Skip to content

fix: compile Docker Turnstile key into frontend bundle - #442

Merged
JacquesDelfrate merged 2 commits into
mainfrom
fix/turnstile-webpack-build-env
Sep 22, 2026
Merged

JacquesDelfrate merged 2 commits into
mainfrom
fix/turnstile-webpack-build-env

Conversation

@JacquesDelfrate

@JacquesDelfrate JacquesDelfrate commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • explicitly allowlist APP_PUBLIC_TURNSTILE_SITE_KEY in the shared webpack DefinePlugin configuration
  • exclude that key from the existing dotenv-webpack definitions to preserve .env support without a duplicate definition
  • keep dotenv-webpack system-variable loading disabled so unrelated Docker/CI environment variables cannot enter the client bundle

Context

This is a follow-up to #440. The Dockerfiles exported the public Turnstile site key before yarn run build, but webpack did not read that variable. Login and registration therefore still received the empty example value.

Validation

  • built the production Nginx-Orthanc recipe with APP_PUBLIC_TURNSTILE_SITE_KEY=turnstile-pr442-allowlist-sentinel
  • confirmed the sentinel value is present in the generated production JavaScript bundle
  • confirmed the build has no conflicting DefinePlugin warning
  • git diff --check passes

The Turnstile site key is public. No secret key or authentication logic is changed.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot needs on-demand usage enabled

Bugbot uses usage-based billing for this team and requires on-demand usage to be enabled.

A team admin can enable on-demand usage in the Cursor dashboard.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @JacquesDelfrate, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 13 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates the PWA webpack dotenv configuration so system environment variables override .env.example defaults, ensuring the Docker-provided public Turnstile site key is compiled into the production frontend bundle.

Flow diagram for compiling the Docker Turnstile site key

flowchart LR
    DockerBuild[Docker build argument APP_PUBLIC_TURNSTILE_SITE_KEY] --> BuildEnv[Frontend build process environment]
    EnvDefaults[.env.example empty default] --> DotenvWebpack[dotenv-webpack]
    BuildEnv --> DotenvWebpack
    DotenvWebpack --> Bundle[Production JavaScript bundle]
    Bundle --> Turnstile[Login and registration Turnstile configuration]
Loading

File-Level Changes

Change Details Files
Make frontend webpack builds consume environment variables from the build process, allowing Docker-provided public Turnstile configuration to override fallback defaults.
  • Enable dotenv-webpack system variable loading alongside the existing .env.example defaults.
  • Preserve the empty example value as a fallback while prioritizing Docker/CI build arguments such as APP_PUBLIC_TURNSTILE_SITE_KEY.
platform/app/.webpack/webpack.pwa.js

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: Medium. Review is required, and this is not an approval.

The diff is one flag in platform/app/.webpack/webpack.pwa.js: dotenv-webpack systemvars: true. In the pinned 1.8.0 plugin, that starts from a copy of the entire build process.env and emits a DefinePlugin entry for every key. APP_PUBLIC_TURNSTILE_SITE_KEY is not in the .webpack/webpack.base.js allowlist, so a Docker/CI value now overrides the empty .env.example default and can reach login and registration. The same switch also inlines every other process.env.* reference in the client bundle that the base allowlist does not already define, including APP_PUBLIC_API_URL, APP_PUBLIC_DEFAULT_TENANT, Firebase client config, and the remaining study-processing flags.

No auth logic, secrets, or deployment config changed. There is no CODEOWNERS file. Please confirm the build environments that run this webpack config do not export any name the client bundle reads via process.env.* except the intended public values.

Requested reviewers: danvincent11, kabaluyot.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Comment thread platform/app/.webpack/webpack.pwa.js Outdated
@cursor
cursor Bot requested review from danvincent11 and kabaluyot September 22, 2026 23:19

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Low. Approved.

The previous systemvars: true change is no longer in the diff. What remains is a scoped build fix:

  • .webpack/webpack.base.js adds process.env.APP_PUBLIC_TURNSTILE_SITE_KEY to the existing DefinePlugin allowlist, with the same process.env read and empty-string fallback as the other public flags.
  • platform/app/.webpack/webpack.pwa.js still constructs dotenv-webpack 1.8.0 without systemvars. That constructor returns a DefinePlugin whose definitions are applied later, and this change deletes only process.env.APP_PUBLIC_TURNSTILE_SITE_KEY from that map.

The empty .env.example value for that one public site key no longer overrides the build environment. Other dotenv keys are unchanged, and the full build environment is not copied into the client bundle. No auth logic, secret key, or deployment config is in this diff. There is no CODEOWNERS file.

Two reviewers were already requested, so none were added. The earlier systemvars concern is addressed.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@JacquesDelfrate
JacquesDelfrate merged commit fb4e1f5 into main Sep 22, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant