fix: address code review findings from 2026-08-17
- scope no-cache headers to non-static routes (restore immutable asset caching) - reset cached rejected MongoDB promise so retries can succeed - use last X-Forwarded-For entry in Content Editor rate limiter (anti-spoofing) - remove weak Mongo defaults from compose files (fail loudly on missing env) - move staging banner text to common.json content - read APP_PORT from env file in deploy.sh healthcheck - filter network noise from staging smoke console assertions Closes MITHOME-48, MITHOME-49, MITHOME-50, MITHOME-51, MITHOME-52, MITHOME-53, MITHOME-54
This commit is contained in:
@@ -13,7 +13,9 @@ services:
|
||||
- "127.0.0.1:8081:3000" # Belső port — csak nginx-en keresztül elérhető
|
||||
environment:
|
||||
- NODE_ENV=production
|
||||
- MONGODB_URI=${MONGODB_URI:-mongodb://mongodb:27017/mozdit}
|
||||
# No fallback for MONGODB_URI: with root auth enabled on the Mongo container an
|
||||
# unauthenticated default URI would silently break the app — fail loudly instead.
|
||||
- MONGODB_URI=${MONGODB_URI}
|
||||
- MONGODB_DB=${MONGODB_DB:-mozdit}
|
||||
- NEXT_PUBLIC_SITE_URL=${NEXT_PUBLIC_SITE_URL:-https://stage.mozdit.hu}
|
||||
- NEXT_PUBLIC_DEPLOY_ENV=staging
|
||||
@@ -39,7 +41,8 @@ services:
|
||||
- "127.0.0.1:27019:27017" # Belső port, nem ütközik a prod 27018-cal
|
||||
environment:
|
||||
- MONGO_INITDB_ROOT_USERNAME=${MONGO_ROOT_USER:-admin}
|
||||
- MONGO_INITDB_ROOT_PASSWORD=${MONGO_ROOT_PASSWORD:-password123}
|
||||
# No weak default password: a missing value must fail the container loudly.
|
||||
- MONGO_INITDB_ROOT_PASSWORD=${MONGO_ROOT_PASSWORD}
|
||||
- MONGO_INITDB_DATABASE=mozdit
|
||||
volumes:
|
||||
- mongodb_data_staging:/data/db
|
||||
|
||||
Reference in New Issue
Block a user