Files
sap-erp/PUBLISH-GUIDE.md
T
John 69b4e68baf
SAP-ERP Portal CI/CD / build (push) Failing after 5m20s
first commit
2026-09-23 17:31:02 +05:30

205 lines
8.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# SAP-ERP Portal — Publishing Guide (Local Windows Server)
How to run this portal permanently on a local Windows machine so everyone on
your network can use it, it starts automatically with Windows, and restarts
itself if it ever crashes. No extra software is needed beyond Node.js —
everything uses built-in Windows features (Task Scheduler).
---
## 1. What you are deploying
| Piece | What it is |
|---|---|
| `server.js` | The Node/Express app — serves the web UI (`public/`) **and** all APIs on **port 5000** |
| `.env` | ALL configuration: SQL Server, SAP Service Layer, company DB, JWT secret, port |
| `services/SapDiConsole/` | Compiled DI-API console exe (Purchase Requests). Built once with `build.bat` |
| `deploy/` | The publish scripts described below |
| `logs/` | Created automatically — server output + supervisor log |
The app needs live network access to the **SQL Server** (`192.9.205.132:1433`)
and the **SAP Service Layer** (`https://192.9.205.132:50000`), and the SAP
**DI API v10.00.331** installed locally for the Purchase Request feature.
---
## 2. One-time setup on the server machine
1. **Install Node.js LTS** (v18 or newer) from https://nodejs.org — use the
default installer options ("Add to PATH" must stay ticked, it is by default).
Verify in a new Command Prompt: `node -v`
2. **Copy the whole project folder** to its permanent home, e.g. `D:\sap-erp`
*(scripts work from any folder — they always operate on their own parent folder)*.
3. **Install dependencies** (only needed if `node_modules` was not copied):
```bat
cd /d D:\sap-erp
npm install
```
4. **Configure `.env`** — copy it from the current machine or review every key
(SQL host/user/password, `SAP_B1_SERVER`, `SAP_B1_COMPANY`, `SAP_B1_USER`/`PASSWORD`,
`JWT_SECRET`, optional `PORT`). **Never commit or share this file — it holds passwords.**
5. **Build the DI console** (Purchase Requests) if `services\SapDiConsole\bin\Release\net472\SapDiConsole.exe`
doesn't exist yet:
```bat
cd /d D:\sap-erp\services\SapDiConsole
build.bat
```
Requires the SAP B1 **DI API (build ≥ 331)** installed on this machine.
6. **Open the firewall** so other PCs can reach the portal
*(right-click → Run as administrator)*:
```bat
deploy\open-firewall.bat
```
7. **Test it manually first** — double-click `deploy\start-server.bat`.
A console window opens; browse to **http://localhost:5000** and log in.
Close the window when done testing (or leave it — step 3 below replaces it).
---
## 3. Publish — auto-start with Windows
Right-click → **Run as administrator**:
```bat
deploy\install-autostart.bat
```
This registers a Task-Scheduler task **"SAP-ERP-Portal"** that:
- starts the portal **at every Windows boot** (no user login needed, runs as SYSTEM),
- runs it **hidden** (no console window),
- and because the task runs the **supervisor loop**, the server is
**restarted automatically within 5 seconds** if it ever crashes.
It also starts the portal immediately, so you're live as soon as it finishes.
---
## 4. Daily operations
| Action | How |
|---|---|
| Check it's running | `deploy\status.bat` |
| Stop | `deploy\stop-server.bat` |
| Start (background) | `schtasks /Run /TN "SAP-ERP-Portal"` — or reboot |
| Start (visible console, for debugging) | `deploy\start-server.bat` |
| View logs | `logs\server.log` (app output) · `logs\supervisor.log` (start/crash history) |
| Remove autostart | `deploy\uninstall-autostart.bat` *(as administrator)* |
**Users access the portal at:** `http://<server-ip>:5000`
(find the IP with `ipconfig` — give users that address, e.g. `http://192.9.205.50:5000`).
Optionally add a DNS/hosts entry like `erp.mitra.local` pointing to that IP.
