# ============================================================
# All-in-one: Asterisk 22 + Node bridge/dashboard — BYTECODE-PROTECTED.
#
# Two stages, both built from the SAME `base` stage so the Node/V8 build
# is byte-identical between compile time and run time (V8 bytecode only
# runs on the exact V8 it was compiled with):
#   builder — has the .js source, compiles it to .jsc, deletes the .js
#   runtime — receives /app from builder: bytecode only, no source
#
# Ship ONLY the built image (docker save/load). Never ship this folder.
# ============================================================
FROM andrius/asterisk:22 AS base

# Node 20 (NodeSource) + Python/build deps for native node modules + sphn
RUN apt-get update && apt-get install -y ca-certificates curl gnupg bash jq procps python3 python3-pip make g++ ffmpeg iputils-ping \
    && mkdir -p /etc/apt/keyrings \
    && curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg \
    && echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_20.x nodistro main" > /etc/apt/sources.list.d/nodesource.list \
    && apt-get update && apt-get install -y nodejs \
    && rm -rf /var/lib/apt/lists/*

RUN pip3 install sphn==0.1.12 numpy dashscope openai --break-system-packages

# ---- builder: source enters, bytecode leaves --------------------------------
FROM base AS builder
# shc (shell->binary compiler) isn't packaged for this base — build it from a
# pinned source release so the shell scripts can be compiled, not shipped raw.
RUN apt-get update && apt-get install -y autoconf automake libtool \
    && curl -fsSL https://github.com/neurobin/shc/archive/refs/tags/4.0.3.tar.gz | tar xz -C /tmp \
    && cd /tmp/shc-4.0.3 && ./autogen.sh && ./configure && make && make install \
    && rm -rf /tmp/shc-4.0.3 && rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY package*.json ./
RUN npm install --build-from-source && npm install bytenode@1.5.6 javascript-obfuscator@4.1.1
COPY . .
# index.js + src/*.js -> .jsc, sources deleted; compiler itself removed after
RUN node compile.js && rm -f compile.js \
    && ! find /app -maxdepth 2 -name '*.js' -not -path '*/node_modules/*' -not -path '*/public/*' -not -name loader.js -not -name certdec.js | grep -q . \
    || (echo 'ERROR: source .js survived the compile step' && exit 1)

# Protect the non-JS source too (everything except the browser HTML):
#   Python engine -> .pyc bytecode  |  shell scripts -> compiled binaries (shc)
RUN python3 -m py_compile transcribe/live_correction_test.py \
    && mv transcribe/__pycache__/live_correction_test.*.pyc transcribe/live_correction_test.pyc \
    && rm -rf transcribe/__pycache__ transcribe/live_correction_test.py \
    && shc -r -f start.sh -o start && shc -r -f manage-extensions.sh -o manage-extensions \
    && shc -r -f ip-sync.sh -o ip-sync \
    && chmod +x start manage-extensions ip-sync \
    && rm -f start.sh manage-extensions.sh ip-sync.sh start.sh.x.c manage-extensions.sh.x.c ip-sync.sh.x.c \
    && ! find /app -maxdepth 2 \( -name '*.py' -o -name '*.sh' \) -not -path '*/node_modules/*' | grep -q . \
    || (echo 'ERROR: python/shell source survived compilation' && exit 1)

# ---- runtime: no .js application source exists in this image ----------------
FROM base
WORKDIR /app
COPY --from=builder /app /app

RUN cp /app/manage-extensions /usr/local/bin/manage-extensions \
    && chmod +x /usr/local/bin/manage-extensions /app/start \
    # Stock-image sample configs we never use — they only generate boot
    # warnings (AEL macro spam, users.conf deprecation notice)
    && rm -f /etc/asterisk/extensions.ael /etc/asterisk/users.conf /etc/asterisk/extensions.lua

ENTRYPOINT []
CMD ["/app/start"]
