mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix - config hardening ## What is the current behavior? CORS is applied at the global level in a permissive mode ## What is the new behavior? Self-hosted envoy config should apply CORS to the `/pg` routes. These should only be called from the studio dashboard (when called via a browser). uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Security & Access** * Added stricter CORS controls for the `/pg/` route. * Requests are limited to the configured public URL and localhost origins. * Standard HTTP methods and headers are supported, with preflight responses cached for one hour. * **Documentation** * Updated self-hosting guidance to describe the `/pg/` route’s CORS policy. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
36 lines
1.3 KiB
Bash
Executable File
36 lines
1.3 KiB
Bash
Executable File
#!/bin/sh
|
|
set -e
|
|
|
|
# Generate SHA1 base64 hash for Envoy basic auth user list
|
|
PASSWORD_HASH=$(printf '%s' "${DASHBOARD_PASSWORD}" | openssl sha1 -binary | openssl base64)
|
|
DASHBOARD_BASIC_AUTH="${DASHBOARD_USERNAME}:{SHA}${PASSWORD_HASH}"
|
|
|
|
echo "Generating Envoy configuration..."
|
|
|
|
# Process the lds.yaml template with environment variables using sed
|
|
# Using | as delimiter since JWT tokens contain /
|
|
sed -e "s|\${ANON_KEY}|${ANON_KEY}|g" \
|
|
-e "s|\${ANON_KEY_ASYMMETRIC}|${ANON_KEY_ASYMMETRIC}|g" \
|
|
-e "s|\${SERVICE_ROLE_KEY}|${SERVICE_ROLE_KEY}|g" \
|
|
-e "s|\${SERVICE_ROLE_KEY_ASYMMETRIC}|${SERVICE_ROLE_KEY_ASYMMETRIC}|g" \
|
|
-e "s|\${SUPABASE_PUBLISHABLE_KEY}|${SUPABASE_PUBLISHABLE_KEY}|g" \
|
|
-e "s|\${SUPABASE_SECRET_KEY}|${SUPABASE_SECRET_KEY}|g" \
|
|
-e "s|\${SUPABASE_PUBLIC_URL}|${SUPABASE_PUBLIC_URL}|g" \
|
|
-e "s|\${DASHBOARD_BASIC_AUTH}|${DASHBOARD_BASIC_AUTH}|g" \
|
|
/etc/envoy/lds.template.yaml > /etc/envoy/lds.yaml
|
|
|
|
if [ -n "$SUPABASE_SECRET_KEY" ] && \
|
|
[ -n "$SUPABASE_PUBLISHABLE_KEY" ] && \
|
|
[ -n "$SERVICE_ROLE_KEY_ASYMMETRIC" ] && \
|
|
[ -n "$ANON_KEY_ASYMMETRIC" ]; then
|
|
echo "Envoy sb_ key translation enabled"
|
|
else
|
|
echo "Envoy running in legacy API key mode (sb_ keys disabled)"
|
|
fi
|
|
|
|
echo "Envoy configuration generated successfully"
|
|
echo "Starting Envoy..."
|
|
|
|
# Start Envoy
|
|
exec envoy -c /etc/envoy/envoy.yaml "$@"
|