Skip to content

feat: add fail-fast validation for required environment variables in env.ts #35

Description

@coderabbitai

Summary

The apps/api/src/lib/env.ts config object currently uses insecure dummy fallback values for critical environment variables (DATABASE_URL, BETTER_AUTH_SECRET, BETTER_AUTH_URL). This allows the application to start with invalid or insecure configuration.

Problem

Using fallback values like "dummy-secret-change-me" for the auth secret weakens session security. A predictable secret makes session tokens easier to forge.

Proposed Solution

Add a requireEnv helper that throws an informative error at boot time if a required environment variable is missing:

  • DATABASE_URL — required; no dummy fallback
  • BETTER_AUTH_SECRET — required; no dummy fallback
  • BETTER_AUTH_URL — required; no dummy fallback
  • PORT — optional, can default to 3000

References

/cc @silky-x0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions