Skip to content

fix: pass Turnstile site key to frontend Docker builds - #440

Merged
JacquesDelfrate merged 1 commit into
mainfrom
fix/turnstile-docker-build-config
Sep 22, 2026
Merged

JacquesDelfrate merged 1 commit into
mainfrom
fix/turnstile-docker-build-config

Conversation

@JacquesDelfrate

@JacquesDelfrate JacquesDelfrate commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • expose APP_PUBLIC_TURNSTILE_SITE_KEY as a Docker build argument in the primary frontend image
  • propagate the same public site key through all four Nginx recipe images
  • document the build argument and frontend environment variable in current and versioned deployment docs
  • clarify the existing .env.example entry without adding a secret value

The Turnstile site key is public and is compiled into the frontend bundle. The corresponding secret key remains backend-only.

Motivation

Login and registration already read process.env.APP_PUBLIC_TURNSTILE_SITE_KEY, but Docker builds did not expose that value to the frontend build. This caused container-built deployments to render without the configured Turnstile widget.

Validation

  • confirmed login and registration consume APP_PUBLIC_TURNSTILE_SITE_KEY
  • confirmed every supported frontend Docker build path now declares and exports the argument before yarn run build
  • git diff --check passes
  • unrelated custom-CA and general environment-comment changes are excluded

Summary by Sourcery

Enable container-built frontends to receive the public Turnstile site key required by authentication flows.

Bug Fixes:

  • Pass the public Cloudflare Turnstile site key into frontend Docker builds so login and registration widgets render correctly in containerized deployments.

Build:

  • Add the Turnstile site key build argument to the primary frontend image and all supported Nginx recipe images.

Documentation:

  • Document the Turnstile Docker build argument and frontend environment variable in current and versioned deployment documentation.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @JacquesDelfrate, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 14 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Reviewer's Guide

Pass the public Turnstile site key from Docker build arguments into the frontend bundle for the primary image and all four Nginx recipes, and document the required build-time and frontend environment configuration in current and versioned deployment docs.

File-Level Changes

Change Details Files
Wire the public Turnstile site key into frontend Docker build-time environment variables across all supported image recipes.
  • Declare the site key as a build argument with an empty default.
  • Export the build argument before compiling the frontend bundle.
Dockerfile
platform/app/.recipes/Nginx-Dcm4chee-Keycloak/dockerfile
platform/app/.recipes/Nginx-Dcm4chee/dockerfile
platform/app/.recipes/Nginx-Orthanc-Keycloak/dockerfile
platform/app/.recipes/Nginx-Orthanc/dockerfile
Document configuration of the Turnstile site key for Docker deployments and frontend environments.
  • Add the build argument to Docker commands, supported-argument lists, and examples.
  • Add the public frontend variable to current and versioned environment-variable documentation.
  • Clarify the example environment entry without exposing a secret.
platform/docs/docs/deployment/docker/docker.md
platform/docs/docs/platform/environment-variables.md
platform/docs/versioned_docs/version-3.10/deployment/docker/docker.md
platform/docs/versioned_docs/version-3.10/platform/environment-variables.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@JacquesDelfrate
JacquesDelfrate merged commit 86751e2 into main Sep 22, 2026
8 checks passed
@cursor
cursor Bot requested review from danvincent11 and kabaluyot September 22, 2026 23:05

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Medium. Review is required, and this is not an approval.

The diff adds an optional APP_PUBLIC_TURNSTILE_SITE_KEY build arg to the primary image and all four Nginx recipe images, plus docs and an .env.example comment. The default is empty, so existing builds that omit the arg keep an empty key. There is no secret material and no auth-logic change.

The wiring does not reach the login or registration bundle. platform/app/.webpack/webpack.pwa.js loads dotenv-webpack without systemvars, so it only reads .env and platform/app/.env.example. .webpack/webpack.base.js inlines a fixed process.env list and does not include APP_PUBLIC_TURNSTILE_SITE_KEY. A Docker ENV set before yarn run build is therefore ignored, and the compiled value stays the empty example default. The same gap is in every recipe Dockerfile changed here.

Login and registration read process.env.APP_PUBLIC_TURNSTILE_SITE_KEY at build time, so container images built with this arg will still ship without the Turnstile widget.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Comment thread Dockerfile
ARG PUBLIC_URL=/
ARG APP_PUBLIC_TURNSTILE_SITE_KEY=
ENV PUBLIC_URL=${PUBLIC_URL}
ENV APP_PUBLIC_TURNSTILE_SITE_KEY=${APP_PUBLIC_TURNSTILE_SITE_KEY}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This ENV is visible to the Node process, but the production bundle will not pick it up. dotenv-webpack is created in platform/app/.webpack/webpack.pwa.js without systemvars, and .webpack/webpack.base.js only defines a fixed set of process.env keys. APP_PUBLIC_TURNSTILE_SITE_KEY is not in that set, so the value compiled into login and registration remains the empty .env.example default even when this build arg is passed. The four recipe Dockerfiles have the same gap.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch. The Docker ENV was not consumed by dotenv-webpack. I enabled systemvars in webpack.pwa.js and verified the fix by building the production Nginx recipe with a sentinel APP_PUBLIC_TURNSTILE_SITE_KEY, then confirming that sentinel is present in the generated app bundle. Because #440 was already merged, the correction is in follow-up PR #442.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant