Repository navigation
chore(security): drop the unused enforceSecrets() duplicate - #10775
Merged
diegosouzapw merged 1 commit intoAug 20, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
maxmad64bis
marked this pull request as draft
August 19, 2026 20:05
maxmad64bis
force-pushed
the
fix/wire-enforce-secrets
branch
from
August 19, 2026 21:40
549c950 to
22dbcf4
Compare
maxmad64bis
marked this pull request as ready for review
August 19, 2026 21:57
5 tasks done
secretsValidator.ts exported enforceSecrets(), which validates the secrets and exits on error. Its only caller was src/server-init.ts, a module nothing imports. It looks like a guard that never runs, but the same validateSecrets() call is already fatal at boot through enforceWebRuntimeEnv() (src/lib/env/runtimeEnv.ts), wired unconditionally in registerNodejs(): its errors are merged into the list that triggers process.exit(1). enforceSecrets() is a strict subset of that, so wiring it in would refuse nothing the server does not already refuse. Remove it rather than give it a second caller, and pin the real guard: a regression test asserts enforceWebRuntimeEnv() still runs after ensureSecrets() at boot and that secret errors stay fatal, which nothing covered before.
maxmad64bis
force-pushed
the
fix/wire-enforce-secrets
branch
from
August 19, 2026 22:00
22dbcf4 to
87bbadc
Compare
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…zapw#10775) Merged via merge-train (release/v3.8.50, batch1 2026-08-20) — static gates (typecheck/file-size/complexity/cognitive/changelog) green on the combined tree; test:unit reds observed in the boarded run were verified pre-existing on the pure release tip (unrelated flake), not caused by this PR. Thanks for the contribution!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
enforceSecrets()insrc/shared/utils/secretsValidator.tsvalidates the secrets and exits onerror, and its only caller is
src/server-init.ts— a module nothing imports. It reads like aguard that never runs.
enforceWebRuntimeEnv()(src/lib/env/runtimeEnv.ts) is called unconditionallyfrom
registerNodejs()and runs the samevalidateSecrets(); its errors are merged into thelist that triggers
process.exit(1). A missing or too-shortAPI_KEY_SECRETalready refuses toboot, and has since v3.6.6.
enforceSecrets()is a strict subset of that check, so giving it acaller would refuse nothing the server does not already refuse.
validateSecrets()— the logic both went through — is untouched.Related Issues
src/server-init.tsas dead code. chore(startup): remove server-init.ts, a module nothing imports #10780 removes thatmodule.
Validation
tests/unit/secrets-boot-guard.test.ts(8/8) and the two integration files that asserted on the removed function (87 pass, 4 skipped)
npm run lintTests Added Or Updated
tests/unit/secrets-boot-guard.test.ts(new, replacestests/unit/enforce-secrets-boot-wiring.test.ts)tests/integration/integration-wiring.test.tstests/integration/security-hardening.test.tsThe new file keeps the
validateSecretsrule coverage and adds what nothing covered before: thatenforceWebRuntimeEnv()still runs afterensureSecrets()at boot, that secret errors stay in thefatal list, and that no second
enforce*entry point comes back.Coverage Notes
src/shared/utils/secretsValidator.tsloses a function and its branches; the remainingvalidateSecrets()keeps its direct coverage.src/server-init.tsloses an import and a call.No production code is added.
Reviewer Notes
src/server-init.tsis touched only to drop the import and the call. chore(startup): remove server-init.ts, a module nothing imports #10780 removes that moduleoutright; whichever lands second needs a trivial rebase.
fix/wire-enforce-secrets) predates the change of approach — this PR removesthe function rather than wiring it.