Repository navigation
Fix 403 on / and all static assets (frontend file modes) - #19
Merged
Merged
Conversation
… in the image abct-deploy builds from a clone made under umask 027, so frontend files were 0640 and directories 0750 (root:root). COPY keeps those modes, and nginx workers (www-data) got EACCES on /app/frontend: / and /classic returned 403, and every /static and /next/static asset was 403, so /next/ rendered unstyled with no JS. Normalise the modes after COPY, and add a regression test. Incident: ABCT-403-INCIDENT-2026-09-29 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Overview
Labels (5 changes)
org.opencontainers.image.authors=Chris Catalano
org.opencontainers.image.base.name=python:3.11-slim
-org.opencontainers.image.created=2026-09-29T10:45:04.139Z
-org.opencontainers.image.description=A Better Crypto Tracker
+org.opencontainers.image.description=Multi-chain cryptocurrency portfolio tracker supporting Cardano, Ethereum, Bitcoin, Solana, Polygon, and Base
org.opencontainers.image.documentation=https://github.com/Tarrant64/abct/blob/main/README.md
org.opencontainers.image.icon=https://raw.githubusercontent.com/Tarrant64/abct/main/frontend/static/apple-touch-icon.png
org.opencontainers.image.licenses=MIT
-org.opencontainers.image.revision=aa80d90094ae53bde33020d6df53c71f479184cc
org.opencontainers.image.source=https://github.com/Tarrant64/abct
-org.opencontainers.image.title=abct
+org.opencontainers.image.title=ABCT - A Better Crypto Tracker
org.opencontainers.image.url=https://github.com/Tarrant64/abct
org.opencontainers.image.vendor=ABCT Project
-org.opencontainers.image.version=latest
+org.opencontainers.image.version=1.12.3 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Since the first abct-deploy build (4f68c10, 2026-09-28 about 20:06 CDT),
/and/classicreturn 403./next/returns 200, but every asset it loads (v2.css, v2-app.js, v2-shell.js, v2-cache.js, session-auth.js, favicon) is 403, so the page renders broken.Root cause
abct-deploy runs with
umask 027and does a freshgit clone, so the build context has 0640 files and 0750 dirs.COPY frontend/ /app/frontend/keeps those modes, and the nginx workers run aswww-data, so nginx logsopen() "/app/frontend/index.html" failed (13: Permission denied). The fac2ac1 image, built by hand under umask 022, has 0644/0755 and works. The file contents are identical across images.Fix
RUN chmod -R a+rX /app/frontendright after the COPY. With this, the image no longer depends on the builder's umask.Test
tests/unit/test_dockerfile_frontend_perms.pyis a static check that the Dockerfile normalises frontend modes after the COPY. It fails without the fix and passes with it.Do not merge without review. Deploy through abct-deploy after merge, then check that
GET /andGET /next/static/css/v2.cssreturn 200.🤖 Generated with Claude Code