Skip to content

Fix 403 on / and all static assets (frontend file modes) - #19

Merged
Tarrant64 merged 1 commit into
mainfrom
fix/frontend-403
Sep 29, 2026
Merged

Tarrant64 merged 1 commit into
mainfrom
fix/frontend-403

Conversation

@Tarrant64

Copy link
Copy Markdown
Owner

Problem

Since the first abct-deploy build (4f68c10, 2026-09-28 about 20:06 CDT), / and /classic return 403. /next/ returns 200, but every asset it loads (v2.css, v2-app.js, v2-shell.js, v2-cache.js, session-auth.js, favicon) is 403, so the page renders broken.

Root cause

abct-deploy runs with umask 027 and does a fresh git clone, so the build context has 0640 files and 0750 dirs. COPY frontend/ /app/frontend/ keeps those modes, and the nginx workers run as www-data, so nginx logs open() "/app/frontend/index.html" failed (13: Permission denied). The fac2ac1 image, built by hand under umask 022, has 0644/0755 and works. The file contents are identical across images.

Fix

RUN chmod -R a+rX /app/frontend right after the COPY. With this, the image no longer depends on the builder's umask.

Test

tests/unit/test_dockerfile_frontend_perms.py is a static check that the Dockerfile normalises frontend modes after the COPY. It fails without the fix and passes with it.

Do not merge without review. Deploy through abct-deploy after merge, then check that GET / and GET /next/static/css/v2.css return 200.

🤖 Generated with Claude Code

… in the image

abct-deploy builds from a clone made under umask 027, so frontend files were 0640
and directories 0750 (root:root). COPY keeps those modes, and nginx workers (www-data)
got EACCES on /app/frontend: / and /classic returned 403, and every /static and
/next/static asset was 403, so /next/ rendered unstyled with no JS. Normalise the
modes after COPY, and add a regression test.

Incident: ABCT-403-INCIDENT-2026-09-29

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Overview

Image reference tarrant64/abct:latest tarrant64/abct:pr-19
- digest a9f7457383d5 aeab366568f2
- tag latest pr-19
- provenance aa80d90
- vulnerabilities critical: 0 high: 7 medium: 7 low: 56 critical: 0 high: 7 medium: 7 low: 56
- platform linux/amd64 linux/amd64
- size 110 MB 126 MB (+16 MB)
- packages 285 285
Labels (5 changes)
  • - 2 removed
  • ± 3 changed
  • 8 unchanged
 org.opencontainers.image.authors=Chris Catalano
 org.opencontainers.image.base.name=python:3.11-slim
-org.opencontainers.image.created=2026-09-29T10:45:04.139Z
-org.opencontainers.image.description=A Better Crypto Tracker
+org.opencontainers.image.description=Multi-chain cryptocurrency portfolio tracker supporting Cardano, Ethereum, Bitcoin, Solana, Polygon, and Base
 org.opencontainers.image.documentation=https://github.com/Tarrant64/abct/blob/main/README.md
 org.opencontainers.image.icon=https://raw.githubusercontent.com/Tarrant64/abct/main/frontend/static/apple-touch-icon.png
 org.opencontainers.image.licenses=MIT
-org.opencontainers.image.revision=aa80d90094ae53bde33020d6df53c71f479184cc
 org.opencontainers.image.source=https://github.com/Tarrant64/abct
-org.opencontainers.image.title=abct
+org.opencontainers.image.title=ABCT - A Better Crypto Tracker
 org.opencontainers.image.url=https://github.com/Tarrant64/abct
 org.opencontainers.image.vendor=ABCT Project
-org.opencontainers.image.version=latest
+org.opencontainers.image.version=1.12.3

@Tarrant64
Tarrant64 merged commit 5f78eaf into main Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant