Render the app privacy policies from the app repos
Each policy now has exactly one copy: docs/PRIVACY.md in the app's own repository. The pages keep their URLs and chrome and render that file through a content collection, so the published page and the app's own documentation cannot drift. scripts/sync-external.mjs shallow-clones both repos into external/ from prebuild and predev — not from CI: Coolify builds the site from the repo, so a checkout that only ran in a Gitea job would never reach the deploy. It falls back to the raw file if git is unavailable, and takes <APP>_REF or <APP>_LOCAL for work against a branch or an unpushed working copy. A missing, empty or malformed policy fails the build, verified against the real image: the deploy stops rather than publishing an empty privacy page.
This commit is contained in:
@@ -7,6 +7,14 @@ WORKDIR /app
|
||||
# Use npm install (not npm ci): Astro 7's wasm32 optional deps (@emnapi/*)
|
||||
# make npm ci's strict lock-sync check fail across npm/node versions. install
|
||||
# reconciles the lockfile and builds reliably.
|
||||
# git: the build fetches the app repositories whose docs/PRIVACY.md this site
|
||||
# renders (scripts/sync-external.mjs, run from `prebuild`). node:slim ships
|
||||
# without it; the script would fall back to fetching the raw files over HTTPS,
|
||||
# but a shallow clone is the intended path and keeps the failure modes obvious.
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends git ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY package.json package-lock.json* ./
|
||||
RUN npm install --no-audit --no-fund
|
||||
|
||||
|
||||
Reference in New Issue
Block a user