Commit .autoenv — the loader that keeps Claude Code on one secret store
This file has always been designed to be committed and says so in its own header;
it simply never was, so every clone of this workspace has been reconstructing it
by hand or duplicating tokens instead.
It holds no secret. It reads `.secrets/` (gitignored, 0600) and exports three
variables, because Claude Code expands `${VAR}` in `.mcp.json` from the *process*
environment and cannot read a file — so without it, CONTEXT7_TOKEN and the gitea
pair must be duplicated as literals in `.claude/settings.local.json`. opencode
needs none of this: it reads `.secrets/` directly via `{file:...}`.
Verified before committing that no value appears in it, only the three names and
the paths they are read from.
Safe in a worktree by construction: a worktree receives tracked files only, so
`.secrets/` is absent there and the whole block is skipped rather than failing.
Workers are fed by the launcher's env instead — which is where the name mismatch
documented in wiki chapter 12 (GITEA_TOKEN vs GITEA_ACCESS_TOKEN) has to be
reconciled.
This commit is contained in:
@@ -0,0 +1,27 @@
|
|||||||
|
# Workspace environment — loaded by autoenv on entering this directory.
|
||||||
|
#
|
||||||
|
# Single source of truth for credentials is .secrets/ (gitignored, 0600).
|
||||||
|
# NO secret value belongs in this file; it only reads them, so it is committed.
|
||||||
|
#
|
||||||
|
# Why it exists: Claude Code expands ${VAR} in .mcp.json from the *process
|
||||||
|
# environment* and has no way to read a file, so without this its tokens must be
|
||||||
|
# duplicated as literals in .claude/settings.local.json. opencode does not need
|
||||||
|
# this file — it reads .secrets/ directly via {file:.secrets/...} — which keeps
|
||||||
|
# opencode working even when launched outside a login shell.
|
||||||
|
|
||||||
|
_cb_dir="${${AUTOENV_CUR_FILE:-${(%):-%N}}:A:h}"
|
||||||
|
_cb_secrets="$_cb_dir/.secrets"
|
||||||
|
|
||||||
|
# A git worktree receives tracked files only, so .secrets/ is absent there.
|
||||||
|
# Workers are fed by the launcher's env instead — do nothing rather than fail.
|
||||||
|
if [[ -d "$_cb_secrets" ]]; then
|
||||||
|
_cb_load() {
|
||||||
|
[[ -r "$_cb_secrets/$2" ]] && export "$1"="$(<"$_cb_secrets/$2")"
|
||||||
|
}
|
||||||
|
_cb_load CONTEXT7_TOKEN context7-token
|
||||||
|
_cb_load GITEA_ACCESS_TOKEN gitea-token
|
||||||
|
_cb_load GITEA_HOST gitea-host
|
||||||
|
unset -f _cb_load
|
||||||
|
fi
|
||||||
|
|
||||||
|
unset _cb_dir _cb_secrets
|
||||||
Reference in New Issue
Block a user