diff --git a/setup_server.py b/setup_server.py index 9ad631c..d50c18f 100644 --- a/setup_server.py +++ b/setup_server.py @@ -356,25 +356,36 @@ def install(data): chown(integ_path) log("integrations.json creato") - # 5. modules.json - mods = APP_DIR / "config/modules.json.example" - if mods.exists(): - shutil.copy(mods, CONFIG_DIR / "modules.json") - chown(CONFIG_DIR / "modules.json") - log("modules.json copiato") - - # 5b. File .example aggiuntivi (config sezioni recenti) - # - automations.json: config feed TI sources + cron daemon TI - # - siem_integrations.json: catalogo SIEM Integration Builder - # - subnet_registry.json: mapping sede/reparto da subnet - for stem in ("automations", "siem_integrations", "subnet_registry"): - src = APP_DIR / f"config/{stem}.json.example" - dst = CONFIG_DIR / f"{stem}.json" - if src.exists() and not dst.exists(): - shutil.copy(src, dst) - os.chmod(dst, 0o640) - chown(dst) - log(f"{stem}.json copiato da template") + # 5. Config da template .example (glob-driven, idempotente). + # + # Copia OGNI config/.json.example presente nel repo in + # config/.json, SOLO se la destinazione non esiste gia' + # (mai clobber su re-run / re-install). + # + # Fonte di verita': i .example versionati nel repo argos. Aggiungere + # un nuovo file config = aggiungere il suo .example, senza toccare + # questo installer. Allineato a backend/blueprints/backup.py + # ALLOWED_FILES (provider_*, soar_*, siem_integrations, ...). + # + # Skip dei file GENERATI altrove in questo install(): + # argos.json -> step 3 (generate_argos_json) + # integrations.json -> step 4 (generate_integrations_json + pdf) + # argos_users.json -> step 9 (create_admin_user) — copiarlo qui + # inietterebbe utenti d'esempio prima dell'admin. + # File con segreti -> chmod 600 (gli altri 640). + _GENERATED = {"argos.json", "integrations.json", "argos_users.json"} + _SECRET = {"provider_credentials.json", "soar_credentials.json"} + for src in sorted((APP_DIR / "config").glob("*.json.example")): + name = src.name[:-len(".example")] # foo.json.example -> foo.json + if name in _GENERATED: + continue + dst = CONFIG_DIR / name + if dst.exists(): + continue + shutil.copy(src, dst) + os.chmod(dst, 0o600 if name in _SECRET else 0o640) + chown(dst) + log(f"{name} copiato da template") # 6. Logo cliente logo_src = SETUP_DIR / "logo_cliente.png"