Windows/IIS install fixes found by validating on a real win11 VM
Deployed to win11 + IIS + MySQL 5.6 end to end; fixed what broke.
- requirements.txt: add tzdata. Windows has no IANA tz database, so
ZoneInfo('America/New_York') (notifications recognition/recert) fails and the
plugin won't import. Also confirmed waitress (added earlier) is required.
- deploy/windows/web.config: comment out the X-Forwarded-For <rewrite> block by
default - it needs URL Rewrite, and with it active but the module absent IIS
returns HTTP 500.19. Uncomment after installing URL Rewrite.
- docs/DEPLOY-WINDOWS-IIS.md: add the required `appcmd unlock config` step for
system.webServer/handlers + httpPlatform (locked server-wide by default ->
500.19 without it) and the app-pool icacls grant.
Verified: IIS -> HttpPlatformHandler -> waitress -> app on :8090, all plugins
load, admin login works.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -138,12 +138,21 @@ to reproduce the exact enabled set, then just run `flask plugin upgrade-all`.)
|
||||
`waitress-serve --port=%HTTP_PLATFORM_PORT% wsgi:app` and sets
|
||||
`FLASK_ENV=production` + `PYTHONPATH`.
|
||||
3. Create `APP_ROOT\logs` for the HttpPlatform stdout log.
|
||||
4. Recycle the app pool / restart the site.
|
||||
4. **Unlock the handler sections** (locked server-wide by default; without this
|
||||
IIS returns **HTTP 500.19** "section cannot be used at this path"):
|
||||
```powershell
|
||||
%windir%\system32\inetsrv\appcmd unlock config /section:system.webServer/handlers
|
||||
%windir%\system32\inetsrv\appcmd unlock config /section:system.webServer/httpPlatform
|
||||
```
|
||||
5. Grant the app-pool identity read/execute on `APP_ROOT` and modify on
|
||||
`APP_ROOT\logs` (e.g. `icacls APP_ROOT /grant "IIS AppPool\<pool>:(OI)(CI)RX" /T`).
|
||||
6. Recycle the app pool / restart the site.
|
||||
|
||||
TLS terminates at the IIS binding. The optional URL Rewrite rule in the
|
||||
web.config sets `X-Forwarded-For` to the real client IP (HttpPlatformHandler
|
||||
otherwise forwards from loopback, so audit logs and the kiosk visitor-location
|
||||
feature would see 127.0.0.1). Drop that block if URL Rewrite is not installed.
|
||||
TLS terminates at the IIS binding. The `X-Forwarded-For` URL Rewrite rule in the
|
||||
web.config (real client IP for audit logs / kiosk visitor-location) is
|
||||
**commented out by default** because it needs the URL Rewrite module - with it
|
||||
active but URL Rewrite absent, IIS returns HTTP 500.19. Install URL Rewrite and
|
||||
uncomment the `<rewrite>` block to enable it.
|
||||
|
||||
## 7. Smoke test
|
||||
|
||||
|
||||
Reference in New Issue
Block a user