> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# 開発ツールのセットアップ

## 推奨開発ツール

これらのオプションサービスは Overleaf の実行には必須ではありませんが、ローカル開発時の開発・デバッグ・調査に強く推奨されます。

* **Hoppscotch** は Postman に似た軽量の API テストツールで、ブラウザベースのため開発に非常に便利です。
  * フロントエンド: [http://localhost:3000](http://localhost:3000/)
  * プロキシ(CORS 回避用): [http://localhost:9159](http://localhost:9159/)
* **RedisInsight** は Redis のデータを確認するためのビジュアルインターフェースを提供します。UI のアドレス: [http://localhost:5540](http://localhost:5540/)
* **Mongo Express** は MongoDB 用の Web ベース UI です。[http://localhost:8081](http://localhost:8081/) にアクセスし、**認証情報** `admin:pass` でログインできます。

`docker-compose.yml` に以下を追加してください。

<Accordion title="develop/docker-compose.yml">
  ```yml title="develop/docker-compose.yml" theme={null}
  # services: 
    # Overleaf Dev Containers
    # ...
    
    # Add those for your development
    # API debug
    hoppscotch-frontend:
      image: hoppscotch/hoppscotch-frontend:latest
      ports:
        - "3000:3000"

    hoppscotch-proxy:
      image: hoppscotch/proxyscotch:latest
      environment:
        - PORT=9159
      ports:
        - "9159:9159"

    # Redis-insight
    redis-insight:
      image: redislabs/redisinsight:latest
      ports:
        - "5540:5540"
      depends_on:
        - redis
      volumes:
        - ./data/redis-insight:/data

    # mongo-express
    # basicAuth credentials are "admin:pass"
    mongo-express:
      image: mongo-express
      ports:
        - "8081:8081"
      environment:
        ME_CONFIG_MONGODB_SERVER: mongo
  ```
</Accordion>

### Hoppscotch のセットアップ

#### API リクエストのプロキシ

Hoppscotch をセットアップするには、[http://localhost:3000](http://localhost:3000/) にアクセスし、設定タブを開きます。デバッグツールがコンテナ内部のネットワークとやり取りできるように、`Proxy` を [http://localhost:9159](http://localhost:9159/) に設定する必要があります。

<Frame>
  <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-6.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=10eae686404ed9da3a1c722ee536e2bb" alt="" width="2210" height="1446" data-path="images/dev/image-6.png" />
</Frame>

これで [http://web:3000/status](http://web:3000/status) にリクエストを送り、web が稼働しているかを確認できます。

<Frame>
  <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-7.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=7acf8612db25a86a3cbe85cb7732ae04" alt="" width="2126" height="1449" data-path="images/dev/image-7.png" />
</Frame>

#### CSRF の問題

<Warning>
  Postman などのデバッグツールで **POST** リクエストを送信すると、ログインが **forbidden** になり、401 エラーが返されることがあります。これは Overleaf が **CSRF** 検証によって保護されているためです。
</Warning>

<Frame>
  <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-9.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=19d2f0be555349d1b1c0e95839afb8e4" alt="" width="1695" height="1200" data-path="images/dev/image-9.png" />
</Frame>

コンソールには次のように表示される場合があります。

<Frame>
  <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-10.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=65b38b322d5e940eaa171564dcdb0384" alt="" width="1614" height="551" data-path="images/dev/image-10.png" />
</Frame>

Overleaf の開発でこれに対処するには、CSRF トークンを設定する必要があります。以下に詳しい手順を示します。

<Steps>
  <Step title="Pre-Request を追加する">
    Pre-Request に次のコードを追加します。

    <Frame>
      <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-11.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=dfc09ccaec771328ed3b1026f951bd0b" alt="" width="1123" height="704" data-path="images/dev/image-11.png" />
    </Frame>

    スクリプトは以下のとおりです。

    ```js wrap theme={null}
    pm.sendRequest("http://web:3000/dev/csrf", function (err, res) {
        if (err) {
            console.log(err);
            return;
        }

        // 1) Save CSRF token (/dev/csrf)
        const token = res.text().trim();
        pw.env.set("csrftoken", token);
        console.log("csrftoken =", token);

        const setCookieHeader = (res.headers || []).find(h => h.key?.toLowerCase() === "set-cookie")?.value;
        console.log("set-cookie =", setCookieHeader);

        if (!setCookieHeader) return;

        const cookiePair = setCookieHeader.split(";")[0].trim(); // overleaf.sid=...
        pw.env.set("cookie_header", cookiePair);
        console.log("cookie_header =", cookiePair);
    });
    ```
  </Step>

  <Step title="リクエストヘッダーを追加する">
    以下のヘッダーを追加する必要があります。

    | ヘッダー名 | ヘッダー値 |
    | - | - |
    | Content-Type | `application/json` |
    | X-Csrf-Token | `<<csrftoken>>` |
    | Cookie | `<<cookie_header>>` |

    <Frame>
      <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-12.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=0e62c9be402f8caab1844a7b102eeb29" alt="" width="1018" height="479" data-path="images/dev/image-12.png" />
    </Frame>
  </Step>

  <Step title="API ツールでログインする">
    これでユーザー名とパスワードでログインできます。

    ```json5 theme={null}
    {
      "_csrf": "<<csrftoken>>",
      "email": "admin@overleaf.com",
      "password": "xxxxxx"
    }
    ```

    以下は、誤ったユーザー名またはパスワードを入力した場合のレスポンスです。

    <Frame>
      <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/dev/image-13.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=cf570827c538094c795c3de8874ba13c" alt="" width="1050" height="830" data-path="images/dev/image-13.png" />
    </Frame>
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.