# Development only. Not for production use. ARG PDS_IMAGE=ghcr.io/bluesky-social/pds:0.4.219 FROM ${PDS_IMAGE} # the oauth provider treats a `same-site` navigation to /oauth/authorize as csrf # and only allows same-origin/cross-site/none. localinfra serves web/ and the pds # from sibling subdomains of one registrable domain. RUN set -eu; \ f=$(find /app/node_modules/.pnpm \ -path '*@atproto/oauth-provider/dist/router/create-authorization-page-middleware.js' \ | head -1); \ [ -n "$f" ] || { echo "oauth-provider middleware not found; pds layout changed" >&2; exit 1; }; \ grep -q "\['same-origin', 'cross-site', 'none'\]" "$f" || { \ echo "fetch-site allowlist not in the expected shape; re-check the patch" >&2; exit 1; }; \ sed -i "s/\['same-origin', 'cross-site', 'none'\]/['same-origin', 'same-site', 'cross-site', 'none']/" "$f"; \ grep -q "\['same-origin', 'same-site', 'cross-site', 'none'\]" "$f"