Repository navigation
fix: compile Docker Turnstile key into frontend bundle - #442
Conversation
Bugbot needs on-demand usage enabledBugbot uses usage-based billing for this team and requires on-demand usage to be enabled. A team admin can enable on-demand usage in the Cursor dashboard. |
There was a problem hiding this comment.
Sorry @JacquesDelfrate, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 5 days and 13 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates the PWA webpack dotenv configuration so system environment variables override .env.example defaults, ensuring the Docker-provided public Turnstile site key is compiled into the production frontend bundle. Flow diagram for compiling the Docker Turnstile site keyflowchart LR
DockerBuild[Docker build argument APP_PUBLIC_TURNSTILE_SITE_KEY] --> BuildEnv[Frontend build process environment]
EnvDefaults[.env.example empty default] --> DotenvWebpack[dotenv-webpack]
BuildEnv --> DotenvWebpack
DotenvWebpack --> Bundle[Production JavaScript bundle]
Bundle --> Turnstile[Login and registration Turnstile configuration]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Stale comment
Risk: Medium. Review is required, and this is not an approval.
The diff is one flag in
platform/app/.webpack/webpack.pwa.js:dotenv-webpacksystemvars: true. In the pinned 1.8.0 plugin, that starts from a copy of the entire buildprocess.envand emits a DefinePlugin entry for every key.APP_PUBLIC_TURNSTILE_SITE_KEYis not in the.webpack/webpack.base.jsallowlist, so a Docker/CI value now overrides the empty.env.exampledefault and can reach login and registration. The same switch also inlines every otherprocess.env.*reference in the client bundle that the base allowlist does not already define, includingAPP_PUBLIC_API_URL,APP_PUBLIC_DEFAULT_TENANT, Firebase client config, and the remaining study-processing flags.No auth logic, secrets, or deployment config changed. There is no CODEOWNERS file. Please confirm the build environments that run this webpack config do not export any name the client bundle reads via
process.env.*except the intended public values.Requested reviewers: danvincent11, kabaluyot.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Risk: Low. Approved.
The previous systemvars: true change is no longer in the diff. What remains is a scoped build fix:
.webpack/webpack.base.jsaddsprocess.env.APP_PUBLIC_TURNSTILE_SITE_KEYto the existing DefinePlugin allowlist, with the sameprocess.envread and empty-string fallback as the other public flags.platform/app/.webpack/webpack.pwa.jsstill constructs dotenv-webpack 1.8.0 withoutsystemvars. That constructor returns a DefinePlugin whosedefinitionsare applied later, and this change deletes onlyprocess.env.APP_PUBLIC_TURNSTILE_SITE_KEYfrom that map.
The empty .env.example value for that one public site key no longer overrides the build environment. Other dotenv keys are unchanged, and the full build environment is not copied into the client bundle. No auth logic, secret key, or deployment config is in this diff. There is no CODEOWNERS file.
Two reviewers were already requested, so none were added. The earlier systemvars concern is addressed.
Sent by Cursor Automation: Assign PR reviewers


Summary
APP_PUBLIC_TURNSTILE_SITE_KEYin the shared webpackDefinePluginconfigurationdotenv-webpackdefinitions to preserve.envsupport without a duplicate definitiondotenv-webpacksystem-variable loading disabled so unrelated Docker/CI environment variables cannot enter the client bundleContext
This is a follow-up to #440. The Dockerfiles exported the public Turnstile site key before
yarn run build, but webpack did not read that variable. Login and registration therefore still received the empty example value.Validation
APP_PUBLIC_TURNSTILE_SITE_KEY=turnstile-pr442-allowlist-sentinelDefinePluginwarninggit diff --checkpassesThe Turnstile site key is public. No secret key or authentication logic is changed.