1}
|
|
mailpit_port=${TEST_MAILPIT_PORT:-8027}
|
|
codex_session_id=${TEST_CODEX_SESSION_ID:-}
|
|
google_oauth_client_id=${TEST_GOOGLE_OAUTH_CLIENT_ID:-}
|
|
google_oauth_client_secret=${TEST_GOOGLE_OAUTH_CLIENT_SECRET:-}
|
|
google_oauth_authorized_party_ids=${TEST_GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS:-}
|
|
web_push_vapid_public_key=${TEST_WEB_PUSH_VAPID_PUBLIC_KEY:-}
|
|
web_push_vapid_private_key=${TEST_WEB_PUSH_VAPID_PRIVATE_KEY:-}
|
|
web_push_vapid_subject=${TEST_WEB_PUSH_VAPID_SUBJECT:-}
|
|
firebase_application_id=${TEST_WNH_FIREBASE_APPLICATION_ID:-}
|
|
firebase_api_key=${TEST_WNH_FIREBASE_API_KEY:-}
|
|
firebase_project_id=${TEST_WNH_FIREBASE_PROJECT_ID:-}
|
|
firebase_sender_id=${TEST_WNH_FIREBASE_GCM_SENDER_ID:-}
|
|
fcm_project_id=${TEST_FCM_PROJECT_ID:-}
|
|
fcm_service_account_json_base64=${TEST_FCM_SERVICE_ACCOUNT_JSON_BASE64:-}
|
|
android_app_links_package_name=${TEST_ANDROID_APP_LINKS_PACKAGE_NAME:-}
|
|
android_app_links_fingerprints=${TEST_ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS:-}
|
|
support_inbox_address=${TEST_SUPPORT_INBOX_ADDRESS:-}
|
|
git_sha=$(git -C "$ROOT" rev-parse --short=12 HEAD)
|
|
|
|
require_single_line_env_value TEST_COMPOSE_PROJECT_NAME "$compose_project_name"
|
|
require_single_line_env_value TEST_PUBLIC_EDGE_NETWORK "$public_edge_network"
|
|
require_single_line_env_value TEST_PUBLIC_UPSTREAM_NAME "$public_upstream_name"
|
|
require_single_line_env_value TEST_HTTP_BIND_ADDRESS "$http_bind_address"
|
|
require_single_line_env_value TEST_HTTP_PORT "$http_port"
|
|
require_single_line_env_value TEST_MAILPIT_BIND_ADDRESS "$mailpit_bind_address"
|
|
require_single_line_env_value TEST_MAILPIT_PORT "$mailpit_port"
|
|
require_single_line_env_value TEST_CODEX_SESSION_ID "$codex_session_id"
|
|
require_single_line_env_value TEST_GOOGLE_OAUTH_CLIENT_ID "$google_oauth_client_id"
|
|
require_single_line_env_value TEST_GOOGLE_OAUTH_CLIENT_SECRET "$google_oauth_client_secret"
|
|
require_single_line_env_value \
|
|
TEST_GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS "$google_oauth_authorized_party_ids"
|
|
require_single_line_env_value TEST_WEB_PUSH_VAPID_PUBLIC_KEY "$web_push_vapid_public_key"
|
|
require_single_line_env_value TEST_WEB_PUSH_VAPID_PRIVATE_KEY "$web_push_vapid_private_key"
|
|
require_single_line_env_value TEST_WEB_PUSH_VAPID_SUBJECT "$web_push_vapid_subject"
|
|
require_single_line_env_value TEST_WNH_FIREBASE_APPLICATION_ID "$firebase_application_id"
|
|
require_single_line_env_value TEST_WNH_FIREBASE_API_KEY "$firebase_api_key"
|
|
require_single_line_env_value TEST_WNH_FIREBASE_PROJECT_ID "$firebase_project_id"
|
|
require_single_line_env_value TEST_WNH_FIREBASE_GCM_SENDER_ID "$firebase_sender_id"
