mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-26 02:06:49 +00:00
feat: RBAC, atomic deployments, fleet backups, and licensing (Pro) (#185)
* feat: add RBAC viewer accounts, atomic deployments, and fleet-wide backups (Pro) Introduces three Pro-tier features: - RBAC: Multi-user system with admin/viewer roles, user management UI, automatic migration from single-admin credentials, viewer restrictions across the entire UI (read-only editor, hidden action buttons) - Atomic Deployments: Pre-deploy file backup to .sencho-backup/, automatic rollback on health probe failure, manual rollback button, health probes added to stack updates, webhook-triggered deploys use atomic rollback - Fleet-Wide Backups: Point-in-time snapshots of compose files across all nodes (local + remote), stored centrally in SQLite, per-stack restore with optional redeploy, graceful handling of offline nodes * fix(settings): use correct ProGate prop name in UsersSection * fix(settings): remove unused isPro prop from UsersSection * fix(auth): fetch user info after login and setup so isAdmin is set correctly * feat(pricing): revise pricing strategy and enforce variant-based seat limits Raise Personal Pro from $49/yr to $69/yr with 3 viewer seats (up from 1). Add $15/mo billing option for Team Pro. Mark lifetime pricing as a 90-day early-adopter offer. Store Lemon Squeezy variant_name on activation/validation and enforce seat limits server-side per variant. * feat(licensing): add Lemon Squeezy checkout, webhook, and billing portal integration Server-side checkout URL generation (POST /api/checkout) with admin email pre-fill and instance_id custom data. HMAC-SHA256 verified webhook endpoint (POST /api/webhooks/lemonsqueezy) handling order, subscription, and payment lifecycle events for automatic license activation. Customer billing portal link stored from webhook events and exposed via GET /api/billing/portal. In-app checkout buttons in Settings with manual license key fallback. * fix(licensing): exempt Lemon Squeezy webhook from auth middleware The catch-all auth middleware on /api/* was blocking the public webhook endpoint. Added /webhooks/lemonsqueezy to the exemption list alongside /auth/* and /webhooks/:id/trigger. * feat(pricing): update pricing to final live rates Personal Pro: $7.99/month, $69.99/year, $249 lifetime. Team Pro: $49.99/month, $499.99/year, $1,499 lifetime. Added personal_monthly checkout variant across backend, frontend, and website. * refactor(licensing): remove server-side checkout/webhook for self-hosted model Sencho is self-hosted — each user runs their own instance, so there is no central server to receive webhooks or hold the store API key. Replaced in-app checkout buttons with a "View Pricing" redirect to sencho.io and kept manual license key activation as the primary flow. - Delete LemonSqueezyService (checkout, webhook, HMAC verification) - Remove POST /api/checkout, GET /api/billing/portal, POST /api/webhooks/lemonsqueezy - Remove raw body parser and auth exemption for webhook route - Remove all LEMONSQUEEZY_* env vars from .env.example - Replace checkout buttons in SettingsModal with single "View Pricing" button - Simplify LicenseContext checkout to open sencho.io pricing page - Update licensing docs to reflect website-based purchase flow * chore: normalize em-dashes to hyphens across codebase (linter) * chore: remove accidentally tracked directories from index
This commit is contained in:
