view docker/libervia-web-dev/Dockerfile @ 4212:5f2d496c633f

core: get rid of `pickle`: Use of `pickle` to serialise data was a technical legacy that was causing trouble to store in database, to update (if a class was serialised, a change could break update), and to security (pickle can lead to code execution). This patch remove all use of Pickle in favour in JSON, notably: - for caching data, a Pydantic model is now used instead - for SQLAlchemy model, the LegacyPickle is replaced by JSON serialisation - in XEP-0373 a class `PublicKeyMetadata` was serialised. New method `from_dict` and `to_dict` method have been implemented to do serialisation. - new methods to (de)serialise data can now be specified with Identity data types. It is notably used to (de)serialise `path` of avatars. A migration script has been created to convert data (for upgrade or downgrade), with special care for XEP-0373 case. Depending of size of database, this migration script can be long to run. rel 443
author Goffi <goffi@goffi.org>
date Fri, 23 Feb 2024 13:31:04 +0100
parents 43cc8c27adc7
children
line wrap: on
line source

ARG REVISION
FROM libervia/backend:${REVISION:-dev}

LABEL maintainer="Goffi <tmp_dockerfiles@goffi.org>"

ARG REVISION
ARG DEBIAN_FRONTEND=noninteractive

USER root

RUN apt-get install -y --no-install-recommends yarnpkg
WORKDIR /home/libervia
USER libervia
RUN cd /src && hg clone https://repos.goffi.org/libervia-web -u "${REVISION:-@}" && \
    ~/libervia_env/bin/pip install -e libervia-web

RUN ./entrypoint.sh \
    # we build here to avoid re-downloading node modules or other browser
    # dependencies on each run
    libervia-web fg -- --build-only && \
    libervia-backend stop

EXPOSE 8080 8443

ENTRYPOINT ["libervia-web"]
CMD ["fg"]