Skip to content

Feat/fail fast env validation - #58

Merged
Basharkhan7776 merged 3 commits into
Openlabsops:mainfrom
yashraj639:feat/fail-fast-env-validation
Jun 23, 2026
Merged

Basharkhan7776 merged 3 commits into
Openlabsops:mainfrom
yashraj639:feat/fail-fast-env-validation

Conversation

@yashraj639

@yashraj639 yashraj639 commented Jun 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds a requireEnv helper that throws an informative error at boot time
if a required environment variable is missing, replacing insecure dummy
fallbacks that could silently weaken session security.

Changes Made

Testing

  • DATABASE_URL="postgresql://dummy" bun turbo lint passes with 0 errors, 0 warnings
  • 4 packages linted successfully
  • No regressions introduced

Related Issues

Checklist

  • Code follows project conventions
  • Tests pass
  • No linting errors

Release Notes

  • Security hardening: Enforces that critical environment variables (DATABASE_URL, BETTER_AUTH_SECRET, BETTER_AUTH_URL) must be explicitly configured, preventing the application from starting with insecure dummy placeholder values
  • Fail-fast validation: Application now fails immediately at boot time if required environment variables are missing, providing clear error messages instead of silently running with invalid credentials
  • Improved developer experience: Eliminates security misconfiguration risks by making missing required variables obvious during deployment or startup
  • Maintains backward compatibility: Optional variables like PORT retain their default values
  • Minor cleanup: Fixed ESLint configuration in sidebar component and synchronized environment variable tracking in build system

@coderabbitai

coderabbitai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@yashraj639, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 46 minutes and 42 seconds. Learn how PR review limits work.

To continue reviewing without waiting, enable usage-based billing in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses rolling per-developer review limits. Reviews become available again as older review attempts age out of the rolling limit window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 4447d1fe-3519-4ab9-aa69-119e4247c7af

📥 Commits

Reviewing files that changed from the base of the PR and between 04a8779 and eb5b0f0.

📒 Files selected for processing (1)
  • apps/api/src/lib/env.ts
📝 Walkthrough

Walkthrough

Adds a requireEnv helper to apps/api/src/lib/env.ts that throws at boot if a required environment variable is absent, replacing dummy fallbacks for DATABASE_URL, BETTER_AUTH_SECRET, and BETTER_AUTH_URL. turbo.json's globalEnv is expanded with OAuth and frontend URL vars. An ESLint suppression comment in sidebar.tsx is corrected.

Changes

Environment Variable Hardening

Layer / File(s) Summary
requireEnv helper and config updates
apps/api/src/lib/env.ts, turbo.json
requireEnv(key) throws a runtime error when a required env var is missing; config.databaseUrl, config.auth.secret, and config.auth.url now use it instead of dummy fallbacks. turbo.json's globalEnv is expanded to include BETTER_AUTH_URL, Google/GitHub OAuth vars, and FRONTEND_URL.
ESLint comment fix in SidebarMenuSkeleton
packages/ui/src/components/ui/sidebar.tsx
ESLint disable comment in the skeleton useEffect is changed from exhaustive-deps to react-hooks/set-state-in-effect with a note explaining the intentional hydration-mismatch avoidance.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~5 minutes

Possibly related PRs

  • Openlabsops/Snap-form#40: Modifies the same turbo.json globalEnv entries for BETTER_AUTH_* vars and changes the same ESLint disable comment in sidebar.tsx.

Poem

🐇 A bunny once found a dummy secret key,
"This placeholder's trouble!" said she with a plea.
So she wrote requireEnv, strict and true,
No more fake passwords sneaking through!
The warren is safe — hooray, hip-hop-hoo! 🎉

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Feat/fail fast env validation' directly and accurately summarizes the main change: implementing fail-fast validation for environment variables through the requireEnv helper.
Linked Issues check ✅ Passed The PR successfully implements all requirements from issue #35: requireEnv helper validates DATABASE_URL, BETTER_AUTH_SECRET, and BETTER_AUTH_URL as required variables, eliminates dummy fallbacks, and maintains PORT as optional with 3000 default.
Out of Scope Changes check ✅ Passed Changes to turbo.json adding environment variables to globalEnv and sidebar.tsx ESLint comment update are scope-appropriate maintenance tasks supporting the primary fail-fast validation implementation.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@apps/api/src/lib/env.ts`:
- Line 10: The port configuration is accepting arbitrary string values from
process.env.PORT without validation. Modify the port assignment in the config
export to parse the PORT environment variable as an integer using parseInt with
radix 10, validate that the parsed result is a valid number and within
acceptable port range (1-65535), and fall back to 3000 if the environment
variable is missing or invalid. This ensures only properly formatted port
numbers are used for the server configuration.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 70ee1810-929a-450f-9d9d-33f4b584f487

📥 Commits

Reviewing files that changed from the base of the PR and between f74e8ee and 04a8779.

📒 Files selected for processing (3)
  • apps/api/src/lib/env.ts
  • packages/ui/src/components/ui/sidebar.tsx
  • turbo.json
📜 Review details
🔇 Additional comments (2)
apps/api/src/lib/env.ts (1)

1-7: LGTM!

Also applies to: 11-25

turbo.json (1)

7-12: LGTM!

Comment thread apps/api/src/lib/env.ts Outdated

@Basharkhan7776 Basharkhan7776 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merging

@Basharkhan7776
Basharkhan7776 merged commit 733a40f into Openlabsops:main Jun 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: add fail-fast validation for required environment variables in env.ts

2 participants