+11
-11
@@ -1,9 +1,9 @@
|
||||
# Cross-compilation helper — provides xx-clang, xx-apk, etc.
|
||||
# Cross-compilation helper - provides xx-clang, xx-apk, etc.
|
||||
# Runs on the BUILD platform; its binaries are copied into build stages below.
|
||||
FROM --platform=$BUILDPLATFORM tonistiigi/xx AS xx
|
||||
|
||||
# Stage 1: Build Frontend
|
||||
# Runs on the BUILD platform (amd64) — frontend has no native modules so the
|
||||
# Runs on the BUILD platform (amd64) - frontend has no native modules so the
|
||||
# compiled output (JS/CSS/HTML) is entirely platform-agnostic.
|
||||
FROM --platform=$BUILDPLATFORM node:20-alpine AS frontend-builder
|
||||
|
||||
@@ -20,7 +20,7 @@ COPY package.json /app/package.json
|
||||
RUN npm run build
|
||||
|
||||
# Stage 2: Compile TypeScript
|
||||
# Runs on the BUILD platform (amd64) — tsc output is platform-agnostic JS.
|
||||
# Runs on the BUILD platform (amd64) - tsc output is platform-agnostic JS.
|
||||
FROM --platform=$BUILDPLATFORM node:20-alpine AS backend-builder
|
||||
|
||||
WORKDIR /app/backend
|
||||
@@ -35,7 +35,7 @@ RUN npm config set fetch-retry-maxtimeout 120000 && \
|
||||
COPY backend/ ./
|
||||
RUN npm run build
|
||||
|
||||
# Stage 3: Production dependencies (cross-compiled — NO QEMU execution)
|
||||
# Stage 3: Production dependencies (cross-compiled - NO QEMU execution)
|
||||
# Runs on the BUILD platform (amd64) but compiles native modules
|
||||
# (bcrypt, better-sqlite3, node-pty) for the TARGET platform using
|
||||
# tonistiigi/xx + clang as the cross-compiler.
|
||||
@@ -61,9 +61,9 @@ WORKDIR /app
|
||||
# Cross (TARGETARCH != BUILDARCH, e.g. amd64 → arm64):
|
||||
# xx-clang targets the foreign architecture without QEMU. The target sysroot
|
||||
# is populated via xx-apk:
|
||||
# g++ — libstdc++ headers/libs (all three native modules use C++)
|
||||
# musl-dev — musl libc headers for the target arch
|
||||
# linux-headers — <pty.h> / <termios.h> required by node-pty
|
||||
# g++ - libstdc++ headers/libs (all three native modules use C++)
|
||||
# musl-dev - musl libc headers for the target arch
|
||||
# linux-headers - <pty.h> / <termios.h> required by node-pty
|
||||
RUN if [ "$TARGETARCH" = "$BUILDARCH" ]; then \
|
||||
apk add --no-cache python3 make g++; \
|
||||
else \
|
||||
@@ -73,7 +73,7 @@ RUN if [ "$TARGETARCH" = "$BUILDARCH" ]; then \
|
||||
|
||||
COPY backend/package*.json backend/.npmrc ./
|
||||
|
||||
# Native: plain npm ci — g++ compiles native modules for the host arch.
|
||||
# Native: plain npm ci - g++ compiles native modules for the host arch.
|
||||
# Cross: npm_config_arch tells prebuild-install/node-pre-gyp which pre-built
|
||||
# binary to attempt; CC/CXX/AR route compilation through xx-clang so
|
||||
# the output targets the foreign arch without any QEMU emulation.
|
||||
@@ -88,7 +88,7 @@ RUN if [ "$TARGETARCH" = "$BUILDARCH" ]; then \
|
||||
fi
|
||||
|
||||
# Stage 4: Production runtime
|
||||
# Runs on the TARGET platform — no compilation happens here.
|
||||
# Runs on the TARGET platform - no compilation happens here.
|
||||
FROM node:20-alpine
|
||||
|
||||
# Install Docker CLI, Docker Compose CLI, and Bash for Host Console
|
||||
@@ -123,7 +123,7 @@ RUN addgroup -S sencho && adduser -S -G sencho sencho \
|
||||
#
|
||||
# NOTE: USER directive is intentionally absent here. The entrypoint starts as
|
||||
# root so it can chown the mounted data volume, then exec's as sencho. Static
|
||||
# security scanners (Trivy, Clair) may flag "running as root" — this is a known
|
||||
# security scanners (Trivy, Clair) may flag "running as root" - this is a known
|
||||
# and accepted trade-off for self-hosted apps with user-supplied volume mounts.
|
||||
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
||||
# Strip Windows CRLF line endings that can sneak in on Windows dev machines
|
||||
@@ -135,7 +135,7 @@ RUN sed -i 's/\r//' /usr/local/bin/docker-entrypoint.sh \
|
||||
# Expose port
|
||||
EXPOSE 3000
|
||||
|
||||
# Health check — polls the public /api/health endpoint every 30s
|
||||
# Health check - polls the public /api/health endpoint every 30s
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
|
||||
CMD node -e "const h=require('http');h.get('http://localhost:3000/api/health',r=>{process.exit(r.statusCode===200?0:1)}).on('error',()=>process.exit(1))"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user