Skip to content

Commit e3ab63e

Browse files
committed
fix(reverb): align ports, host validation, and dev instance tooling
1 parent 57acc7f commit e3ab63e

9 files changed

Lines changed: 27 additions & 23 deletions

File tree

‎.github/workflows/coolify-next-build.yml‎

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,8 @@ on:
66
paths-ignore:
77
- .github/workflows/coolify-helper.yml
88
- .github/workflows/coolify-helper-next.yml
9-
- .github/workflows/coolify-realtime.yml
10-
- .github/workflows/coolify-realtime-next.yml
119
- .github/workflows/pr-quality.yaml
1210
- docker/coolify-helper/Dockerfile
13-
- docker/coolify-realtime/Dockerfile
1411
- docker/testing-host/Dockerfile
1512
- templates/**
1613
- CHANGELOG.md

‎app/Http/Middleware/TrustHosts.php‎

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,16 +14,13 @@ class TrustHosts extends Middleware
1414
* Handle the incoming request.
1515
*
1616
* Skip host validation for certain routes:
17-
* - Terminal auth routes (called by realtime container)
1817
* - API routes (use token-based authentication, not host validation)
1918
* - Webhook endpoints (use cryptographic signature validation)
2019
*/
2120
public function handle(Request $request, $next)
2221
{
2322
// Skip host validation for these routes
2423
if ($request->is(
25-
'terminal/auth',
26-
'terminal/auth/ips',
2724
'api/*',
2825
'webhooks/*'
2926
)) {

‎docker-compose.prod.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ services:
2525
- /data/coolify/source/.env
2626
ports:
2727
- "${APP_PORT:-8000}:8080"
28-
- "${SOKETI_PORT:-6001}:6001"
28+
- "${REVERB_PORT:-${SOKETI_PORT:-6001}}:6001"
2929
- "${TERMINAL_PORT:-6002}:6002"
3030
expose:
3131
- "${APP_PORT:-8000}"

‎docker-compose.windows.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ services:
5151
- IS_WINDOWS_DOCKER_DESKTOP=true
5252
ports:
5353
- "${APP_PORT:-8000}:8080"
54-
- "${SOKETI_PORT:-6001}:6001"
54+
- "${REVERB_PORT:-${SOKETI_PORT:-6001}}:6001"
5555
- "${TERMINAL_PORT:-6002}:6002"
5656
expose:
5757
- "${APP_PORT:-8000}"

‎other/nightly/docker-compose.prod.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ services:
2525
- /data/coolify/source/.env
2626
ports:
2727
- "${APP_PORT:-8000}:8080"
28-
- "${SOKETI_PORT:-6001}:6001"
28+
- "${REVERB_PORT:-${SOKETI_PORT:-6001}}:6001"
2929
- "${TERMINAL_PORT:-6002}:6002"
3030
expose:
3131
- "${APP_PORT:-8000}"

‎other/nightly/docker-compose.windows.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ services:
5050
- IS_WINDOWS_DOCKER_DESKTOP=true
5151
ports:
5252
- "${APP_PORT:-8000}:8080"
53-
- "${SOKETI_PORT:-6001}:6001"
53+
- "${REVERB_PORT:-${SOKETI_PORT:-6001}}:6001"
5454
- "${TERMINAL_PORT:-6002}:6002"
5555
expose:
5656
- "${APP_PORT:-8000}"

