diff --git a/apps/angular/src/index.html b/apps/angular/src/index.html index 1e325c50..54ba34c2 100644 --- a/apps/angular/src/index.html +++ b/apps/angular/src/index.html @@ -1,16 +1,20 @@ - - - EShopOnAbp - - - - - - -
-
- + + + + EShopOnAbp + + + + + + + + +
+
+ + diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs index 8b57f016..3f1ebc6b 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs @@ -78,6 +78,7 @@ public class EShopOnAbpAuthServerModule : AbpModule var hostingEnvironment = context.Services.GetHostingEnvironment(); var configuration = context.Services.GetConfiguration(); + ConfigureSameSiteCookiePolicy(context); ConfigureSwagger(context, configuration); context.Services.AddAuthentication() @@ -148,6 +149,11 @@ public class EShopOnAbpAuthServerModule : AbpModule } } + private void ConfigureSameSiteCookiePolicy(ServiceConfigurationContext context) + { + context.Services.AddSameSiteCookiePolicy(); + } + public override void OnApplicationInitialization(ApplicationInitializationContext context) { var app = context.GetApplicationBuilder(); @@ -181,6 +187,7 @@ public class EShopOnAbpAuthServerModule : AbpModule app.UseStaticFiles(); app.UseRouting(); app.UseCors(); + app.UseCookiePolicy(); app.UseAuthentication(); app.UseJwtTokenMiddleware(); app.UseAbpSerilogEnrichers(); diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs new file mode 100644 index 00000000..f888c976 --- /dev/null +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs @@ -0,0 +1,70 @@ +using Microsoft.AspNetCore.Builder; +using Microsoft.AspNetCore.Http; + +namespace Microsoft.Extensions.DependencyInjection +{ + public static class SameSiteCookiesServiceCollectionExtensions + { + public static IServiceCollection AddSameSiteCookiePolicy(this IServiceCollection services) + { + services.Configure(options => + { + options.MinimumSameSitePolicy = SameSiteMode.Unspecified; + options.OnAppendCookie = cookieContext => + CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); + options.OnDeleteCookie = cookieContext => + CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); + }); + + return services; + } + + private static void CheckSameSite(HttpContext httpContext, CookieOptions options) + { + if (options.SameSite == SameSiteMode.None) + { + var userAgent = httpContext.Request.Headers["User-Agent"].ToString(); + if (!httpContext.Request.IsHttps || DisallowsSameSiteNone(userAgent)) + { + // For .NET Core < 3.1 set SameSite = (SameSiteMode)(-1) + options.SameSite = SameSiteMode.Unspecified; + } + } + } + + private static bool DisallowsSameSiteNone(string userAgent) + { + // Cover all iOS based browsers here. This includes: + // - Safari on iOS 12 for iPhone, iPod Touch, iPad + // - WkWebview on iOS 12 for iPhone, iPod Touch, iPad + // - Chrome on iOS 12 for iPhone, iPod Touch, iPad + // All of which are broken by SameSite=None, because they use the iOS networking stack + if (userAgent.Contains("CPU iPhone OS 12") || userAgent.Contains("iPad; CPU OS 12")) + { + return true; + } + + // Cover Mac OS X based browsers that use the Mac OS networking stack. This includes: + // - Safari on Mac OS X. + // This does not include: + // - Chrome on Mac OS X + // Because they do not use the Mac OS networking stack. + if (userAgent.Contains("Macintosh; Intel Mac OS X 10_14") && + userAgent.Contains("Version/") && userAgent.Contains("Safari")) + { + return true; + } + + // Cover Chrome 50-69, because some versions are broken by SameSite=None, + // and none in this range require it. + // Note: this covers some pre-Chromium Edge versions, + // but pre-Chromium Edge does not require SameSite=None. + if (userAgent.Contains("Chrome/5") || userAgent.Contains("Chrome/6")) + { + return true; + } + + return false; + } + } +} \ No newline at end of file diff --git a/etc/docker/certs/eshop-ssl.conf b/etc/docker/certs/eshop-ssl.conf index e82d4494..e433b42b 100644 --- a/etc/docker/certs/eshop-ssl.conf +++ b/etc/docker/certs/eshop-ssl.conf @@ -28,7 +28,7 @@ DNS.6 = app-publicweb DNS.7 = gateway-web DNS.8 = gateway-web-public DNS.9 = administration-service -DNS.10 = identity-service +DNS.10 = identity-service DNS.11 = catalog-service DNS.12 = basket-service DNS.13 = ordering-service diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 10e400cc..769b0e49 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -3,32 +3,48 @@ version: '3.7' services: lb: image: nginx:1.21 + container_name: load-balancer-container ports: - 80:80 - 443:443 volumes: - - ./nginx/certs/app-publicweb+2.pem:/etc/nginx/certs/app-cert.pem:ro - - ./nginx/certs/app-publicweb+2-key.pem:/etc/nginx/certs/app-key.pem:ro + - ./nginx/certs/eshop-st-web+10.pem:/etc/nginx/certs/app-cert.pem:ro + - ./nginx/certs/eshop-st-web+10-key.pem:/etc/nginx/certs/app-cert-key.pem:ro - ./nginx/conf.d:/etc/nginx/conf.d:ro + depends_on: + - eshop-st-administration + - eshop-st-authserver + - eshop-st-identity + - eshop-st-basket + - eshop-st-catalog + - eshop-st-ordering + - eshop-st-payment + - eshop-st-web + - eshop-st-public-web + - eshop-st-gateway-web-public + - eshop-st-gateway-web networks: - eshoponabp-network - administration-service: + eshop-st-administration: image: eshoponabp/service-administration:latest container_name: administration-service-container build: context: ../../ dockerfile: services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker + # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44353:443" + - App__SelfUrl=https://eshop-st-administration + - App__CorsOrigins=https://gateway-web,gateway-web-public + - RemoteServices__AbpIdentity__BaseUrl=eshop-st-identity + - RemoteServices__AbpIdentity__UseCurrentAccessToken=false + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - IdentityClients__Default__Authority=http://eshop-st-identity + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -39,25 +55,34 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - identity-service: + eshop-st-identity: image: eshoponabp/service-identity:latest container_name: identity-service-container build: context: ../../ dockerfile: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker + # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq + - App__SelfUrl=https://eshop-st-identity + - App__CorsOrigins=https://gateway-web,gateway-web-public + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44351:443" + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - IdentityServerClients__Web__RootUrl=https://eshop-st-web + - IdentityServerClients__PublicWeb__RootUrl=https://eshop-st-public-web + - IdentityServerClients__WebGateway__RootUrl=https://localhost:44372 + - IdentityServerClients__PublicWebGateway__RootUrl=https://eshop-st-gateway-web-public + - IdentityServerClients__IdentityService__RootUrl=https://eshop-st-identity + - IdentityServerClients__AdministrationService__RootUrl=https://eshop-st-administration + - IdentityServerClients__AccountService__RootUrl=https://eshop-st-authserver + - IdentityServerClients__CatalogService__RootUrl=https://localhost:44354 + - IdentityServerClients__BasketService__RootUrl=https://localhost:44355 + - IdentityServerClients__OrderingService__RootUrl=https://localhost:44356 + - IdentityServerClients__PaymentService__RootUrl=https://localhost:44357 depends_on: redis: condition: service_healthy @@ -68,30 +93,26 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - catalog-service: + eshop-st-catalog: image: eshoponabp/service-catalog:latest container_name: catalog-service-container build: context: ../../ dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80;http://+:81; + - App__SelfUrl=https://eshop-st-catalog + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web,https://eshop-st-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44354:443" - # - "5000:80" - # - "81:81" + - Kestrel__EndPoints__gRPC__Protocols=Http2 + - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -102,26 +123,24 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - basket-service: + eshop-st-basket: image: eshoponabp/service-basket:latest container_name: basket-service-container build: context: ../../ dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - RemoteServices__Catalog__BaseUrl=https://catalog-service - # - RemoteServices__Catalog__GrpcUrl=http://catalog-service - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44355:443" + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80 + - App__SelfUrl=https://eshop-st-basket + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web + - RemoteServices__Catalog__BaseUrl=http://eshop-st-catalog:80 + - RemoteServices__Catalog__GrpcUrl=http://eshop-st-catalog:81 + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -132,25 +151,23 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - ordering-service: + eshop-st-ordering: image: eshoponabp/service-ordering:latest container_name: ordering-service-container build: context: ../../ dockerfile: services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-ordering + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-web + - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44356:443" depends_on: redis: condition: service_healthy @@ -163,26 +180,26 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - payment-service: + eshop-st-payment: image: eshoponabp/service-payment:latest container_name: payment-service-container build: context: ../../ dockerfile: services/payment/src/EShopOnAbp.PaymentService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-payment + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public - ConnectionStrings__PaymentService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Payment;Pooling=false; - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq - Payment__PayPal__ClientId=PAYPAL_CLIENT_ID - Payment__PayPal__Secret=PAYPAL_SECRET - Payment__PayPal__Environment=Sandbox - # ports: - # - "44357:443" depends_on: redis: condition: service_healthy @@ -193,84 +210,66 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - app-web: - image: eshoponabp/app-web:latest - container_name: app-web-container + eshop-st-authserver: + image: eshoponabp/app-authserver:latest + container_name: app-authserver-container build: context: ../../ - dockerfile: apps/angular/Dockerfile + dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile environment: + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-authserver + - App__CorsOrigins=https://eshop-st-web,https://eshop-st-public-web,https://eshop-st-identity,http://eshop-st-administration,https://eshop-st-administration,https://eshop-st-catalog,https://eshop-st-basket,https://eshop-st-ordering,https://eshop-st-payment + - App__RedirectAllowedUrls=http://eshop-st-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - RemoteServices__Default__BaseUrl=http://gateway-web-public - # ports: - # - "4200:80" depends_on: redis: condition: service_healthy + postgres-db: + condition: service_healthy rabbitmq: condition: service_healthy restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - app-authserver: - image: eshoponabp/app-authserver:latest - container_name: app-authserver-container + eshop-st-web: + image: eshoponabp/app-web:latest + container_name: app-web-container build: context: ../../ - dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile - environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - - ASPNETCORE_HTTPS_PORT=44330 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - App__SelfUrl=https://app-authserver - # - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service - # - App__RedirectAllowedUrls=http://app-web - - AuthServer__Authority=https://app-authserver - - AuthServer__RequireHttpsMetadata=true - # - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44330:443" + dockerfile: apps/angular/Dockerfile + volumes: + - ./nginx/dynamic-env.json://usr/share/nginx/html/dynamic-env.json depends_on: redis: condition: service_healthy - postgres-db: - condition: service_healthy rabbitmq: condition: service_healthy - restart: on-failure + restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - app-publicweb: + eshop-st-public-web: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container build: context: ../../ dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - App__SelfUrl=https://app-publicweb - - AuthServer__Authority=https://app-authserver - - AuthServer__RequireHttpsMetadata=true - # - RemoteServices__Default__BaseUrl=http://gateway-web-public - # - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public - # ports: - # - "44335:443" + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-public-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - RemoteServices__Default__BaseUrl=http://eshop-st-gateway-web-public/ + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://eshop-st-gateway-web-public depends_on: redis: condition: service_healthy @@ -279,9 +278,7 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - gateway-web: + eshop-st-gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container build: @@ -289,18 +286,20 @@ services: dockerfile: gateways/web/src/EShopOnAbp.WebGateway/Dockerfile environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-gateway-web + - App__CorsOrigins=https://eshop-st-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver - - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://identity-service - - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service - - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service - - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://eshop-st-authserver + - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://eshop-st-identity + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://eshop-st-catalog + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://eshop-st-ordering + - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://eshop-st-administration # ports: # - "44372:443" depends_on: @@ -311,29 +310,26 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - gateway-web-public: + eshop-st-gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container build: context: ../../ dockerfile: gateways/web-public/src/EShopOnAbp.WebPublicGateway/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-gateway-web-public + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver - - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service - - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://basket-service - - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service - - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://payment-service - - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://catalog-service - # ports: - # - "44373:443" + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://eshop-st-authserver + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://eshop-st-catalog + - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://eshop-st-basket + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://eshop-st-ordering + - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://eshop-st-payment + - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://eshop-st-catalog depends_on: redis: condition: service_healthy @@ -342,8 +338,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate networks: eshoponabp-network: diff --git a/etc/docker/nginx/conf.d/default.conf b/etc/docker/nginx/conf.d/default.conf index 4dbfcbf5..60df3f24 100644 --- a/etc/docker/nginx/conf.d/default.conf +++ b/etc/docker/nginx/conf.d/default.conf @@ -1,15 +1,174 @@ server { listen 80; listen 443 ssl; - server_name administration-service; + server_name eshop-st-administration; ssl_certificate /etc/nginx/certs/app-cert.pem; - ssl_certificate_key /etc/nginx/certs/app-key.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; location / { - proxy_pass http://administration-service:80; + proxy_pass http://eshop-st-administration:80; proxy_set_header Host $host; } } +server { + listen 80; + listen 443 ssl; + server_name eshop-st-identity; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-identity:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-authserver; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-authserver:80; + proxy_set_header Host $host; + add_header from-ingress true; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-web; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-web:80; + proxy_set_header Host $host; + + proxy_buffer_size 128k; + proxy_buffers 4 256k; + proxy_busy_buffers_size 256k; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-public-web; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-public-web:80; + proxy_set_header Host $host; + + proxy_buffer_size 128k; + proxy_buffers 4 256k; + proxy_busy_buffers_size 256k; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-basket; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-basket:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-catalog; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-catalog:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-ordering; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-ordering:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-payment; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-payment:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-gateway-web-public; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-gateway-web-public:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-gateway-web; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-gateway-web:80; + proxy_set_header Host $host; + } +} \ No newline at end of file diff --git a/etc/docker/nginx/dynamic-env.json b/etc/docker/nginx/dynamic-env.json new file mode 100644 index 00000000..56c559a2 --- /dev/null +++ b/etc/docker/nginx/dynamic-env.json @@ -0,0 +1,23 @@ +{ + "production": true, + "application": { + "baseUrl":"https://eshop-st-web", + "name": "EShopOnAbp", + "logoUrl": "" + }, + "oAuthConfig": { + "issuer": "https://eshop-st-authserver", + "redirectUri": "https://eshop-st-web", + "clientId": "Web", + "responseType": "code", + "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService", + "strictDiscoveryDocumentValidation": false, + "requireHttps": false + }, + "apis": { + "default": { + "url": "https://eshop-st-gateway-web", + "rootNamespace": "EShopOnAbp" + } + } +} \ No newline at end of file