mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-10-07 01:52:20 -04:00
- Workflow: use github.ref for the concurrency group so distinct PRs from the same source branch don't cancel each other - Workflow: extract the generated DB password from the installer's 'Password:' output and verify the 'ospos' account can authenticate with DB_PASS - Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session, pass the root password via a private 0600 defaults file (no argv exposure), and scope the SQL account to the 'localhost' client host - Docs: interactive mode requires a tty (download-then-run, not a pipe); clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
140 lines
5.0 KiB
YAML
140 lines
5.0 KiB
YAML
name: Install Script Test
|
|
|
|
on:
|
|
push:
|
|
paths:
|
|
- 'scripts/install-ubuntu.sh'
|
|
- '.github/workflows/install-script-test.yml'
|
|
pull_request:
|
|
paths:
|
|
- 'scripts/install-ubuntu.sh'
|
|
- '.github/workflows/install-script-test.yml'
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
install-test:
|
|
name: Test Install Script (${{ matrix.scenario }})
|
|
runs-on: ubuntu-22.04
|
|
timeout-minutes: 30
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- scenario: default
|
|
db_pass: ''
|
|
- scenario: custom-password
|
|
db_pass: 'TestPass123!'
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Make install script executable
|
|
run: chmod +x scripts/install-ubuntu.sh
|
|
|
|
- name: Run install script
|
|
env:
|
|
DB_PASS: ${{ matrix.db_pass }}
|
|
run: |
|
|
set -o pipefail
|
|
echo "Running install script with scenario: ${{ matrix.scenario }}"
|
|
sudo -E bash scripts/install-ubuntu.sh 2>&1 | tee install-output.log
|
|
echo "Install completed successfully"
|
|
|
|
- name: Wait for services to stabilize
|
|
run: sleep 10
|
|
|
|
- name: Verify Apache is running
|
|
run: |
|
|
echo "Checking Apache status..."
|
|
sudo systemctl status apache2 --no-pager
|
|
sudo systemctl is-active apache2
|
|
|
|
- name: Verify MariaDB is running
|
|
run: |
|
|
echo "Checking MariaDB status..."
|
|
sudo systemctl status mariadb --no-pager
|
|
sudo systemctl is-active mariadb
|
|
|
|
- name: Verify Apache HTTP response
|
|
run: |
|
|
echo "Testing HTTP response on port 80..."
|
|
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" http://localhost/)
|
|
echo "HTTP Response Code: $HTTP_CODE"
|
|
if [ "$HTTP_CODE" = "200" ] || [ "$HTTP_CODE" = "302" ]; then
|
|
echo "Apache is responding correctly"
|
|
elif [ "$HTTP_CODE" = "500" ]; then
|
|
echo "HTTP 500 - Application error. Checking .env configuration..."
|
|
# Never print secret values (password, encryption key) to the log;
|
|
# show only non-secret keys and confirm the sensitive ones are present.
|
|
sudo cat /var/www/ospos/.env 2>/dev/null | grep -E "database\.default\.(hostname|database|username)|CI_ENVIRONMENT" | head -10
|
|
sudo grep -q '^encryption\.key=.' /var/www/ospos/.env 2>/dev/null && echo "encryption.key is set" || echo "WARNING: encryption.key is NOT set"
|
|
sudo cat /var/www/ospos/writable/logs/*.log 2>/dev/null | tail -20 || true
|
|
curl -s -L http://localhost/ | head -50
|
|
exit 1
|
|
else
|
|
echo "Unexpected HTTP code: $HTTP_CODE"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Verify OSPOS login page
|
|
run: |
|
|
echo "Checking OSPOS login page..."
|
|
# Follow redirects (-L): the root path may 302 to the login route, so
|
|
# fetch the final page to actually see the login form.
|
|
curl -s -L http://localhost/ | grep -qi "login\|password\|username" && echo "Login page content found" || {
|
|
echo "Login page verification failed"
|
|
curl -s -L http://localhost/ | head -50
|
|
exit 1
|
|
}
|
|
|
|
- name: Verify database exists
|
|
env:
|
|
DB_PASS: ${{ matrix.db_pass != '' && matrix.db_pass || '' }}
|
|
run: |
|
|
echo "Verifying database..."
|
|
|
|
# Extract the generated password from install output if using default.
|
|
# The installer prints " Password: <value>" (the first such line is the DB
|
|
# password; a later one is the app login password), so anchor on it and take
|
|
# the first match.
|
|
if [ -z "${{ matrix.db_pass }}" ]; then
|
|
GENERATED_PASS=$(grep -oP '^\s*Password: \K[^\s]+' install-output.log | head -n 1 || true)
|
|
if [ -n "$GENERATED_PASS" ]; then
|
|
DB_PASS="$GENERATED_PASS"
|
|
fi
|
|
fi
|
|
|
|
# Check database exists
|
|
sudo mysql -u root -e "SHOW DATABASES LIKE 'ospos';" | grep -q ospos && echo "Database 'ospos' exists" || {
|
|
echo "Database 'ospos' not found"
|
|
sudo mysql -u root -e "SHOW DATABASES;"
|
|
exit 1
|
|
}
|
|
|
|
# Check tables exist (use the app account so the scenario actually proves
|
|
# `ospos` can authenticate with the configured DB_PASS, not just root)
|
|
TABLE_COUNT=$(sudo mysql -u ospos -p"$DB_PASS" ospos -e "SHOW TABLES;" | wc -l)
|
|
echo "Found $TABLE_COUNT tables in database"
|
|
if [ "$TABLE_COUNT" -gt 5 ]; then
|
|
echo "Database tables verified"
|
|
else
|
|
echo "Not enough tables found"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Upload install log
|
|
uses: actions/upload-artifact@v4
|
|
if: always()
|
|
with:
|
|
name: install-log-${{ matrix.scenario }}
|
|
path: install-output.log
|
|
retention-days: 7 |