---
## 5. Updating the application
1. `deploy\stop-server.bat`
2. Copy the new/changed files over the folder (keep your `.env`!)
3. If `package.json` changed: `npm install`
4. If `services/SapDiConsole` changed: re-run its `build.bat`
5. `schtasks /Run /TN "SAP-ERP-Portal"` (or reboot)
6. Users press **Ctrl+F5** in the browser once (pages are cache-busted, but a
hard refresh guarantees the newest files)
---
## 6. Changing the port (e.g. if 5000 is taken)
1. Add to `.env`:
```
PORT=8080
```
(any free port — check with `netstat -ano | findstr :8080` that nothing is on it)
2. Re-run `deploy\open-firewall.bat` *(as administrator)* — it **reads the port
from `.env` automatically** and replaces the old rule.
3. Restart the portal (`deploy\stop-server.bat`, then `schtasks /Run /TN "SAP-ERP-Portal"`).
`deploy\status.bat` also reads the port from `.env`, so it always checks the
right one. Users then browse to `http://<server-ip>:8080`.
---
## 7. Troubleshooting
| Symptom | Check |
|---|---|
| Page won't open from another PC but works on the server | Firewall — re-run `deploy\open-firewall.bat`; confirm with `deploy\status.bat` that port 5000 is LISTENING |
| "NOT RUNNING" in status | `logs\server.log` tail — usually a bad `.env` value (SQL/SAP unreachable) or port already in use |
| Starts then dies repeatedly | `logs\supervisor.log` shows exit codes; fix the cause in `logs\server.log` — the loop keeps retrying every 5 s |
| Task exists but nothing runs after reboot | Node not on the SYSTEM PATH — reinstall Node.js with defaults, or edit `deploy\start-server.bat` to use the full path `"C:\Program Files\nodejs\node.exe"` |
| Purchase Request errors (DI API) | DI API build must be ≥ 331 and `Interop.SAPbobsCOM.dll` regenerated — see the comment inside `services\SapDiConsole\build.bat` |
| SAP/SQL password changed | Update `.env`, then stop + start the portal |
---
## 8. Compiled deployment — ship NO source code to the server (recommended)
Instead of copying the project, build a **dist** package on your development
machine and copy only that. The server then holds no readable source and no
`node_modules` at all.
On the **development machine**:
```bat
deploy\build-dist.bat
```
This produces `dist\` containing only:
| | |
|---|---|
| `server.js` | the ENTIRE backend (server + routes + services + all npm packages) bundled & minified into one ~4 MB file — variable names crushed, comments stripped, no project structure |
| `public\` | the frontend (browsers download this anyway) |
| `deploy\` | the run/install scripts from section 3–4 |
| `SapDiConsole\…` + `sap-di-pr.ps1` | the DI-API console for Purchase Requests |
| `uploads\`, `logs\` | empty runtime folders |
Then on the **server**:
1. Copy the **contents of `dist\`** to the app folder (e.g. `D:\sap-erp-portal`)
2. Place the real **`.env`** there (it is deliberately never part of the build)
3. Run `deploy\open-firewall.bat` and `deploy\install-autostart.bat` as admin — same as section 3
4. Only **Node.js** needs to be installed on the server — **no `npm install`, no node_modules**
**Updating:** rebuild on the dev machine, stop the portal, copy the new
`dist\server.js` (and `public\` if the frontend changed) over, start again.
**Honest limits:** minified JS deters reading and copying but is not
encryption — combine it with `deploy\protect-folder.bat` (section 9) and a
short server-admin list for real protection. The `.env` is still plain text
on the server; the ACL lock is what protects it.
## 9. Protecting the source code & passwords on the server
**Browser users can never see the backend.** Express serves only `public/` and
API responses — `server.js`, `routes/`, `services/` and `.env` are unreachable
over the network. (Frontend HTML/JS is visible in every web app by nature.)
**The real risk is people who log into the server machine** — they could open
the folder and read the code and, worse, the passwords in `.env`. Protect it:
1. Run *(as administrator)*:
```bat
deploy\protect-folder.bat
```
This strips folder permissions down to **SYSTEM + Administrators** only.
Standard Windows users on the machine get "Access denied", while the portal
keeps running because its scheduled task runs as SYSTEM.
Undo anytime: `icacls "<app folder>" /reset /T`
2. **Don't hand out admin/RDP access** to the server — that is the actual
security boundary. Anyone who is a Windows *administrator* on the box can
always get to the files, no tool can prevent that.
3. Use the **compiled deployment** (section 8) so no readable source is on the
server in the first place.
## 10. Good practices
- **Back up** `.env` and the app DB (`SAP-ERP` database on the SQL server) regularly.
- Keep the server on a **UPS** and set Windows power settings to never sleep.
- The `logs\` folder grows over time — delete or archive old logs occasionally.