fix: add E2E opt-out for fail-loud secret/DB-URL guards
Playwright runs the server via `react-router serve` with
NODE_ENV=production but against a local dev Postgres and local cookie
secrets. The guards added in 5a7bb76 refused to start under that
configuration. `E2E=true` (already set by the CI E2E job) is now the
explicit opt-out: in real production this env var is never set, so the
guard still bites.
This commit is contained in:
parent
9d48d26a6e
commit
ebedfa257b
3 changed files with 13 additions and 8 deletions
10
.github/workflows/ci.yml
vendored
10
.github/workflows/ci.yml
vendored
|
|
@ -255,14 +255,12 @@ jobs:
|
|||
run: pnpm test:e2e
|
||||
env:
|
||||
BROUTER_URL: http://localhost:17777
|
||||
# E2E=true is the explicit opt-out from the fail-loud
|
||||
# requireSecret() / getDatabaseUrl() guards — playwright boots
|
||||
# the server via `react-router serve` (NODE_ENV=production) but
|
||||
# against the local dev Postgres + local cookie secrets.
|
||||
E2E: "true"
|
||||
INTEGRATION_SECRET: ${{ secrets.INTEGRATION_SECRET }}
|
||||
# pnpm test:e2e starts the server via `react-router serve`, which
|
||||
# boots with NODE_ENV=production. requireSecret() refuses to start
|
||||
# in production without these set — supply random throwaway values
|
||||
# for CI so the fail-loud guard still bites in real prod deploys.
|
||||
JWT_SECRET: ci-jwt-secret-only-for-e2e-do-not-reuse
|
||||
SESSION_SECRET: ci-session-secret-only-for-e2e-do-not-reuse
|
||||
|
||||
- name: Playwright job summary
|
||||
if: ${{ !cancelled() }}
|
||||
|
|
|
|||
|
|
@ -18,7 +18,10 @@ export function getOrigin(): string {
|
|||
*/
|
||||
export function requireSecret(name: string, devFallback: string): string {
|
||||
const value = process.env[name];
|
||||
const isProd = process.env.NODE_ENV === "production";
|
||||
// Playwright runs `react-router serve` (NODE_ENV=production) against a
|
||||
// local stack. E2E=true is the explicit opt-out so the guard still
|
||||
// bites in real prod deploys.
|
||||
const isProd = process.env.NODE_ENV === "production" && process.env.E2E !== "true";
|
||||
if (isProd) {
|
||||
if (!value || value === devFallback) {
|
||||
throw new Error(
|
||||
|
|
|
|||
|
|
@ -15,7 +15,11 @@ const DEV_DB_URL = "postgres://trails:trails@localhost:5432/trails";
|
|||
export function getDatabaseUrl(override?: string): string {
|
||||
if (override) return override;
|
||||
const url = process.env.DATABASE_URL;
|
||||
if (process.env.NODE_ENV === "production") {
|
||||
// Playwright runs `react-router serve` which boots with
|
||||
// NODE_ENV=production, but the CI E2E suite legitimately points at a
|
||||
// local Postgres using the dev URL. E2E=true is the explicit opt-out.
|
||||
const isProd = process.env.NODE_ENV === "production" && process.env.E2E !== "true";
|
||||
if (isProd) {
|
||||
if (!url || url === DEV_DB_URL) {
|
||||
throw new Error(
|
||||
"Refusing to start: DATABASE_URL is unset or matches the dev default. " +
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue