towerops/lib/towerops_web/endpoint.ex
Graham McIntire 8682cdce55 fix: resolve session salts at runtime so prod release boots
The @session_options module attribute used Application.compile_env, which
baked compile-time placeholders into the endpoint while runtime.exs set
the real values from SESSION_SIGNING_SALT / SESSION_ENCRYPTION_SALT env
vars. Phoenix detected the mismatch and refused to start (failing migrate
Job in k8s).

- Remove hardcoded salts from config/config.exs (no compile-time binding)
- Add stable per-env salts in dev.exs / test.exs so local + CI don't need
  the env vars
- Split static cookie opts (@static_session_options) from runtime-resolved
  opts in endpoint.ex; expose session_options/0 as an MFA tuple in socket
  connect_info so LiveView decodes sessions with the same runtime salts
- New ToweropsWeb.Plugs.RuntimeSession wraps Plug.Session, fetches salts
  from app env on first request, and caches the initialized opts in
  :persistent_term (zero per-request overhead after warm-up)
2026-05-12 16:26:54 -05:00

151 lines
5 KiB
Elixir

defmodule ToweropsWeb.Endpoint do
use Phoenix.Endpoint, otp_app: :towerops
use Absinthe.Phoenix.Endpoint
# The session will be stored in the cookie and signed,
# this means its contents can be read but not tampered with.
# `http_only: true` blocks JavaScript access via `document.cookie` (XSS
# defense). `secure` is enabled in :prod by `config/runtime.exs` so the
# cookie is never sent over plain HTTP; left off here so local HTTP dev
# still works.
#
# Session salts (`signing_salt`, `encryption_salt`) come from env vars at
# runtime via `config/runtime.exs` (see `runtime_session_opts/0` below).
# They are merged in by `ToweropsWeb.Plugs.RuntimeSession` and by
# `session_options/0` (used by LiveView/socket `connect_info`).
@static_session_options [
store: :cookie,
key: "_towerops_key",
same_site: "Lax",
http_only: true
]
@doc """
Session options resolved at runtime. Used as an MFA tuple in socket
`connect_info` so LiveView decodes the session using the same salts
that `ToweropsWeb.Plugs.RuntimeSession` uses to encode it.
"""
def session_options do
@static_session_options ++ runtime_session_opts()
end
@doc false
def runtime_session_opts do
[
signing_salt: Application.fetch_env!(:towerops, :session_signing_salt),
encryption_salt: Application.fetch_env!(:towerops, :session_encryption_salt),
secure: Application.get_env(:towerops, :secure_cookies, false)
]
end
socket "/live", Phoenix.LiveView.Socket,
websocket: [connect_info: [session: {__MODULE__, :session_options, []}]],
longpoll: [connect_info: [session: {__MODULE__, :session_options, []}]]
socket "/socket/agent", ToweropsWeb.AgentSocket,
websocket: [connect_info: [:peer_data]],
longpoll: false
socket "/socket/graphql", ToweropsWeb.GraphQLSocket,
websocket: true,
longpoll: false
socket "/mobile/socket", ToweropsWeb.MobileSocket,
websocket: [timeout: 60_000],
longpoll: false
# Serve at "/" the static files from "priv/static" directory.
#
# When code reloading is disabled (e.g., in production),
# the `gzip` option is enabled to serve compressed
# static files generated by running `phx.digest`.
plug Plug.Static,
at: "/",
from: :towerops,
gzip: not code_reloading?,
only: ToweropsWeb.static_paths(),
raise_on_missing_only: code_reloading?
# Generated coverage rasters live outside priv/static so the path can point
# at a shared NFS mount in production (see :coverage_storage_dir). Keep this
# plug after the main static plug so /coverage URLs only fall through here.
plug Plug.Static,
at: "/coverage",
from: Application.compile_env(:towerops, :coverage_storage_dir, {:towerops, "priv/static/coverage"}),
gzip: false
# Code reloading can be explicitly enabled under the
# :code_reloader configuration of your endpoint.
if code_reloading? do
socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket
plug Phoenix.LiveReloader
plug Phoenix.CodeReloader
plug Phoenix.Ecto.CheckRepoStatus, otp_app: :towerops
end
plug Phoenix.LiveDashboard.RequestLogger,
param_key: "request_logger",
cookie_key: "request_logger"
plug Plug.RequestId
plug ToweropsWeb.Plugs.RemoteIpLogger
plug ToweropsWeb.Plugs.FilterNoisyLogs
plug ToweropsWeb.Plugs.BruteForceProtection
plug ToweropsWeb.Plugs.SecurityHeaders
plug Plug.Telemetry,
event_prefix: [:phoenix, :endpoint],
log: {__MODULE__, :telemetry_log_level, []}
# Dynamic log level for Plug.Telemetry — suppresses logging for
# health checks and uptime monitors (filtered by FilterNoisyLogs plug).
def telemetry_log_level(conn) do
if conn.private[:plug_skip_telemetry] do
false
else
:info
end
end
plug Plug.Parsers,
parsers: [:urlencoded, :multipart, :json],
pass: ["*/*"],
body_reader: {ToweropsWeb.Endpoint.BodyReader, :read_body, []},
json_decoder: Phoenix.json_library()
# Custom body reader that skips parsing for protobuf content type
# and caches raw body for webhook signature verification.
defmodule BodyReader do
@moduledoc false
def read_body(conn, opts) do
case Plug.Conn.get_req_header(conn, "content-type") do
["application/x-protobuf" | _] ->
# Don't parse protobuf, let the controller handle it
{:ok, "", conn}
_ ->
case Plug.Conn.read_body(conn, opts) do
{:ok, body, conn} ->
conn = update_in(conn.private[:raw_body], &((&1 || "") <> body))
{:ok, body, conn}
other ->
other
end
end
end
end
plug Plug.MethodOverride
plug Plug.Head
plug ToweropsWeb.Plugs.RuntimeSession, @static_session_options
# Enable SQL Sandbox metadata for LiveView tests
# This allows LiveView processes to access the test's sandbox connection
if Application.compile_env(:towerops, :sql_sandbox) do
plug Phoenix.Ecto.SQL.Sandbox
end
plug ToweropsWeb.Plugs.MarkdownNegotiation
plug ToweropsWeb.Router
end