|
|
require_single_line_env_value TEST_FCM_PROJECT_ID "$fcm_project_id"
|
|
require_single_line_env_value TEST_FCM_SERVICE_ACCOUNT_JSON_BASE64 "$fcm_service_account_json_base64"
|
|
require_single_line_env_value TEST_ANDROID_APP_LINKS_PACKAGE_NAME "$android_app_links_package_name"
|
|
require_single_line_env_value TEST_ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS "$android_app_links_fingerprints"
|
|
require_single_line_env_value TEST_SUPPORT_INBOX_ADDRESS "$support_inbox_address"
|
|
|
|
[[ "$compose_project_name" =~ ^[a-zA-Z0-9_-]+$ ]] || {
|
|
echo "TEST_COMPOSE_PROJECT_NAME contains unsupported characters." >&2
|
|
exit 1
|
|
}
|
|
[[ "$public_edge_network" =~ ^[a-zA-Z0-9_-]+$ ]] || {
|
|
echo "TEST_PUBLIC_EDGE_NETWORK contains unsupported characters." >&2
|
|
exit 1
|
|
}
|
|
[[ "$public_upstream_name" =~ ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ ]] || {
|
|
echo "TEST_PUBLIC_UPSTREAM_NAME must be a lowercase Docker DNS alias." >&2
|
|
exit 1
|
|
}
|
|
[[ -n "$codex_session_id" ]] || {
|
|
echo "TEST_CODEX_SESSION_ID is required for the Build Week feedback page." >&2
|
|
exit 1
|
|
}
|
|
if [[ -n "$google_oauth_client_id" || -n "$google_oauth_client_secret" ]]; then
|
|
[[ -n "$google_oauth_client_id" && -n "$google_oauth_client_secret" ]] || {
|
|
echo "Test Google OAuth client ID and secret must either both be set or both be empty." >&2
|
|
exit 1
|
|
}
|
|
fi
|
|
if [[ -n "$google_oauth_authorized_party_ids" &&
|
|
(-z "$google_oauth_client_id" || -z "$google_oauth_client_secret") ]]; then
|
|
echo "Test Android Google authorized parties require the Google OAuth client." >&2
|
|
exit 1
|
|
fi
|
|
if [[ "$google_oauth_authorized_party_ids" == ,* ||
|
|
"$google_oauth_authorized_party_ids" == *,,* ||
|
|
"$google_oauth_authorized_party_ids" == *, ]]; then
|
|
echo "TEST_GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS contains an empty value." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ -n "$android_app_links_package_name" || -n "$android_app_links_fingerprints" ]]; then
|
|
[[ -n "$android_app_links_package_name" && -n "$android_app_links_fingerprints" ]] || {
|
|
echo "Test Android App Links package and fingerprints must either both be set or both be empty." >&2
|
|
exit 1
|
|
}
|
|
fi
|
|
|
|
firebase_values="$firebase_application_id $firebase_api_key $firebase_project_id $firebase_sender_id"
|
|
firebase_configured=false
|
|
if grep -q '[^[:space:]]' <<<"$firebase_values"; then
|
|
for value in "$firebase_application_id" "$firebase_api_key" \
|
|
"$firebase_project_id" "$firebase_sender_id"; do
|
|
[[ -n "$value" ]] || {
|
|
echo "All four test WNH_FIREBASE_* values must be configured together." >&2
