diff --git a/bitnami/matomo/5/debian-12/Dockerfile b/bitnami/matomo/5/debian-12/Dockerfile index 01d06fd4482f..be816ed39e77 100644 --- a/bitnami/matomo/5/debian-12/Dockerfile +++ b/bitnami/matomo/5/debian-12/Dockerfile @@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith" ARG TARGETARCH LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \ - org.opencontainers.image.created="2026-05-23T09:21:49Z" \ + org.opencontainers.image.created="2026-05-26T09:25:04Z" \ org.opencontainers.image.description="Application packaged by Broadcom, Inc." \ org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/matomo/README.md" \ org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/matomo" \ @@ -62,7 +62,7 @@ ENV APACHE_HTTPS_PORT_NUMBER="" \ APACHE_HTTP_PORT_NUMBER="" \ APP_VERSION="5.10.0" \ BITNAMI_APP_NAME="matomo" \ - IMAGE_REVISION="7" \ + IMAGE_REVISION="8" \ LD_LIBRARY_PATH="/opt/bitnami/postgresql/lib:$LD_LIBRARY_PATH" \ PATH="/opt/bitnami/common/bin:/opt/bitnami/php/bin:/opt/bitnami/php/sbin:/opt/bitnami/apache/bin:/opt/bitnami/mysql/bin:$PATH" diff --git a/bitnami/matomo/5/debian-12/docker-compose.yml b/bitnami/matomo/5/debian-12/docker-compose.yml index 334db7e6b7b1..0ea0235b0622 100644 --- a/bitnami/matomo/5/debian-12/docker-compose.yml +++ b/bitnami/matomo/5/debian-12/docker-compose.yml @@ -20,6 +20,7 @@ services: - "80:8080" - "443:8443" environment: + - MATOMO_PASSWORD=bitnami - MATOMO_DATABASE_HOST=mariadb - MATOMO_DATABASE_PORT_NUMBER=3306 - MATOMO_DATABASE_USER=bn_matomo diff --git a/bitnami/matomo/5/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh b/bitnami/matomo/5/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh index 1c69e0e48a5d..335c1c7c9ef7 100644 --- a/bitnami/matomo/5/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh +++ b/bitnami/matomo/5/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh @@ -139,3 +139,40 @@ wait_for_log_entry() { return 1 fi } + +######################## +# Creates a secure temporary file containing the provided secret +# Arguments: +# $1 - secret to write to the temporary file +# Returns: +# String +######################### +credential_to_temp_file() { + local secret="$1" + local tmp_file + + # Use mktemp with a specific prefix for easier debugging if something lingers + if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then + echo "Error: Failed to create temp file" >&2 + return 1 + fi + + # Restrict permissions before writing the secret + chmod 0600 "$tmp_file" + # Write secret and ensure it's flushed to disk + printf "%s" "$secret" > "$tmp_file" + # Output the filename so the caller can capture it + echo "$tmp_file" +} + +######################## +# Cleans up temporary files created by credential_to_temp_file +# Arguments: +# None +# Returns: +# None +######################### +cleanup_credentials() { + debug "Cleaning up temporary files containing credentials" + rm -rf "${TMPDIR:-/tmp}"/at.cred.* +} diff --git a/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmatomo.sh b/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmatomo.sh index c8bdddada036..f1344255dcdb 100644 --- a/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmatomo.sh +++ b/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmatomo.sh @@ -41,6 +41,11 @@ matomo_validate() { error "$1" error_code=1 } + check_empty_value() { + if is_empty_value "${!1}"; then + print_validation_error "${1} must be set" + fi + } check_yes_no_value() { if ! is_yes_no_value "${!1}" && ! is_true_false_value "${!1}"; then print_validation_error "The allowed values for ${1} are: yes no" @@ -51,7 +56,6 @@ matomo_validate() { print_validation_error "The allowed values for ${1} are: ${2}" fi } - check_valid_port() { local port_var="${1:?missing port variable}" local err @@ -61,12 +65,11 @@ matomo_validate() { } # Validate credentials + check_empty_value "MATOMO_PASSWORD" if is_boolean_yes "$ALLOW_EMPTY_PASSWORD"; then warn "You set the environment variable ALLOW_EMPTY_PASSWORD=${ALLOW_EMPTY_PASSWORD}. For safety reasons, do not use this flag in a production environment." else - for empty_env_var in "MATOMO_DATABASE_PASSWORD" "MATOMO_PASSWORD"; do - is_empty_value "${!empty_env_var}" && print_validation_error "The ${empty_env_var} environment variable is empty or not set. Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow a blank password. This is only recommended for development environments." - done + is_empty_value "${MATOMO_DATABASE_PASSWORD}" && print_validation_error "The MATOMO_DATABASE_PASSWORD environment variable is empty or not set. Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow a blank password. This is only recommended for development environments." fi # Check yes no values @@ -79,7 +82,7 @@ matomo_validate() { for empty_env_var in "MATOMO_SMTP_USER" "MATOMO_SMTP_PASSWORD"; do is_empty_value "${!empty_env_var}" && warn "The ${empty_env_var} environment variable is empty or not set." done - is_empty_value "$MATOMO_SMTP_PORT_NUMBER" && print_validation_error "The MATOMO_SMTP_PORT_NUMBER environment variable is empty or not set." + check_empty_value "MATOMO_SMTP_PORT_NUMBER" ! is_empty_value "$MATOMO_SMTP_PORT_NUMBER" && check_valid_port "MATOMO_SMTP_PORT_NUMBER" ! is_empty_value "$MATOMO_SMTP_PROTOCOL" && check_multi_value "MATOMO_SMTP_PROTOCOL" "ssl tls none" ! is_empty_value "$MATOMO_SMTP_AUTH" && check_multi_value "MATOMO_SMTP_AUTH" "Plain Login Cram-md5" diff --git a/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmysqlclient.sh b/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmysqlclient.sh index c096f4d1e1c1..054084de6928 100644 --- a/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmysqlclient.sh +++ b/bitnami/matomo/5/debian-12/rootfs/opt/bitnami/scripts/libmysqlclient.sh @@ -263,7 +263,12 @@ mysql_execute_print_output() { fi args+=("-N" "-u" "$user") [[ -n "$db" ]] && args+=("$db") - [[ -n "$pass" ]] && args+=("-p$pass") + # Avoid passing credentials as arguments to mysql, to avoid leaking them given a local observer with /proc read access can read them + if [[ -n "$pass" ]]; then + local pass_file + pass_file="$(credential_to_temp_file "$pass")" + args+=("-p$(<"$pass_file")") + fi [[ "${#opts[@]}" -gt 0 ]] && args+=("${opts[@]}") [[ "${#extra_opts[@]}" -gt 0 ]] && args+=("${extra_opts[@]}") @@ -271,7 +276,6 @@ mysql_execute_print_output() { if [[ "${BITNAMI_DEBUG:-false}" = true ]]; then local mysql_cmd mysql_cmd="$(