diff --git a/backend/lib/config.js b/backend/lib/config.js index 71205013..59cb6598 100644 --- a/backend/lib/config.js +++ b/backend/lib/config.js @@ -145,7 +145,7 @@ const generateKeys = () => { // Write keys config try { - fs.writeFileSync(keysFile, JSON.stringify(keys, null, 2)); + fs.writeFileSync(keysFile, JSON.stringify(keys, null, 2), { mode: 0o600 }); } catch (err) { logger.error(`Could not write JWT key pair to config file: ${keysFile}: ${err.message}`); process.exit(1); diff --git a/docker/rootfs/etc/s6-overlay/s6-rc.d/prepare/30-ownership.sh b/docker/rootfs/etc/s6-overlay/s6-rc.d/prepare/30-ownership.sh index fa946518..4236c90a 100755 --- a/docker/rootfs/etc/s6-overlay/s6-rc.d/prepare/30-ownership.sh +++ b/docker/rootfs/etc/s6-overlay/s6-rc.d/prepare/30-ownership.sh @@ -46,6 +46,12 @@ for loc in "${locations[@]}"; do chownit "$loc" done +# Ensure the JWT key file is owned by the runtime user, even when the /data +# directory ownership already matches PUID:PGID (chownit skips recursion then) +if [ -f /data/keys.json ]; then + chown "$PUID:$PGID" /data/keys.json +fi + if [ "$(is_true "${SKIP_CERTBOT_OWNERSHIP:-}")" = '1' ]; then log_info 'Skipping ownership change of certbot directories' else