mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-11-09 22:56:29 +00:00
Enhance Shopware role: fix init script permissions, CSP for data: fonts, and unify shell usage
- Added 'font-src data:' to CSP whitelist to allow inline fonts in Admin UI - Refactored init.sh to run as root only for volume permission setup, then drop privileges to www-data - Unified all bash invocations to sh for POSIX compliance - Added missing 'bundles' named volume and mount to Docker Compose - Set init container to run as root (0:0) for permission setup - Added admin user rename step via Ansible task See discussion: https://chatgpt.com/share/69087361-859c-800f-862c-7413350cca3e
This commit is contained in:
@@ -1,4 +1,22 @@
|
||||
# Ensures that the admin user exists and always has the desired password
|
||||
- name: "Rename default Shopware admin user to {{ users.administrator.username }}"
|
||||
shell: |
|
||||
docker exec -i --user {{ SHOPWARE_USER }} {{ SHOPWARE_WEB_CONTAINER }} sh -lc '
|
||||
set -e
|
||||
cd {{ SHOPWARE_ROOT }}
|
||||
old_user="admin"
|
||||
new_user="{{ users.administrator.username }}"
|
||||
if php bin/console user:list | grep -q "^$old_user "; then
|
||||
echo "[INFO] Renaming Shopware user: $old_user -> $new_user"
|
||||
php bin/console user:update "$old_user" --username="$new_user" || true
|
||||
else
|
||||
echo "[INFO] No user named $old_user found (already renamed or custom setup)"
|
||||
fi
|
||||
'
|
||||
args:
|
||||
chdir: "{{ docker_compose.directories.instance }}"
|
||||
changed_when: false
|
||||
no_log: "{{ MASK_CREDENTIALS_IN_LOGS | bool }}"
|
||||
|
||||
- name: "Ensure Shopware admin exists and has the desired password"
|
||||
shell: |
|
||||
docker exec -i --user {{ SHOPWARE_USER }} {{ SHOPWARE_WEB_CONTAINER }} sh -lc '
|
||||
@@ -17,3 +35,4 @@
|
||||
'
|
||||
args:
|
||||
chdir: "{{ docker_compose.directories.instance }}"
|
||||
no_log: "{{ MASK_CREDENTIALS_IN_LOGS | bool }}"
|
||||
Reference in New Issue
Block a user