feat(skudak-cloud): repair LibreSign, brand its mail, add Redis
LibreSign had been silently broken since it was first deployed in January. Every step of the old before-starting hook ended in `|| echo`, so six months of failures logged nothing. LibreSign repair - Root cause was a stale config_path: a valid OpenSSL root CA existed at generation 1, a failed CFSSL attempt left an empty generation 2, and config_path was left pointing at the empty one. Regenerated as "Skudak LLP" (was the pre-rename "Skudak Rennsport LLP"). - Deleted the hook. Java/PDFtk/jSignPdf live under data/appdata_*, a persisted volume, so they only ever needed installing once. Install and verification are now explicit tasks that actually fail. - PHP_MEMORY_LIMIT 1024M -- the 512M image default fails opaquely mid-signature. LC_ALL/LANG so the JVM is not ANSI_X3.4-1968. - signature_render_mode=GRAPHIC_ONLY. Any other mode halves the stamp width and overlays a name/date block that collides with the drawn mark and duplicates what our documents already typeset. The value must be exactly GRAPHIC_ONLY; a bare "GRAPHIC" is accepted by occ, matches no radio in the UI, and silently reverts to default. - write_qrcode_on_footer=false, written with --type=boolean because FooterHandler reads it via getValueBool and the typed appconfig API does not coerce a string "0". The validation URL text is kept. - identification_documents=0 -- the default gates signing behind an ID upload plus admin approval, so signers saw no way to sign. - shareapi_restrict_user_enumeration_full_match=no, so an email owned by an existing account can be added as a signer. Root cause is in core (MailPlugin.php:163), not LibreSign. Do NOT set full_match_email=no -- that disables email signer search entirely. Mail branding (skudakmail app) - Two supported extension points, no core patch and no LibreSign fork: mail_template_class for layout, subjects, button labels and the footer LibreSign never adds; and a BeforeMessageSent listener to embed the wordmark as a cid: part so it survives remote-image blocking. - A third listener adds scoped CSS fixing the signing page being clipped on iOS Safari (100vh -> 100dvh). Patched upstream too. - skudakmail-verify.php.j2 asserts all of the above through the real useTemplate() path and fails the play on drift. Every assertion was proven to fail when deliberately regressed. Redis - memcache.locking was unset, so Nextcloud used DBLockingProvider and every file lock became a MariaDB write -- the contention behind the intermittent multi-second stalls. Verified after: db locks static, redis keys growing. - requirepass lives in a mounted 0640 conf, not --requirepass, which would leak it into podman inspect, the systemd unit and ps. The file is chowned to uid 999 because redis-server does not run as root and the :ro mount stops the image fixing it itself. - No maxmemory: cache is evictable, locks are NOT, and evicting a held lock permits concurrent writers to one file. No persistence either -- a restored RDB could reinstate locks whose owner is long dead. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -110,6 +110,25 @@ bookstack_server_name_new: wiki.skudak.com
|
||||
cloud_skudak_server_name_new: cloud.skudak.com
|
||||
gitea_skudak_server_name: git.skudak.com
|
||||
|
||||
# LibreSign root certificate authority identity for skudak-cloud. This is the
|
||||
# issuer name that appears on every signed document, so it must match the
|
||||
# entity's legal name -- it was previously generated as "Skudak Rennsport LLP",
|
||||
# the pre-rename name. Changing these values does NOT re-issue the CA on its
|
||||
# own; see the guarded generate task in containers/skudak/cloud.yml.
|
||||
# Skudak brand palette, mirroring ~/src/skudak/skudak-site/src/styles/variables.css.
|
||||
# --color-gray-900 for the mail header band and UI chrome; the white signature
|
||||
# logo is legible on it. --color-accent is spent only on the CTA button, and
|
||||
# lives in the skudakmail app rather than here since theming has no second
|
||||
# colour slot.
|
||||
theming_skudak_primary: "#0A0A0A"
|
||||
|
||||
libresign_skudak_cert_cn: Skudak LLP
|
||||
libresign_skudak_cert_o: Skudak LLP
|
||||
libresign_skudak_cert_c: US
|
||||
libresign_skudak_cert_st: New Hampshire
|
||||
libresign_skudak_cert_l: Newbury
|
||||
|
||||
|
||||
# Legacy nginx/ModSecurity configuration removed - Caddy provides built-in security
|
||||
|
||||
# Web server configuration (Caddy is the default)
|
||||
|
||||
Reference in New Issue
Block a user