fix: prefer plain SERVER_API_TOKEN over the Secrets Store binding at build time - #17
Merged
colinmcdonald22 merged 1 commit intoSep 13, 2026
Conversation
…build time During `vite build` the Cloudflare platform proxy exposes SERVER_API_TOKEN as a local Secrets Store binding whose get() fails with `Secret "skycrypt-server-api-key" not found`, breaking prerendering in CI. Read the dynamic env first (the plain string in dev/prerender, the binding in deployed Workers) and only fall back to event.platform.env.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the failing
Deploy Workersrun on dev: https://github.com/LunarClient/SkyCrypt/actions/runs/34767441597/job/103751131850During
vite buildthe Cloudflare platform proxy exposesSERVER_API_TOKENas a local Secrets Store binding for the selectedCLOUDFLARE_ENV. Itsget()fails withSecret "skycrypt-server-api-key" not foundbecause the secret only exists in Cloudflare, which broke prerendering and madegetAllStatsreturn 500.Changes
SERVER_API_TOKENfrom$env/dynamic/privatefirst and only fall back toevent.platform.env. Local dev and prerender get the plain string from the environment (restoring the pre-feat: bind SERVER_API_TOKEN from Secrets Store #16 build behaviour); deployed Workers still receive the Secrets Store binding through the same env and go through the.get()branch.App.Platformtype so the.get()branch type-checks, and fall back to an empty token if neither source is present.Testing
pnpm checkandoxfmtpass.pnpm buildwas not run locally because prerender requires the live API.Note
The failing run's log shows the
SERVER_API_TOKENsecret as blank rather than masked in thecloudflare-productionenvironment. Prerender built fine that way before #16, so it should not block this change, but it may be worth setting.