fixes for scalar and access

This commit is contained in:
Vitali sharp8n 2026-09-02 20:33:19 +03:00
parent 96c319c2ff
commit 9354f3ab02
3 changed files with 14 additions and 3 deletions

View file

@ -27,7 +27,9 @@ RUN apt-get update \
# boundary and subprocess/Roslyn execute as this user). /tmp stays world-writable
# for the TypeScript executor's esbuild bundle; the workflow code checkout is
# mounted read-only (see compose) and only read, never written.
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin appuser
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin appuser \
&& mkdir -p /data/workflow-tenants \
&& chown -R appuser:appuser /data
USER appuser
EXPOSE 5259

View file

@ -19,6 +19,7 @@ public class AuthMiddleware
new("/health/ready"),
new("/openapi"),
new("/scalar"), // interactive API explorer (Scalar) — no operator key needed
new("/api/scalar"), // Scalar reference exposed under /api/scalar/<svc> — no operator key needed
new("/h"), // webhook receiver (external callers have no operator key)
};

View file

@ -281,8 +281,16 @@ catch (Exception ex)
Log.Logger.Error(ex, "Failed to apply EF Core migrations on startup");
}
app.MapOpenApi();
app.MapScalarApiReference();
// Scalar API reference + OpenAPI document are exposed under a dedicated
// per-service prefix (/api/scalar/workflows/...) so Caddy can route them on the
// public origin without colliding with the webapi Scalar reference. The OpenAPI
// document is served at the SAME prefix (not the default /openapi/v1.json) so
// Scalar's relative spec + asset resolution stays consistent behind the proxy.
app.MapOpenApi("/api/scalar/workflows/openapi/{documentName}.json");
app.MapScalarApiReference("/api/scalar/workflows", options =>
{
options.OpenApiRoutePattern = "/api/scalar/workflows/openapi/{documentName}.json";
});
app.MapControllers();
if (runWorker)