Files
sap-erp/PUBLISH-GUIDE.md
T
John 69b4e68baf
SAP-ERP Portal CI/CD / build (push) Failing after 5m20s
first commit
2026-09-23 17:31:02 +05:30

8.5 KiB
Raw Blame History

SAP-ERP Portal — Publishing Guide (Local Windows Server)

How to run this portal permanently on a local Windows machine so everyone on your network can use it, it starts automatically with Windows, and restarts itself if it ever crashes. No extra software is needed beyond Node.js — everything uses built-in Windows features (Task Scheduler).


1. What you are deploying

Piece What it is
server.js The Node/Express app — serves the web UI (public/) and all APIs on port 5000
.env ALL configuration: SQL Server, SAP Service Layer, company DB, JWT secret, port
services/SapDiConsole/ Compiled DI-API console exe (Purchase Requests). Built once with build.bat
deploy/ The publish scripts described below
logs/ Created automatically — server output + supervisor log

The app needs live network access to the SQL Server (192.9.205.132:1433) and the SAP Service Layer (https://192.9.205.132:50000), and the SAP DI API v10.00.331 installed locally for the Purchase Request feature.


2. One-time setup on the server machine

  1. Install Node.js LTS (v18 or newer) from https://nodejs.org — use the default installer options ("Add to PATH" must stay ticked, it is by default). Verify in a new Command Prompt: node -v

  2. Copy the whole project folder to its permanent home, e.g. D:\sap-erp (scripts work from any folder — they always operate on their own parent folder).

  3. Install dependencies (only needed if node_modules was not copied):

    cd /d D:\sap-erp
    npm install
    
  4. Configure .env — copy it from the current machine or review every key (SQL host/user/password, SAP_B1_SERVER, SAP_B1_COMPANY, SAP_B1_USER/PASSWORD, JWT_SECRET, optional PORT). Never commit or share this file — it holds passwords.

  5. Build the DI console (Purchase Requests) if services\SapDiConsole\bin\Release\net472\SapDiConsole.exe doesn't exist yet:

    cd /d D:\sap-erp\services\SapDiConsole
    build.bat
    

    Requires the SAP B1 DI API (build ≥ 331) installed on this machine.

  6. Open the firewall so other PCs can reach the portal (right-click → Run as administrator):

    deploy\open-firewall.bat
    
  7. Test it manually first — double-click deploy\start-server.bat. A console window opens; browse to http://localhost:5000 and log in. Close the window when done testing (or leave it — step 3 below replaces it).


3. Publish — auto-start with Windows

Right-click → Run as administrator:

deploy\install-autostart.bat

This registers a Task-Scheduler task "SAP-ERP-Portal" that:

  • starts the portal at every Windows boot (no user login needed, runs as SYSTEM),
  • runs it hidden (no console window),
  • and because the task runs the supervisor loop, the server is restarted automatically within 5 seconds if it ever crashes.

It also starts the portal immediately, so you're live as soon as it finishes.


4. Daily operations

Action How
Check it's running deploy\status.bat
Stop deploy\stop-server.bat
Start (background) schtasks /Run /TN "SAP-ERP-Portal" — or reboot
Start (visible console, for debugging) deploy\start-server.bat
View logs logs\server.log (app output) · logs\supervisor.log (start/crash history)
Remove autostart deploy\uninstall-autostart.bat (as administrator)

Users access the portal at: http://<server-ip>:5000 (find the IP with ipconfig — give users that address, e.g. http://192.9.205.50:5000). Optionally add a DNS/hosts entry like erp.mitra.local pointing to that IP.


