From 9354f3ab0250b677b0d660e005604bd2836874b9 Mon Sep 17 00:00:00 2001 From: Vitali sharp8n Date: Wed, 2 Sep 2026 20:33:19 +0300 Subject: [PATCH] fixes for scalar and access --- Dockerfile | 4 +++- Middleware/AuthMiddleware.cs | 1 + Program.cs | 12 ++++++++++-- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 02a5596..ec7f0b1 100644 --- a/Dockerfile +++ b/Dockerfile @@ -27,7 +27,9 @@ RUN apt-get update \ # boundary and subprocess/Roslyn execute as this user). /tmp stays world-writable # for the TypeScript executor's esbuild bundle; the workflow code checkout is # mounted read-only (see compose) and only read, never written. -RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin appuser +RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin appuser \ + && mkdir -p /data/workflow-tenants \ + && chown -R appuser:appuser /data USER appuser EXPOSE 5259 diff --git a/Middleware/AuthMiddleware.cs b/Middleware/AuthMiddleware.cs index 819c96b..bd7e716 100644 --- a/Middleware/AuthMiddleware.cs +++ b/Middleware/AuthMiddleware.cs @@ -19,6 +19,7 @@ public class AuthMiddleware new("/health/ready"), new("/openapi"), new("/scalar"), // interactive API explorer (Scalar) — no operator key needed + new("/api/scalar"), // Scalar reference exposed under /api/scalar/ — no operator key needed new("/h"), // webhook receiver (external callers have no operator key) }; diff --git a/Program.cs b/Program.cs index a8c3f15..d830055 100644 --- a/Program.cs +++ b/Program.cs @@ -281,8 +281,16 @@ catch (Exception ex) Log.Logger.Error(ex, "Failed to apply EF Core migrations on startup"); } -app.MapOpenApi(); -app.MapScalarApiReference(); +// Scalar API reference + OpenAPI document are exposed under a dedicated +// per-service prefix (/api/scalar/workflows/...) so Caddy can route them on the +// public origin without colliding with the webapi Scalar reference. The OpenAPI +// document is served at the SAME prefix (not the default /openapi/v1.json) so +// Scalar's relative spec + asset resolution stays consistent behind the proxy. +app.MapOpenApi("/api/scalar/workflows/openapi/{documentName}.json"); +app.MapScalarApiReference("/api/scalar/workflows", options => +{ + options.OpenApiRoutePattern = "/api/scalar/workflows/openapi/{documentName}.json"; +}); app.MapControllers(); if (runWorker)