Sign inSign up

richardjennings/prose

By richardjennings

•Updated over 9 years ago

An all in one Dockerfile for https://github.com/prose/prose

Image
0

230

richardjennings/prose repository overview

⁠Dockerfile for github.com/prose/prose⁠

⁠Why

I found the Prose⁠ project interesting and wanted to run it locally. I suspected that I would be able to use Nginx as a proxy rather than the mechanism suggested in the docs⁠ and so had some fun writing this Dockerfile.

⁠About

This Dockerfile provides a "hybrid" Prose⁠ install suitable to run locally. There is no support for SSL currently.

Prose uses Github's OAuth2 API. Requests to http://github.com/login/oauth/access_token⁠ to exchange an authorization code for an access token cannot be made directly by a browser via XHR due to same-origin policy⁠ constraints. The Prose project recommends using prose/gatekeeper⁠ to proxy browser requests for an access token, avoiding same origin issues.

This Dockerfile uses Nginx to serve Prose assets and also provide a proxy to the Github /login/oauth/access_token endpoint.

The proxy functionality can be found in nginx.conf⁠ and looks like (at the time of writing):

        location /authenticate/ {
            rewrite ^/authenticate/(.*)$ /login/oauth/access_token break;
            proxy_method POST;
            proxy_set_body "{\"client_id\":\"%GITHUB_CLIENT_ID%\",\"client_secret\":\"%GITHUB_CLIENT_SECRET%\", \"code\":\"$1\"}";
            proxy_set_header Content-Type "application/json";
            proxy_set_header Accept 'application/json';
            proxy_set_header Accept-Encoding "";
            proxy_set_header HOST "github.com";
            sub_filter_types "*";
            sub_filter '"access_token"' '"token"';
            sub_filter_once on;
            proxy_pass https://github.com/;
        }

One objective was to make the Nginx proxying compatible with Prose without any code changes needed. To do this:

  • A POST request to Github is created when a GET request to /authenticate/mycode is made.
  • A rewrite rule pulls the code out of the url. This code is then added to a crafted JSON POST body.
  • The Nginx http sub module⁠ is used to change "access_token" to "token" in the response body.

⁠Running

To run the build image, 2 environment variables need to be specified. These are:

  • GITHUB_CLIENT_ID - the client id of your Github application
  • GITHUB_CLIENT_SECRET - the client secret of your Github application

An example running locally on port 8080:

$ docker run -d -p 8080:80 --env "GITHUB_CLIENT_ID=YOUR_ID" --env "GITHUB_CLIENT_SECRET=YOUR_SECRET" --name prose richardjennings/prose 

The Dockerfile uses an entrypoint.sh script which uses sed to replace tokens in code & configuration files with the values provided when the container is run, allowing the runtime specification of Github application details.

Tag summary

Content type

Image

Digest

Size

107 MB

Last updated

over 9 years ago

docker pull richardjennings/prose