From bd36ec6f47ee7bf0599cfe3cd06d7d0474c2dc36 Mon Sep 17 00:00:00 2001 From: addshore Date: Fri, 25 Sep 2026 20:03:49 +0100 Subject: [PATCH] Run Passport setup as www-data Apache reads OAuth keys as www-data. Creating them as that user prevents unreadable root-owned keys. --- Makefile | 2 +- README.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/Makefile b/Makefile index ddb31b5c7..6122789fa 100644 --- a/Makefile +++ b/Makefile @@ -6,7 +6,7 @@ test: docker compose exec api bash -c 'LOG_CHANNEL=stderr LOG_LEVEL=debug vendor/bin/phpunit ${FILTER}' init: - docker compose exec api bash -c 'php artisan migrate:fresh && php artisan passport:install --no-interaction && php artisan key:generate' + docker compose exec api bash -c 'php artisan migrate:fresh && su -s /bin/sh www-data -c "php artisan passport:install --no-interaction" && php artisan key:generate' test-fresh: init test diff --git a/README.md b/README.md index 8757149ac..691e84531 100644 --- a/README.md +++ b/README.md @@ -50,7 +50,7 @@ docker compose down --volumes Run everything in one go: ```sh -docker compose exec api bash -c 'php artisan migrate:fresh && php artisan passport:install --no-interaction && php artisan db:seed && php artisan key:generate && php artisan storage:link' +docker compose exec api bash -c 'php artisan migrate:fresh && su -s /bin/sh www-data -c "php artisan passport:install --no-interaction" && php artisan db:seed && php artisan key:generate && php artisan storage:link' ``` Or each command separately: @@ -60,7 +60,7 @@ Or each command separately: docker compose exec api php artisan migrate:fresh # Create some certs needed for authentication (passport is a laravel plugin) -docker compose exec api php artisan passport:install --no-interaction +docker compose exec --user www-data api php artisan passport:install --no-interaction # Seed some useful development data docker compose exec api php artisan db:seed