4 Commits
Author SHA1 Message Date
ogrechkoandClaude Sonnet 5 ea6c43f5af Fix production build: npm registry flakiness, stray package-lock.json dir, TS error
- registry.npmjs.org was intermittently ETIMEDOUT mid-download from this
  host; switched to registry.npmmirror.com (also raised npm's own retry
  budget as a second line of defense).
- frontend/package-lock.json on disk was actually an empty directory
  (untracked, root-owned — a stray artifact, likely from an old bad
  bind-mount), which broke `COPY . .` once npm install got past it.
- documents/page.tsx had a real type error (selectedItem.file narrowing
  didn't survive into the .map() closure) that `next dev` never
  surfaced but `next build`'s stricter check does — fixed by hoisting
  the narrowed array into selectedFiles once instead of re-narrowing
  selectedItem.file at each use.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
2026-09-03 05:18:49 +00:00
ogrechkoandClaude Sonnet 5 2cb2bc0729 Run frontend in production mode instead of exposed npm run dev
next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted
rw was the entry point malware kept getting dropped through (see
prior commit). Now builds and runs `next start`; the bind mount is
gone so a compromised container can no longer write onto host disk.
Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via
the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/
55183 batch — the installed 15.1.6 was vulnerable to all of them and
is the likely actual initial-access vector.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
2026-09-03 04:32:29 +00:00
ogrechkoandClaude Sonnet 5 ee4562530a Remove malware planted via exposed dev-mode frontend
The frontend container ran `next dev` bound to 0.0.0.0:3000 with the
host source directory bind-mounted rw into it. Over months this let
attackers write files directly onto the host filesystem, which then
got swept into git by an unrelated Gitea ZIP restore. Removes 4 UPX-
packed ELF binaries and a defacement marker (cox.txt/html).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
2026-09-03 04:03:32 +00:00
ogrechko e9cd22d36f Add Django backend, Next.js frontend, and deploy templates 2026-08-27 15:38:31 +00:00