Files
workflow-app/Dockerfile
Kühn 6be1791c62 DEV1.0: Initial commit - Workflow Portal with security fixes
- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration
- Frontend: React 18 + Vite + TailwindCSS/DaisyUI
- Security fixes applied (2026-07 + 2026-08):
  - LDAP injection prevention, CSRF protection, HttpOnly cookies
  - Session hashing (SHA-256), account lockout, rate limiting
  - Input validation (zod), file upload security, CSP/HSTS headers
  - V3: express-rate-limit updated (ip-address SSRF fix)
  - V4: postcss updated (nanoid DoS fix)
  - V5: Rate-limit on /health endpoint
  - V6: Session rotation on login (session fixation prevention)
  - V9: Task values array limit (DoS prevention)
  - V10: Frontend XSS audit completed
- Docker: Multi-stage build, non-root user, PostgreSQL + backup service
2026-08-24 09:45:28 +02:00

30 lines
908 B
Docker

FROM node:20-alpine AS frontend-build
WORKDIR /app/frontend
COPY frontend/package*.json ./
RUN npm install
COPY frontend/ ./
RUN npm run build
FROM node:20-alpine
RUN apk add --no-cache python3 make g++ openssl wget su-exec
# Create non-root user (Punkt 6: Non-Root Container)
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
WORKDIR /app
COPY backend/package*.json ./
RUN npm install
COPY backend/ ./
COPY --from=frontend-build /app/frontend/dist ./frontend/dist
# Create data directory
RUN mkdir -p /app/data/uploads
EXPOSE 5000
# Health check (Punkt 7: Docker Healthcheck)
HEALTHCHECK --interval=30s --timeout=5s --retries=3 --start-period=10s \
CMD wget -qO- http://localhost:5000/health || exit 1
# Entrypoint: fix permissions on mounted volumes, then run as non-root user
ENTRYPOINT ["sh", "-c", "chown -R appuser:appgroup /app/data 2>/dev/null; exec su-exec appuser node server.js"]