Mercurial > libervia-backend
annotate docker/prosody-e2e/Dockerfile @ 4212:5f2d496c633f
core: get rid of `pickle`:
Use of `pickle` to serialise data was a technical legacy that was causing trouble to store
in database, to update (if a class was serialised, a change could break update), and to
security (pickle can lead to code execution).
This patch remove all use of Pickle in favour in JSON, notably:
- for caching data, a Pydantic model is now used instead
- for SQLAlchemy model, the LegacyPickle is replaced by JSON serialisation
- in XEP-0373 a class `PublicKeyMetadata` was serialised. New method `from_dict` and
`to_dict` method have been implemented to do serialisation.
- new methods to (de)serialise data can now be specified with Identity data types. It is
notably used to (de)serialise `path` of avatars.
A migration script has been created to convert data (for upgrade or downgrade), with
special care for XEP-0373 case. Depending of size of database, this migration script can
be long to run.
rel 443
author | Goffi <goffi@goffi.org> |
---|---|
date | Fri, 23 Feb 2024 13:31:04 +0100 |
parents | a6811543c7ff |
children | 31c84a32c897 |
rev | line source |
---|---|
3381 | 1 FROM prosody/prosody |
2 | |
3 LABEL maintainer="Goffi <tmp_dockerfiles@goffi.org>" | |
4 | |
5 ARG DEBIAN_FRONTEND=noninteractive | |
6 | |
3497
73e04040d577
docker: update following name changes:
Goffi <goffi@goffi.org>
parents:
3381
diff
changeset
|
7 # we synchronize tls-cert group with the one in libervia-web/libervia-backend |
3381 | 8 RUN addgroup tls-cert --gid 9999 && adduser prosody tls-cert && \ |
9 # we want third party modules | |
10 apt-get update && apt-get install -y --no-install-recommends mercurial && \ | |
11 mkdir -p /usr/local/share/prosody && \ | |
12 hg clone https://hg.prosody.im/prosody-modules /usr/local/share/prosody/modules && \ | |
13 chown -R prosody:prosody /usr/local/share/prosody | |
14 | |
15 COPY --chown=root:prosody prosody.cfg.lua /etc/prosody/prosody.cfg.lua | |
3497
73e04040d577
docker: update following name changes:
Goffi <goffi@goffi.org>
parents:
3381
diff
changeset
|
16 COPY --chown=root:tls-cert certificates/server1.test/cert.pem /usr/share/libervia/certificates/server1.test.pem |
73e04040d577
docker: update following name changes:
Goffi <goffi@goffi.org>
parents:
3381
diff
changeset
|
17 COPY --chown=root:tls-cert certificates/server1.test/key.pem /usr/share/libervia/certificates/server1.test-key.pem |
3381 | 18 |