Skip to content

Fix red main: read hosted tenant delete token lazily from process.env - #9669

Merged
azooz2003-bit merged 1 commit into
mainfrom
feat-hosted-tenant-token-lazy-read
Aug 5, 2026
Merged

azooz2003-bit merged 1 commit into
mainfrom
feat-hosted-tenant-token-lazy-read

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Aug 5, 2026 •

Copy link
Copy Markdown
Collaborator

Main has been red on web tests since 0eecd5a (#9607, "Read hosted credentials through validated runtime env"): 2 failures in web/tests/account-route.test.ts and 1 in web/tests/hosted-subrouter-routes.test.ts. CI is paused, so it landed unnoticed; it currently blocks the merge gate for #9319 (and any other PR gated on web-typecheck).

Mechanism: t3-env's env object freezes values at first import. SUBROUTER_STACK_TENANT_DELETE_TOKEN gates hosted tenant control per client construction, and the tests toggle it per-case via process.env, so the frozen read makes the client permanently "configured": the exchange route returns 200 instead of 503 when unconfigured, and account deletion fires hosted tenant deletes for accounts that never enabled Subrouter.

Fix restores the lazy process.env read (parent-commit behavior) with a comment stating the constraint. Deploy-time validation is unchanged: env.ts still requires the value on Vercel non-preview.

Verified on this branch: tests/hosted-subrouter-routes.test.ts 18/18, tests/account-route.test.ts 65/65, bun run typecheck clean. Both files fail identically on origin/main, pass at 0eecd5afea~1.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Read the hosted tenant delete token lazily from process.env to avoid t3-env freezing the value at import time. This restores per-client configuration, returns 503 when unconfigured, and prevents unintended hosted tenant deletes.

  • Bug Fixes
    • Read SUBROUTER_STACK_TENANT_DELETE_TOKEN via process.env instead of the validated env object from t3-env.
    • Keep deploy-time validation in env.ts for Vercel non-preview deployments.

Written for commit f2c2b6f. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Improved tenant deletion token handling when creating hosted clients.
    • Explicit token overrides and whitespace trimming continue to work as expected.

0eecd5a (#9607) switched SUBROUTER_STACK_TENANT_DELETE_TOKEN to the
validated env object, but t3-env freezes values at first import, so
tenant-control configuration became unobservable after boot and the
unconfigured paths broke: the exchange route returns 200 instead of 503
and account deletion fires hosted tenant deletes for accounts that never
enabled Subrouter. web tests have been red on main since (CI paused).
env.ts still validates presence on Vercel non-preview deployments.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 81818858-e7f0-4e01-9126-f67de8c2bf0a

📥 Commits

Reviewing files that changed from the base of the PR and between 2d9ba4b and f2c2b6f.

📒 Files selected for processing (1)
  • web/services/subrouter/hostedClient.ts

📝 Walkthrough

Walkthrough

The hosted client now resolves SUBROUTER_STACK_TENANT_DELETE_TOKEN from process.env during construction. Explicit option overrides, trimming, and empty-string fallback behavior remain unchanged.

Changes

Tenant delete-token configuration

Layer / File(s) Summary
Hosted client token fallback
web/services/subrouter/hostedClient.ts
The fallback token is read lazily from process.env. Explicit overrides and subsequent empty-string fallback behavior remain unchanged.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

Suggested reviewers: lawrencecchen

🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the lazy process.env read that fixes hosted tenant delete token handling.
Description check ✅ Passed The description explains the bug, fix, deployment validation, and test results, but omits the repository checklist.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed The pull request changes only web/services/subrouter/hostedClient.ts; the diff contains no Swift files or Swift actor-isolation changes.
Cmux Swift Blocking Runtime ✅ Passed The commit changes only web/services/subrouter/hostedClient.ts; it introduces no Swift changes or Swift blocking runtime patterns.
Cmux Browser Automation Off-Main ✅ Passed The PR changes only web/services/subrouter/hostedClient.ts; the diff contains no browser.* socket commands, WebKit waits, worker routing, or main-actor changes covered by this rule.
Cmux Expensive Synchronous Load ✅ Passed The diff changes only web/services/subrouter/hostedClient.ts; it adds no Swift code or synchronous agent-history load, so this Swift-only check is not applicable.
Cmux Cache Substitution Correctness ✅ Passed The diff replaces a frozen env read with a per-construction process.env read; hostedClient.ts has no persistence, history, undo, or snapshot cache path.
Cmux No Hacky Sleeps ✅ Passed The only production change reads the tenant token from process.env and adds a comment; the diff introduces no sleeps, timers, polling, fixed delays, or wall-clock synchronization.
Cmux Algorithmic Complexity ✅ Passed The diff only changes a scalar environment lookup in hostedClient.ts:81-85; it adds no collection scan, sort, join, batch action, or slower algorithm.
Cmux Swift Concurrency ✅ Passed The complete origin/main...HEAD diff contains only web/services/subrouter/hostedClient.ts; it adds no Swift code or Swift concurrency patterns.
Cmux Swift @Concurrent ✅ Passed Not applicable: the commit changes only web/services/subrouter/hostedClient.ts and includes zero .swift paths, so the Swift @concurrent rule has no target.
Cmux Swift Package Boundaries ✅ Passed The diff changes only web/services/subrouter/hostedClient.ts, a TypeScript file; it contains no production Swift changes or Swift package-boundary violation.
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only web/services/subrouter/hostedClient.ts; no SwiftPM, Xcode, .gitignore, workflow, or dependency files changed, so the lockfile rule is not applicable.
Cmux Swift Logging ✅ Passed The PR changes only web/services/subrouter/hostedClient.ts; it adds no Swift files or Swift logging statements, so the Swift logging rule is not applicable.
Cmux User-Facing Error Privacy ✅ Passed The diff only changes lazy token lookup and adds a developer-only comment; no user-facing error, alert, API body, or recovery text changed.
Cmux Full Internationalization ✅ Passed The diff only changes environment-token lookup and adds a developer-only comment; it introduces no user-facing text, locale data, or localization surface.
Cmux Swiftui State Layout ✅ Passed The pull request changes only web/services/subrouter/hostedClient.ts, a TypeScript file; it contains no SwiftUI changes covered by this check.
Cmux Architecture Rethink ✅ Passed The patch changes only TypeScript, not Swift. It is a small lazy environment-read correctness fix and adds no timing, state-ownership, wiring, or lifecycle constructs.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The PR changes only web/services/subrouter/hostedClient.ts; no Swift code or auxiliary window is added or changed, so the shortcut rule does not apply.
Cmux Source Artifacts ✅ Passed The only changed path is the hand-written source file web/services/subrouter/hostedClient.ts; the diff adds code comments and changes runtime logic, not a source-control artifact.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The patch changes only web/services/subrouter/hostedClient.ts, a TypeScript file; no Swift file under a non-Test Sources path is in the diff.
Cmux No Ambient Global State ✅ Passed The diff changes only web/services/subrouter/hostedClient.ts, a TypeScript file; the no-ambient-global-state check applies only to production Swift changes.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-hosted-tenant-token-lazy-read

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@azooz2003-bit
azooz2003-bit merged commit 6d0d313 into main Aug 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant