From b39f7f2e9cdfb63eb29bfd6aada8e974abfce1f6 Mon Sep 17 00:00:00 2001 From: Connor Lewis <50084106+imconnorngl@users.noreply.github.com> Date: Sun, 13 Sep 2026 17:20:01 +0100 Subject: [PATCH] fix: prefer plain SERVER_API_TOKEN over the Secrets Store binding at build time During `vite build` the Cloudflare platform proxy exposes SERVER_API_TOKEN as a local Secrets Store binding whose get() fails with `Secret "skycrypt-server-api-key" not found`, breaking prerendering in CI. Read the dynamic env first (the plain string in dev/prerender, the binding in deployed Workers) and only fall back to event.platform.env. --- src/lib/shared/api/mutator/custom-instance.ts | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/src/lib/shared/api/mutator/custom-instance.ts b/src/lib/shared/api/mutator/custom-instance.ts index a3e76ed6e..8ad26b848 100644 --- a/src/lib/shared/api/mutator/custom-instance.ts +++ b/src/lib/shared/api/mutator/custom-instance.ts @@ -36,9 +36,12 @@ const tryGetRequestEvent = () => { export const customFetch = async (url: string, options: RequestInit): Promise => { const event = tryGetRequestEvent(); - // Deployed Workers get a Secrets Store binding; local dev and prerender get a plain string - const token = event?.platform?.env.SERVER_API_TOKEN ?? envPrivate.SERVER_API_TOKEN; - const serverApiToken = typeof token === "string" ? token : await token.get(); + // Deployed Workers get a Secrets Store binding (also surfaced through $env/dynamic/private); + // local dev and prerender get a plain string. Prefer the dynamic env: during `vite build` the + // platform proxy exposes a binding whose get() fails because the secret only exists remotely. + const token = + (envPrivate.SERVER_API_TOKEN as App.Platform["env"]["SERVER_API_TOKEN"]) ?? event?.platform?.env.SERVER_API_TOKEN; + const serverApiToken = typeof token === "string" ? token : ((await token?.get()) ?? ""); const requestInit: RequestInit = { ...options,