|
|
exit 1
|
|
}
|
|
done
|
|
|
|
firebase_prefix="1:$firebase_sender_id:android:"
|
|
if [[ ! "$firebase_sender_id" =~ ^[0-9]+$ ||
|
|
"$firebase_application_id" != "$firebase_prefix"?* ]]; then
|
|
echo "Test Firebase application ID must belong to the configured numeric sender/project number." >&2
|
|
exit 1
|
|
fi
|
|
firebase_configured=true
|
|
fi
|
|
|
|
vapid_values="$web_push_vapid_public_key $web_push_vapid_private_key $web_push_vapid_subject"
|
|
if grep -q '[^[:space:]]' <<<"$vapid_values"; then
|
|
for value in "$web_push_vapid_public_key" "$web_push_vapid_private_key" \
|
|
"$web_push_vapid_subject"; do
|
|
[[ -n "$value" ]] || {
|
|
echo "All three test WEB_PUSH_VAPID_* values must be configured together." >&2
|
|
exit 1
|
|
}
|
|
done
|
|
|
|
if [[ "$web_push_vapid_subject" != mailto:?* &&
|
|
"$web_push_vapid_subject" != https://?* ]]; then
|
|
echo "Test WEB_PUSH_VAPID_SUBJECT must be a non-empty mailto: or https:// URI." >&2
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
if [[ (-n "$fcm_project_id" || -n "$fcm_service_account_json_base64") &&
|
|
(-z "$fcm_project_id" || -z "$fcm_service_account_json_base64") ]]; then
|
|
echo "Test FCM project ID and Base64 service account must be configured together." >&2
|
|
exit 1
|
|
fi
|
|
|
|
fcm_credential_project_id=
|
|
if [[ -n "$fcm_service_account_json_base64" ]]; then
|
|
for command in base64 jq; do
|
|
command -v "$command" >/dev/null 2>&1 || {
|
|
echo "Required command is unavailable for FCM validation: $command" >&2
|
|
exit 1
|
|
}
|
|
done
|
|
if ! fcm_credential_project_id=$(printf '%s' "$fcm_service_account_json_base64" |
|
|
base64 --decode 2>/dev/null |
|
|
jq -er '
|
|
. as $credential
|
|
| (
|
|
($credential.type == "service_account") and
|
|
($credential.project_id | type == "string" and length > 0) and
|
|
($credential.client_email | type == "string" and length > 0) and
|
|
($credential.private_key | type == "string" and length > 0)
|
|
)
|
|
| if . then $credential.project_id else error("incomplete service account") end
|
|
' 2>/dev/null); then
|
|
echo "Test FCM credential is not a complete service-account JSON document." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ "$fcm_credential_project_id" != "$fcm_project_id" ]]; then
|
|
echo "Test FCM service-account project must match TEST_FCM_PROJECT_ID." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ "$firebase_configured" == true &&
|
|
"$fcm_project_id" != "$firebase_project_id" ]]; then
|
|
echo "Test Firebase Android client and FCM service account must use the same project." >&2
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
if [[ -n "$android_app_links_package_name" &&
|
|
"$android_app_links_package_name" != org.whoneedhelp.mobile.staging ]]; then
|
|
echo "Test Android App Links package must be org.whoneedhelp.mobile.staging." >&2
|
|
exit 1
|
|
fi
|
|
|
|
for pair in "HTTP:$http_port" "MAILPIT:$mailpit_port"; do
|
|
value=${pair#*:}
|
|
if [[ ! "$value" =~ ^[0-9]+$ ]] || ((value < 1 || value > 65535)); then
|
|
echo "${pair%%:*} port must be between 1 and 65535." >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
[[ "$http_port" != "$mailpit_port" ]] || {
|
|
echo "Test HTTP and Mailpit ports must be different." >&2
|
|
exit 1
|
|
}
|
|
|
|
postgres_password=$(openssl rand -hex 32)
|
|
secret_key_base=$(openssl rand -hex 64)
|
|
handover_secret=$(openssl rand -hex 64)
|
|
release_cookie=$(openssl rand -hex 64)
|
|
metrics_token=$(openssl rand -hex 32)
|
|
docker_socket_gid=$(stat -c '%g' /var/run/docker.sock)
|
|
postgres_db=who_need_help_test
|
|
database_url="ecto://postgres:$postgres_password@db/$postgres_db"
|
|
|
|
tmp=$(mktemp "$target_dir/.test-env.XXXXXX")
|
|
trap 'rm -f "$tmp"' EXIT HUP INT TERM
|
|
chmod 600 "$tmp"
|
|
|
|
DOMAIN=$domain \
|
|
GIT_SHA_VALUE=$git_sha \
|
|
COMPOSE_PROJECT_NAME_VALUE=$compose_project_name \
|
|
PUBLIC_EDGE_NETWORK_VALUE=$public_edge_network \
|
|
PUBLIC_UPSTREAM_NAME_VALUE=$public_upstream_name \
|
|
HTTP_BIND_ADDRESS_VALUE=$http_bind_address \
|
|
HTTP_PORT_VALUE=$http_port \
|
|
MAILPIT_BIND_ADDRESS_VALUE=$mailpit_bind_address \
|
|
MAILPIT_PORT_VALUE=$mailpit_port \
|
|
DOCKER_SOCKET_GID_VALUE=$docker_socket_gid \
|
|
POSTGRES_DB_VALUE=$postgres_db \
|
|
POSTGRES_PASSWORD_VALUE=$postgres_password \
|
|
DATABASE_URL_VALUE=$database_url \
|
|
SECRET_KEY_BASE_VALUE=$secret_key_base \
|
|
HANDOVER_SECRET_VALUE=$handover_secret \
|
|
RELEASE_COOKIE_VALUE=$release_cookie \
|
|
METRICS_TOKEN_VALUE=$metrics_token \
|
|
GOOGLE_OAUTH_CLIENT_ID_VALUE=$google_oauth_client_id \
|
|
GOOGLE_OAUTH_CLIENT_SECRET_VALUE=$google_oauth_client_secret \
|
|
GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS_VALUE=$google_oauth_authorized_party_ids \
|
|
WEB_PUSH_VAPID_PUBLIC_KEY_VALUE=$web_push_vapid_public_key \
|
|
WEB_PUSH_VAPID_PRIVATE_KEY_VALUE=$web_push_vapid_private_key \
|
|
WEB_PUSH_VAPID_SUBJECT_VALUE=$web_push_vapid_subject \
|
|
FIREBASE_APPLICATION_ID_VALUE=$firebase_application_id \
|
|
FIREBASE_API_KEY_VALUE=$firebase_api_key \
|
|
FIREBASE_PROJECT_ID_VALUE=$firebase_project_id \
|
|
FIREBASE_SENDER_ID_VALUE=$firebase_sender_id \
|
|
FCM_PROJECT_ID_VALUE=$fcm_project_id \
|
|
FCM_SERVICE_ACCOUNT_JSON_BASE64_VALUE=$fcm_service_account_json_base64 \
|
|
ANDROID_APP_LINKS_PACKAGE_NAME_VALUE=$android_app_links_package_name \
|
|