5. Updating the application

  1. deploy\stop-server.bat
  2. Copy the new/changed files over the folder (keep your .env!)
  3. If package.json changed: npm install
  4. If services/SapDiConsole changed: re-run its build.bat
  5. schtasks /Run /TN "SAP-ERP-Portal" (or reboot)
  6. Users press Ctrl+F5 in the browser once (pages are cache-busted, but a hard refresh guarantees the newest files)

6. Changing the port (e.g. if 5000 is taken)

  1. Add to .env:
    PORT=8080
    
    (any free port — check with netstat -ano | findstr :8080 that nothing is on it)
  2. Re-run deploy\open-firewall.bat (as administrator) — it reads the port from .env automatically and replaces the old rule.
  3. Restart the portal (deploy\stop-server.bat, then schtasks /Run /TN "SAP-ERP-Portal").

deploy\status.bat also reads the port from .env, so it always checks the right one. Users then browse to http://<server-ip>:8080.


7. Troubleshooting

Symptom Check
Page won't open from another PC but works on the server Firewall — re-run deploy\open-firewall.bat; confirm with deploy\status.bat that port 5000 is LISTENING
"NOT RUNNING" in status logs\server.log tail — usually a bad .env value (SQL/SAP unreachable) or port already in use
Starts then dies repeatedly logs\supervisor.log shows exit codes; fix the cause in logs\server.log — the loop keeps retrying every 5 s
Task exists but nothing runs after reboot Node not on the SYSTEM PATH — reinstall Node.js with defaults, or edit deploy\start-server.bat to use the full path "C:\Program Files\nodejs\node.exe"
Purchase Request errors (DI API) DI API build must be ≥ 331 and Interop.SAPbobsCOM.dll regenerated — see the comment inside services\SapDiConsole\build.bat
SAP/SQL password changed Update .env, then stop + start the portal

Instead of copying the project, build a dist package on your development machine and copy only that. The server then holds no readable source and no node_modules at all.

On the development machine:

deploy\build-dist.bat

This produces dist\ containing only:

server.js the ENTIRE backend (server + routes + services + all npm packages) bundled & minified into one ~4 MB file — variable names crushed, comments stripped, no project structure
public\ the frontend (browsers download this anyway)
deploy\ the run/install scripts from section 3–4
SapDiConsole\… + sap-di-pr.ps1 the DI-API console for Purchase Requests
uploads\, logs\ empty runtime folders

Then on the server:

  1. Copy the contents of dist\ to the app folder (e.g. D:\sap-erp-portal)
  2. Place the real .env there (it is deliberately never part of the build)
  3. Run deploy\open-firewall.bat and deploy\install-autostart.bat as admin — same as section 3
  4. Only Node.js needs to be installed on the server — no npm install, no node_modules

Updating: rebuild on the dev machine, stop the portal, copy the new dist\server.js (and public\ if the frontend changed) over, start again.

Honest limits: minified JS deters reading and copying but is not encryption — combine it with deploy\protect-folder.bat (section 9) and a short server-admin list for real protection. The .env is still plain text on the server; the ACL lock is what protects it.

9. Protecting the source code & passwords on the server

Browser users can never see the backend. Express serves only public/ and API responses — server.js, routes/, services/ and .env are unreachable over the network. (Frontend HTML/JS is visible in every web app by nature.)

The real risk is people who log into the server machine — they could open the folder and read the code and, worse, the passwords in .env. Protect it:

  1. Run (as administrator):

    deploy\protect-folder.bat
    

    This strips folder permissions down to SYSTEM + Administrators only. Standard Windows users on the machine get "Access denied", while the portal keeps running because its scheduled task runs as SYSTEM. Undo anytime: icacls "<app folder>" /reset /T

  2. Don't hand out admin/RDP access to the server — that is the actual security boundary. Anyone who is a Windows administrator on the box can always get to the files, no tool can prevent that.

  3. Use the compiled deployment (section 8) so no readable source is on the server in the first place.

10. Good practices

  • Back up .env and the app DB (SAP-ERP database on the SQL server) regularly.
  • Keep the server on a UPS and set Windows power settings to never sleep.
  • The logs\ folder grows over time — delete or archive old logs occasionally.