Repository navigation
fix: pass Turnstile site key to frontend Docker builds - #440
Conversation
There was a problem hiding this comment.
Sorry @JacquesDelfrate, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 5 days and 14 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's GuidePass the public Turnstile site key from Docker build arguments into the frontend bundle for the primary image and all four Nginx recipes, and document the required build-time and frontend environment configuration in current and versioned deployment docs. File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Risk: Medium. Review is required, and this is not an approval.
The diff adds an optional APP_PUBLIC_TURNSTILE_SITE_KEY build arg to the primary image and all four Nginx recipe images, plus docs and an .env.example comment. The default is empty, so existing builds that omit the arg keep an empty key. There is no secret material and no auth-logic change.
The wiring does not reach the login or registration bundle. platform/app/.webpack/webpack.pwa.js loads dotenv-webpack without systemvars, so it only reads .env and platform/app/.env.example. .webpack/webpack.base.js inlines a fixed process.env list and does not include APP_PUBLIC_TURNSTILE_SITE_KEY. A Docker ENV set before yarn run build is therefore ignored, and the compiled value stays the empty example default. The same gap is in every recipe Dockerfile changed here.
Login and registration read process.env.APP_PUBLIC_TURNSTILE_SITE_KEY at build time, so container images built with this arg will still ship without the Turnstile widget.
Sent by Cursor Automation: Assign PR reviewers
| ARG PUBLIC_URL=/ | ||
| ARG APP_PUBLIC_TURNSTILE_SITE_KEY= | ||
| ENV PUBLIC_URL=${PUBLIC_URL} | ||
| ENV APP_PUBLIC_TURNSTILE_SITE_KEY=${APP_PUBLIC_TURNSTILE_SITE_KEY} |
There was a problem hiding this comment.
This ENV is visible to the Node process, but the production bundle will not pick it up. dotenv-webpack is created in platform/app/.webpack/webpack.pwa.js without systemvars, and .webpack/webpack.base.js only defines a fixed set of process.env keys. APP_PUBLIC_TURNSTILE_SITE_KEY is not in that set, so the value compiled into login and registration remains the empty .env.example default even when this build arg is passed. The four recipe Dockerfiles have the same gap.
There was a problem hiding this comment.
Good catch. The Docker ENV was not consumed by dotenv-webpack. I enabled systemvars in webpack.pwa.js and verified the fix by building the production Nginx recipe with a sentinel APP_PUBLIC_TURNSTILE_SITE_KEY, then confirming that sentinel is present in the generated app bundle. Because #440 was already merged, the correction is in follow-up PR #442.


Summary
APP_PUBLIC_TURNSTILE_SITE_KEYas a Docker build argument in the primary frontend image.env.exampleentry without adding a secret valueThe Turnstile site key is public and is compiled into the frontend bundle. The corresponding secret key remains backend-only.
Motivation
Login and registration already read
process.env.APP_PUBLIC_TURNSTILE_SITE_KEY, but Docker builds did not expose that value to the frontend build. This caused container-built deployments to render without the configured Turnstile widget.Validation
APP_PUBLIC_TURNSTILE_SITE_KEYyarn run buildgit diff --checkpassesSummary by Sourcery
Enable container-built frontends to receive the public Turnstile site key required by authentication flows.
Bug Fixes:
Build:
Documentation: