Skip to content

feat: bind SERVER_API_TOKEN from Secrets Store - #16

Merged
colinmcdonald22 merged 4 commits into
LunarClient:devfrom
imconnorngl:feat/server-api-token-secret
Sep 13, 2026
Merged

colinmcdonald22 merged 4 commits into
LunarClient:devfrom
imconnorngl:feat/server-api-token-secret

Conversation

@imconnorngl

@imconnorngl imconnorngl commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds secrets_store_secrets bindings for SERVER_API_TOKEN to the production and development environments in wrangler.jsonc, sourcing the server API key (skycrypt-server-api-key) from Cloudflare Secrets Store instead of a plain Worker secret.

Secrets Store bindings expose the value via an async get() rather than a plain string, so custom-instance.ts now reads the token straight from the Worker binding:

const token = event?.platform?.env.SERVER_API_TOKEN ?? envPrivate.SERVER_API_TOKEN;
const serverApiToken = typeof token === "string" ? token : await token.get();

In local vite dev, CI prerender, and anywhere else the platform proxy is used, the value is a plain string from the process env or .env, so get() is only called on the real binding. App.Platform in app.d.ts types it as string | { get(): Promise<string> }.

Also ran oxfmt on wrangler.jsonc so pnpm lint passes.

Verification

  • svelte-check: 0 errors
  • eslint on changed files: clean
  • pnpm build (including prerender) passes locally
  • Not yet exercised against a real Secrets Store binding; worth a quick check on the preview deploy that X-API-Token arrives at the backend.

Add secrets_store_secrets bindings for the production and development
environments so the Worker receives the server API key from Cloudflare
Secrets Store instead of a plain Worker secret.
Secrets Store bindings expose the value via an async get() rather than a
plain string, so the header was going to be sent as [object Object].
Resolve the token at request time, calling get() when the binding is
present and falling back to the plain string from .env for local dev.
The resolved value is cached per isolate; failed lookups are not cached.
Use event.platform.env.SERVER_API_TOKEN.get() directly instead of
sniffing the shape of the dynamic env value and caching it. Falls back
to the .env string when the binding is absent (local vite dev). Adds a
minimal App.Platform type for the binding.
The platform proxy used by vite build/dev exposes SERVER_API_TOKEN as a
string from the process env, so calling get() on it broke prerendering
in CI. Only call get() when the value is the Secrets Store binding.
@colinmcdonald22
colinmcdonald22 merged commit 69c67ae into LunarClient:dev Sep 13, 2026
5 checks passed
@imconnorngl
imconnorngl deleted the feat/server-api-token-secret branch September 13, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants