- Workflow: use github.ref for the concurrency group so distinct PRs from the
same source branch don't cancel each other
- Workflow: extract the generated DB password from the installer's 'Password:'
output and verify the 'ospos' account can authenticate with DB_PASS
- Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session,
pass the root password via a private 0600 defaults file (no argv exposure),
and scope the SQL account to the 'localhost' client host
- Docs: interactive mode requires a tty (download-then-run, not a pipe);
clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
- Add scripts/install-ubuntu.sh: installs Apache/MariaDB/PHP, downloads the
latest stable release, configures the DB + Apache, and optionally sets up
Let's Encrypt SSL (interactive or via env vars).
- Add .github/workflows/install-script-test.yml: runs the installer in a fresh
Ubuntu container and sanity-checks the result.
- Document the installer in INSTALL.md.
- Harden the script: identifier-safe DB_NAME, quote/pipe rejection in
passwords, correct 'Candidate: (none)' PPA detection, keep unix_socket root
auth when no root password is set, select the .zip release asset, and use the
SSL domain as the public hostname for allowedHostnames.
Based on the latest master CI (build-release.yml / deploy-pr.yml left as-is).