feat(backend): identity advertises http_port (HTTP_PORT, default 80)

The native app downloads per-venue UI bundles from the plain-HTTP LAN port
(integrity via the sha256 in the manifest it fetched over pinned TLS), so it
needs to know the published port. compose passes HTTP_PORT to the backend.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 18:24:48 +03:00
co-authored by Claude Opus 5.5
parent 43f21dbf6c
commit 41250b7fc7
2 changed files with 5 additions and 0 deletions
+1
View File
@@ -12,6 +12,7 @@ services:
- VERSION=${VERSION:-0.0.0} - VERSION=${VERSION:-0.0.0}
- HOST_IP=${HOST_IP:-} - HOST_IP=${HOST_IP:-}
- TLS_PORT=${TLS_PORT:-8443} # published port of the proxy's TLS entry (advertised to the app) - TLS_PORT=${TLS_PORT:-8443} # published port of the proxy's TLS entry (advertised to the app)
- HTTP_PORT=${HTTP_PORT:-80} # published plain-HTTP LAN port (app downloads UI bundles from it)
- MASTER_USERNAME=${MASTER_USERNAME:-} - MASTER_USERNAME=${MASTER_USERNAME:-}
- MASTER_PASSWORD=${MASTER_PASSWORD:-} - MASTER_PASSWORD=${MASTER_PASSWORD:-}
volumes: volumes:
+4
View File
@@ -1,6 +1,7 @@
import asyncio import asyncio
import ipaddress import ipaddress
import json import json
import os
import socket import socket
import time import time
from fastapi import APIRouter, Depends, HTTPException, Query from fastapi import APIRouter, Depends, HTTPException, Query
@@ -53,6 +54,9 @@ def identity(db: Session = Depends(get_db)):
"api_version": API_VERSION, "api_version": API_VERSION,
# Encrypted LAN endpoint for the native app: https://<ip>:<port>, pin spki_sha256 # Encrypted LAN endpoint for the native app: https://<ip>:<port>, pin spki_sha256
"tls": tls_info(), "tls": tls_info(),
# Plain-HTTP LAN port: the app downloads UI bundles from it (integrity via
# the sha256 in the manifest it fetched over TLS)
"http_port": int(os.environ.get("HTTP_PORT", "80")),
} }