fix(demo): never leak the release-server IP in the public demo
Demo images / Build & push demo images (push) Failing after 5m0s
Demo images / Build & push demo images (push) Failing after 5m0s
- Companion QR overlay: demo builds encode the demo's own origin (/packages/archipelago-companion.apk ships in the web image) instead of the vps2 raw URL. - Dockerfile.web/.backend: build-time scrub replaces every remaining occurrence of the release-server address with registry.demo.internal and fails the build if any survives. - Mock backend update-mirror list, sideload help text, and changelog prose no longer name the server address. - Copy demo-images workflow into .gitea/workflows/ — Gitea ignores .github/workflows when .gitea/workflows exists, so the CI never ran. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
ad3dae9983
commit
79564486d3
@@ -3561,7 +3561,8 @@ app.post('/rpc/v1', (req, res) => {
|
||||
|
||||
case 'update.list-mirrors': {
|
||||
globalThis.__mockMirrors ||= [
|
||||
{ url: 'http://146.59.87.168:3000/lfg2025/archy/raw/branch/main/releases/manifest.json', label: 'Origin (vps2)' },
|
||||
// Neutral placeholder — the public demo must not reveal the real release-server address.
|
||||
{ url: 'https://updates.archipelago.demo/releases/manifest.json', label: 'Origin' },
|
||||
]
|
||||
return res.json({ result: { mirrors: globalThis.__mockMirrors } })
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user