Commit Graph
5 Commits
Author SHA1 Message Date
bonaminandClaude Opus 5.5 034106918d fix(install): detect HOST_IP from physical NICs only, never a VPN tunnel
`ip route get 1.1.1.1` returns the tunnel address on servers running a
full-tunnel WireGuard/Tailscale/ZeroTier client, so phones got a QR code and
URL pointing at an address they can't reach. Detection now uses the
main-table default route's interface if it is real hardware
(/sys/class/net/<if>/device), else the first physical NIC with an IPv4,
else `hostname -I` as a last resort (the installer shows it for
confirmation). .env.example says HOST_IP must be the physical LAN address.

Tested with a stubbed `ip` + fake sysfs in Debian: wg-quick full tunnel,
tunnel owning the default route, no default route and WiFi-only all pick
the physical address; full install.sh scenarios unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 15:46:51 +03:00
bonaminandClaude Opus 5.5 9fcb4df30e feat(proxy): plain-HTTP LAN entry for waiter (:80) and manager (:8081), no certs required
Phones can now open the waiter app at http://<LAN IP> with no domain, DNS
record or certificate (works around DNS-rebinding failures, KI-001). The
manager gets http://<LAN IP>:8081, with http://<LAN IP>/manager redirecting
there. waiter.*/manager.* hostnames on :80 still redirect to https, so
legacy domain sites behave as before.

- Both plain-HTTP servers are LAN-only (allow RFC1918/loopback/ULA/link-local,
  deny all -> 403), so a router port-forward can't expose an unencrypted POS
- nginx-proxy/nginx.conf and the install.sh heredoc are now byte-identical
  (one canonical config, routing map in its header)
- install.sh generates a 10-year self-signed cert when certs/ is empty (nginx
  won't start its TLS listeners without one), detects HOST_IP via
  'ip route get', prompts for it on fresh installs and backfills it into an
  existing .env, always starts the stack, prints the LAN URLs
- docker-compose publishes 8081; .env.example documents HOST_IP
- pack README: ports/request path updated, CS-5 byte-identical check

Verified: nginx -t; install.sh in Debian (fresh / upgrade without HOST_IP /
re-run - no duplicate HOST_IP, cert SAN includes HOST_IP, key 600); full
stack from freshly built images: every entry point returns the expected
200/301/302, and removing the gateway's range from the allow list yields 403
on :80 and :8081.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 11:50:29 +03:00
bonaminandClaude Opus 5.5 0f9946e6ca fix(proxy): forward WebSocket upgrades and disable buffering in proxy configs
The nginx config written by install.sh proxied waiter.*, manager.* and the
IP default_server without proxy_http_version 1.1 or Upgrade/Connection
headers, so /api/ws/connect never upgraded and live events (new orders,
KDS status, chat, phone calls) never reached waiters or the manager. The
repo's nginx-proxy/nginx.conf had the same gap on the manager block.

Both configs now use a $connection_upgrade map, 1h read/send timeouts and
proxy_buffering off (SSE) on every proxied location. Verified with nginx -t
and a header-echo upstream: old config strips Upgrade, new one forwards it.

Existing sites: copy the new install.sh, re-run it, restart the proxy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 08:28:27 +03:00
bonaminandClaude Sonnet 4.6 0d21b7f20b fix: deployment readiness — correct registry/cloud URLs, fix install.sh
- .env.example: set REGISTRY=registry.bonamin.gr, CLOUD_URL=https://xenia-admin.bonamin.gr, DATA_PATH=/opt/xenia/data
- install.sh: auto-create .env from example, prompt for SITE_ID/SITE_KEY/SECRET_KEY,
  clarify DNS subdomain requirements, add backend API proxy block to nginx config

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-20 14:36:43 +03:00
bonaminandClaude Sonnet 4.6 8ba8c95ecd feat: initial commit — local services (backend + manager dashboard + waiter PWA)
Includes all work to date:
- local_backend: FastAPI backend with products, orders, tables, shifts, cloud sync
- manager_dashboard: React manager UI with product/category management, reports, settings
- waiter_pwa: React PWA for waiter devices
- Category reparent endpoint and UI
- Waiter domain: local_ip sent on heartbeat, waiter_domain persisted from cloud response
- QR code modal in AppInfoTab for waiter domain
- Product form: number input spinners removed, category pre-selected on new product
- Category row: count badge moved to far right

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-20 14:04:38 +03:00