ANDROID_APP_LINKS_FINGERPRINTS_VALUE=$android_app_links_fingerprints \
|
|
SUPPORT_INBOX_ADDRESS_VALUE=$support_inbox_address \
|
|
CODEX_SESSION_ID_VALUE=$codex_session_id \
|
|
awk '
|
|
BEGIN {
|
|
replacement["DEPLOYMENT_TARGET"] = "compose"
|
|
replacement["DEPLOYMENT_ENV"] = "test"
|
|
replacement["COMPOSE_PROJECT_NAME"] = ENVIRON["COMPOSE_PROJECT_NAME_VALUE"]
|
|
replacement["APP_IMAGE"] = "who-need-help:test-" ENVIRON["GIT_SHA_VALUE"]
|
|
replacement["SOCKET_PROXY_IMAGE"] = "who-need-help:socket-proxy-test-" ENVIRON["GIT_SHA_VALUE"]
|
|
replacement["POSTGIS_IMAGE"] = "who-need-help:postgis-test-" ENVIRON["GIT_SHA_VALUE"]
|
|
replacement["APP_TOPOLOGY"] = "compact"
|
|
replacement["DATABASE_MODE"] = "container"
|
|
replacement["HTTP_BIND_ADDRESS"] = ENVIRON["HTTP_BIND_ADDRESS_VALUE"]
|
|
replacement["HTTP_PORT"] = ENVIRON["HTTP_PORT_VALUE"]
|
|
replacement["PUBLIC_EDGE_ENABLED"] = "true"
|
|
replacement["PUBLIC_EDGE_NETWORK"] = ENVIRON["PUBLIC_EDGE_NETWORK_VALUE"]
|
|
replacement["PUBLIC_UPSTREAM_NAME"] = ENVIRON["PUBLIC_UPSTREAM_NAME_VALUE"]
|
|
replacement["MAILPIT_BIND_ADDRESS"] = ENVIRON["MAILPIT_BIND_ADDRESS_VALUE"]
|
|
replacement["MAILPIT_PORT"] = ENVIRON["MAILPIT_PORT_VALUE"]
|
|
replacement["DOCKER_SOCKET_GID"] = ENVIRON["DOCKER_SOCKET_GID_VALUE"]
|
|
replacement["TRAEFIK_TRUSTED_IPS"] = "127.0.0.1/32"
|
|
replacement["TRAEFIK_PROJECT_CONSTRAINT"] = ENVIRON["COMPOSE_PROJECT_NAME_VALUE"]
|
|
replacement["TRAEFIK_APP_NAME"] = "who-need-help-test"
|
|
replacement["TRAEFIK_DOCKER_NETWORK"] = ENVIRON["COMPOSE_PROJECT_NAME_VALUE"] "_ingress"
|
|
replacement["PHX_HOST"] = ENVIRON["DOMAIN"]
|
|
replacement["PHX_SCHEME"] = "https"
|
|
replacement["PHX_URL_PORT"] = "443"
|
|
replacement["WNH_DEBUG_BASE_URL"] = "https://" ENVIRON["DOMAIN"]
|
|
replacement["WNH_BASE_URL"] = "https://" ENVIRON["DOMAIN"]
|
|
replacement["POSTGRES_DB"] = ENVIRON["POSTGRES_DB_VALUE"]
|
|
replacement["POSTGRES_USER"] = "postgres"
|
|
replacement["POSTGRES_PASSWORD"] = ENVIRON["POSTGRES_PASSWORD_VALUE"]
|
|
replacement["DATABASE_URL"] = ENVIRON["DATABASE_URL_VALUE"]
|
|
replacement["DATABASE_SOCKET_DIR"] = ""
|
|
replacement["SECRET_KEY_BASE"] = ENVIRON["SECRET_KEY_BASE_VALUE"]
|
|
replacement["HANDOVER_SECRET"] = ENVIRON["HANDOVER_SECRET_VALUE"]
|
|
replacement["RELEASE_COOKIE"] = ENVIRON["RELEASE_COOKIE_VALUE"]
|
|
replacement["METRICS_TOKEN"] = ENVIRON["METRICS_TOKEN_VALUE"]
|
|
replacement["EMAIL_DELIVERY_PROVIDER"] = "smtp"
|
|
replacement["SMTP_RELAY"] = "mailpit"
|
|
replacement["SMTP_PORT"] = "1025"
|
|
replacement["SMTP_USERNAME"] = ""
|
|
replacement["SMTP_PASSWORD"] = ""
|
|
replacement["SMTP_AUTH"] = "never"
|
|
replacement["SMTP_TLS"] = "never"
|
|
replacement["SMTP_SSL"] = "false"
|
|
