The shipped .env has no app.allowedHostnames line, so the previous sed was a
silent no-op. Since the installer sets CI_ENVIRONMENT=production, the app then
fails fast on first load (App.php throws when the whitelist is empty). Append
the key if it's missing, or substitute it if present.
The cleanup used '[ -n ... ] && rm -f ...', which returns non-zero when the
temp file is unset (the no-root-password default). Under the installer's
'set -e', that non-zero status becomes the script's exit code, failing the CI
step even though the install completed. Rewrite as an if-statement so it
always exits 0.
- Workflow: use github.ref for the concurrency group so distinct PRs from the
same source branch don't cancel each other
- Workflow: extract the generated DB password from the installer's 'Password:'
output and verify the 'ospos' account can authenticate with DB_PASS
- Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session,
pass the root password via a private 0600 defaults file (no argv exposure),
and scope the SQL account to the 'localhost' client host
- Docs: interactive mode requires a tty (download-then-run, not a pipe);
clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
- Add scripts/install-ubuntu.sh: installs Apache/MariaDB/PHP, downloads the
latest stable release, configures the DB + Apache, and optionally sets up
Let's Encrypt SSL (interactive or via env vars).
- Add .github/workflows/install-script-test.yml: runs the installer in a fresh
Ubuntu container and sanity-checks the result.
- Document the installer in INSTALL.md.
- Harden the script: identifier-safe DB_NAME, quote/pipe rejection in
passwords, correct 'Candidate: (none)' PPA detection, keep unix_socket root
auth when no root password is set, select the .zip release asset, and use the
SSL domain as the public hostname for allowedHostnames.
Based on the latest master CI (build-release.yml / deploy-pr.yml left as-is).