‎scripts/dev-instances‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -265,18 +265,19 @@ cmd_urls() {
265265
parse_args "$@"
266266
names=("${NAMES[@]}")
267267
fi
268-
printf '%-6s %-28s %-8s %-8s %-12s\n' "NAME" "URL" "DB" "REDIS" "SOKETI"
268+
printf '%-6s %-28s %-8s %-8s %-12s %-12s\n' "NAME" "URL" "DB" "REDIS" "REVERB" "TERMINAL"
269269
local name envf
270270
for name in "${names[@]}"; do
271271
name="$(normalize_name "$name")"
272272
ensure_env "$name" >/dev/null
273273
envf="$(env_file "$name")"
274-
printf '%-6s %-28s %-8s %-8s %-12s\n' \
274+
printf '%-6s %-28s %-8s %-8s %-12s %-12s\n' \
275275
"$name" \
276276
"$(grep -E '^APP_URL=' "$envf" | cut -d= -f2-)" \
277277
"$(grep -E '^FORWARD_DB_PORT=' "$envf" | cut -d= -f2-)" \
278278
"$(grep -E '^FORWARD_REDIS_PORT=' "$envf" | cut -d= -f2-)" \
279-
"$(grep -E '^FORWARD_PUSHER_PORT=' "$envf" | cut -d= -f2-)"
279+
"$(grep -E '^FORWARD_PUSHER_PORT=' "$envf" | cut -d= -f2-)" \
280+
"$(grep -E '^FORWARD_TERMINAL_PORT=' "$envf" | cut -d= -f2-)"
280281
done
281282
}
282283

‎tests/Feature/ReverbAndTerminalPackagingTest.php‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -129,7 +129,7 @@
129129

130130
it('does not use the browser websocket port as the Docker host port', function (string $composeFile) {
131131
expect(file_get_contents(base_path($composeFile)))
132-
->toContain('"${SOKETI_PORT:-6001}:6001"')
132+
->toContain('"${REVERB_PORT:-${SOKETI_PORT:-6001}}:6001"')
133133
->not->toContain('"${PUSHER_PORT:-6001}:6001"');
134134
})->with([
135135
'production compose' => ['docker-compose.prod.yml'],
@@ -166,8 +166,15 @@
166166
->and(is_dir(base_path('docker/coolify-realtime')))->toBeFalse()
167167
->and(file_exists(base_path('.github/workflows/coolify-realtime.yml')))->toBeFalse()
168168
->and(file_exists(base_path('.github/workflows/coolify-realtime-next.yml')))->toBeFalse()
169+
->and(file_get_contents(base_path('.github/workflows/coolify-next-build.yml')))->not->toContain('coolify-realtime')
169170
->and($productionInstallScript)->not->toContain('LATEST_REALTIME_VERSION')
170171
->not->toContain('| Realtime')
171172
->and($nightlyInstallScript)->not->toContain('LATEST_REALTIME_VERSION')
172173
->not->toContain('| Realtime');
173174
});
175+
176+
it('uses current Reverb and terminal names in development tooling', function () {
177+
expect(file_get_contents(base_path('scripts/dev-instances')))
178+
->toContain('"REVERB" "TERMINAL"')
179+
->not->toContain('"SOKETI"');
180+
});

‎tests/Feature/Security/TrustHostsMiddlewareTest.php‎

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -229,24 +229,26 @@
229229
expect($hosts2)->not->toBeEmpty();
230230
});
231231

232-
it('skips host validation for terminal auth routes', function () {
233-
// These routes should be accessible with any Host header (for internal container communication)
232+
it('allows terminal auth requests from the local terminal server', function () {
234233
$response = $this->postJson('/terminal/auth', [], [
235-
'Host' => 'coolify:8080', // Internal Docker host
234+
'Host' => '127.0.0.1:8080',
236235
]);
237236

238-
// Should not get 400 Bad Host (might get 401 Unauthorized instead)
239237
expect($response->status())->not->toBe(400);
240238
});
241239

242-
it('skips host validation for terminal auth ips route', function () {
243-
// These routes should be accessible with any Host header (for internal container communication)
240+
it('enforces host validation for terminal auth routes', function () {
241+
InstanceSettings::updateOrCreate(
242+
['id' => 0],
243+
['fqdn' => 'https://coolify.example.com']
244+
);
245+
Cache::forget('instance_settings_fqdn_host');
246+
244247
$response = $this->postJson('/terminal/auth/ips', [], [
245-
'Host' => 'soketi:6002', // Another internal Docker host
248+
'Host' => 'evil.com',
246249
]);
247250

248-
// Should not get 400 Bad Host (might get 401 Unauthorized instead)
249-
expect($response->status())->not->toBe(400);
251+
expect($response->status())->toBe(400);
250252
});
251253

252254
it('still enforces host validation for non-terminal routes', function () {

0 commit comments

Comments
 (0)