diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-09 18:22:42 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-09 18:22:42 +0200 |
| commit | fbc2c5d86aed931be38c5fccfff75190eb4d16d1 (patch) | |
| tree | c036e7bb6539ad155aacf87ce61fed9ac2401aca /packaging/build | |
| parent | f2517faca8d35772fb03272ee7f8056421ce2198 (diff) | |
| download | meshbay-fbc2c5d86aed931be38c5fccfff75190eb4d16d1.tar.gz | |
fix(packaging): ship QE/default.env as is, the one TMDB token source
Both builds copy QE/default.env beside the node and stop without it.
No token parsing, no other source, no MESHBAY_ALLOW_NO_TMDB.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packaging/build')
| -rwxr-xr-x | packaging/build/build-node.sh | 57 |
1 files changed, 10 insertions, 47 deletions
diff --git a/packaging/build/build-node.sh b/packaging/build/build-node.sh index fde67a5..b9d542c 100755 --- a/packaging/build/build-node.sh +++ b/packaging/build/build-node.sh @@ -45,55 +45,18 @@ ln -sf /opt/meshbay-common/venv/bin/meshbay-node "$ROOT/usr/bin/meshbay-node" # --- Node-specific assets ------------------------------------------------- mkdir -p "$ROOT/opt/meshbay-node/share" -# Default env with the shared TMDB token, read at build time. The daemon reads -# it in place, beneath <config>/node.env, so it must be readable by whoever runs -# the node -- 0600 root made it unreadable to every per-user node. It is the -# same token in every copy of the package, so 0644 hides nothing. -# -# tmdb.py sends `Authorization: Bearer`, so this is the v4 *read access token* -# (a JWT, "eyJ..."), not the 32-char v3 API key that sits beside it in the same -# note file. Sources, in order: an explicit variable, an explicit file, the -# KEY=VALUE form, then QE/tmdb.txt -- which is free-form prose, so the token is -# matched by shape rather than by a label. -extract_tmdb_token() { - local file="$1" tok="" - [ -f "$file" ] || return 0 - tok=$(sed -n 's/^[[:space:]]*MESHBAY_TMDB_DEFAULT_TOKEN[[:space:]]*=[[:space:]]*//p' \ - "$file" | head -1) - [ -n "$tok" ] || tok=$(grep -oE '^eyJ[A-Za-z0-9._-]{40,}$' "$file" | head -1 || true) - printf '%s' "$tok" | tr -d '"'"'"'\r' -} - -TMDB_TOKEN="${MESHBAY_TMDB_TOKEN:-}" -if [ -z "$TMDB_TOKEN" ] && [ -n "${MESHBAY_TMDB_TOKEN_FILE:-}" ]; then - TMDB_TOKEN=$(extract_tmdb_token "$MESHBAY_TMDB_TOKEN_FILE") -fi -[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/node.env") -[ -n "$TMDB_TOKEN" ] || TMDB_TOKEN=$(extract_tmdb_token "$REPO/QE/tmdb.txt") - -if [ -n "$TMDB_TOKEN" ]; then - cat > "$ROOT/opt/meshbay-node/share/default.env" <<EOF -# Default environment for meshbay-node. -# Read by the daemon beneath <config>/node.env; set a value there to override it. - -# TMDB API token for the Videos app (read-only, shared across installations) -MESHBAY_TMDB_DEFAULT_TOKEN=$TMDB_TOKEN -EOF - chmod 644 "$ROOT/opt/meshbay-node/share/default.env" - echo " TMDB token baked into default.env (${#TMDB_TOKEN} chars)" -elif [ "${MESHBAY_ALLOW_NO_TMDB:-0}" = "1" ]; then - echo " !! no TMDB token; default.env left empty (MESHBAY_ALLOW_NO_TMDB=1)" >&2 - : > "$ROOT/opt/meshbay-node/share/default.env" -else - # Failing here is deliberate: an empty default.env is invisible until a user - # opens the Videos app and finds no metadata, which is exactly how this - # shipped empty on two platforms at once. - echo "!! TMDB token not found. Looked at:" >&2 - echo " \$MESHBAY_TMDB_TOKEN, \$MESHBAY_TMDB_TOKEN_FILE," >&2 - echo " $REPO/QE/node.env, $REPO/QE/tmdb.txt" >&2 - echo " Set MESHBAY_ALLOW_NO_TMDB=1 to build without it." >&2 +# default.env: the shared TMDB token, copied as is from QE/default.env (never +# versioned), one line: MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... The daemon reads it +# beneath <config>/node.env and the operator's own token, so it is only the +# fallback. 0644: a per-user node must read it, and it is the same token in +# every copy of the package. No token, no build: an empty one goes unnoticed. +DEFAULT_ENV="$REPO/QE/default.env" +if [ "$(head -c 30 "$DEFAULT_ENV" 2>/dev/null)" != "MESHBAY_TMDB_DEFAULT_TOKEN=eyJ" ]; then + echo "!! $DEFAULT_ENV missing, or not starting with MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... (no BOM)" >&2 exit 1 fi +install -m 644 "$DEFAULT_ENV" "$ROOT/opt/meshbay-node/share/default.env" +echo " default.env copied from QE/" # --- Systemd units -------------------------------------------------------- mkdir -p "$ROOT/usr/lib/systemd/system" |