replacement["EMAIL_FROM_NAME"] = "\"Who Need Help Test\""
|
|
replacement["EMAIL_FROM_ADDRESS"] = "test@" ENVIRON["DOMAIN"]
|
|
replacement["SUPPORT_INBOX_ADDRESS"] = ENVIRON["SUPPORT_INBOX_ADDRESS_VALUE"]
|
|
replacement["GOOGLE_OAUTH_CLIENT_ID"] = ENVIRON["GOOGLE_OAUTH_CLIENT_ID_VALUE"]
|
|
replacement["GOOGLE_OAUTH_CLIENT_SECRET"] = ENVIRON["GOOGLE_OAUTH_CLIENT_SECRET_VALUE"]
|
|
replacement["GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS"] = ENVIRON["GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS_VALUE"]
|
|
replacement["WEB_PUSH_VAPID_PUBLIC_KEY"] = ENVIRON["WEB_PUSH_VAPID_PUBLIC_KEY_VALUE"]
|
|
replacement["WEB_PUSH_VAPID_PRIVATE_KEY"] = ENVIRON["WEB_PUSH_VAPID_PRIVATE_KEY_VALUE"]
|
|
replacement["WEB_PUSH_VAPID_SUBJECT"] = ENVIRON["WEB_PUSH_VAPID_SUBJECT_VALUE"]
|
|
replacement["WNH_FIREBASE_APPLICATION_ID"] = ENVIRON["FIREBASE_APPLICATION_ID_VALUE"]
|
|
replacement["WNH_FIREBASE_API_KEY"] = ENVIRON["FIREBASE_API_KEY_VALUE"]
|
|
replacement["WNH_FIREBASE_PROJECT_ID"] = ENVIRON["FIREBASE_PROJECT_ID_VALUE"]
|
|
replacement["WNH_FIREBASE_GCM_SENDER_ID"] = ENVIRON["FIREBASE_SENDER_ID_VALUE"]
|
|
replacement["FCM_PROJECT_ID"] = ENVIRON["FCM_PROJECT_ID_VALUE"]
|
|
replacement["FCM_SERVICE_ACCOUNT_FILE"] = ""
|
|
replacement["FCM_SERVICE_ACCOUNT_JSON_BASE64"] = ENVIRON["FCM_SERVICE_ACCOUNT_JSON_BASE64_VALUE"]
|
|
replacement["ANDROID_APP_LINKS_PACKAGE_NAME"] = ENVIRON["ANDROID_APP_LINKS_PACKAGE_NAME_VALUE"]
|
|
replacement["ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS"] = ENVIRON["ANDROID_APP_LINKS_FINGERPRINTS_VALUE"]
|
|
replacement["WNH_ANDROID_SIGNING_KEY_ALIAS"] = ""
|
|
replacement["WNH_ANDROID_DEVELOPMENT_SIGNING_KEY_ALIAS"] = ""
|
|
replacement["WNH_ANDROID_STAGING_SIGNING_KEY_ALIAS"] = "who-need-help-staging"
|
|
replacement["CODEX_SESSION_ID"] = ENVIRON["CODEX_SESSION_ID_VALUE"]
|
|
|
|
for (key in replacement) {
|
|
gsub(/\$/, "$$", replacement[key])
|
|
}
|
|
}
|
|
{
|
|
separator = index($0, "=")
|
|
key = separator > 1 ? substr($0, 1, separator - 1) : ""
|
|
print (key in replacement) ? key "=" replacement[key] : $0
|
|
}
|
|
' "$ROOT/.env.example" >"$tmp"
|
|
|
|
mv "$tmp" "$target"
|
|
chmod 600 "$target"
|
|
trap - EXIT HUP INT TERM
|
|
|
|
unset postgres_password secret_key_base handover_secret release_cookie metrics_token
|
|
unset google_oauth_client_secret
|
|
unset web_push_vapid_private_key firebase_api_key fcm_service_account_json_base64
|
|
unset fcm_credential_project_id
|
|
unset android_app_links_fingerprints
|
|
|
|
"$ROOT/scripts/compose.sh" "$target" config --quiet
|
|
echo "Generated independent test secrets without printing them."
|
|
echo "Created the single mode-0600 test configuration: $target"
|