# xAuth backend
# Copyright (c) 2026 Hubert Lepiarczyk, IceLAB (www.icelab.pl)
# SPDX-License-Identifier: Apache-2.0
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file
# except in compliance with the License. You may obtain a copy of the License at
#     http://www.apache.org/licenses/LICENSE-2.0
# Unless required by applicable law or agreed to in writing, software distributed under the
# License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
# either express or implied. See the License for the specific language governing permissions
# and limitations under the License.

# Base image pinned by digest (python:3.12-slim); refresh deliberately for security updates.
FROM python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9

ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app XAUTH_DB=/data/xauth.db
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY xauth ./xauth
COPY xauth-admin /usr/local/bin/xauth-admin

# chmod in a RUN step: works with the classic builder too (COPY --chmod needs BuildKit), and the
# file may lose its mode when the sources come from a zip; sed drops CRs added by Windows editors
RUN sed -i 's/\r$//' /usr/local/bin/xauth-admin && chmod 755 /usr/local/bin/xauth-admin \
    && useradd -r -u 10001 xauth && mkdir -p /data && chown xauth /data
USER xauth
VOLUME ["/data"]
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=5s CMD python -c "import urllib.request;urllib.request.urlopen('http://127.0.0.1:8000/healthz')"
CMD ["uvicorn", "xauth.app:app_from_env", "--factory", "--host", "0.0.0.0", "--port", "8000"]
