2cb2bc07298b3ba86e638b70142b0b8175cf595c
next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted rw was the entry point malware kept getting dropped through (see prior commit). Now builds and runs `next start`; the bind mount is gone so a compromised container can no longer write onto host disk. Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/ 55183 batch — the installed 15.1.6 was vulnerable to all of them and is the likely actual initial-access vector. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
KKPAB Site
Modernized rebuild of kkpab26.ru using:
- Django + Django REST Framework for content management API
- Next.js for the public website
- PostgreSQL for production data
- Nginx for reverse proxy and static/media delivery
Structure
backend/Django API and adminfrontend/Next.js public websitedeploy/deployment templates
Local setup
Backend
cd backend
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
python manage.py migrate
python manage.py loaddata content/fixtures/initial_data.json
python manage.py createsuperuser
python manage.py runserver 0.0.0.0:7788
Frontend
cd frontend
npm install
cp .env.local.example .env.local
npm run dev
Frontend expects API at http://localhost:7788/api.
Production notes
- build frontend with
npm run build - run Django with
gunicorn - route
/api,/admin,/media,/staticto Django - route
/to Next.js
Languages
Rich Text Format
67.6%
TypeScript
17.6%
Python
8.2%
CSS
6.2%
Dockerfile
0.4%