diff --git a/.autoenv b/.autoenv new file mode 100644 index 0000000..d957e20 --- /dev/null +++ b/.autoenv @@ -0,0 +1,27 @@ +# Workspace environment — loaded by autoenv on entering this directory. +# +# Single source of truth for credentials is .secrets/ (gitignored, 0600). +# NO secret value belongs in this file; it only reads them, so it is committed. +# +# Why it exists: Claude Code expands ${VAR} in .mcp.json from the *process +# environment* and has no way to read a file, so without this its tokens must be +# duplicated as literals in .claude/settings.local.json. opencode does not need +# this file — it reads .secrets/ directly via {file:.secrets/...} — which keeps +# opencode working even when launched outside a login shell. + +_cb_dir="${${AUTOENV_CUR_FILE:-${(%):-%N}}:A:h}" +_cb_secrets="$_cb_dir/.secrets" + +# A git worktree receives tracked files only, so .secrets/ is absent there. +# Workers are fed by the launcher's env instead — do nothing rather than fail. +if [[ -d "$_cb_secrets" ]]; then + _cb_load() { + [[ -r "$_cb_secrets/$2" ]] && export "$1"="$(<"$_cb_secrets/$2")" + } + _cb_load CONTEXT7_TOKEN context7-token + _cb_load GITEA_ACCESS_TOKEN gitea-token + _cb_load GITEA_HOST gitea-host + unset -f _cb_load +fi + +unset _cb_dir _cb_secrets