fix(auth): fail fast when the auth secret is missing, in any environment #67

Open
Hartmut wants to merge 4 commits from fix/auth-runtime-env-validation into main
4 Commits
Author SHA1 Message Date
Hartmutandclaude-flow f141a84a14 chore: ignore .env copies, allow docker commands in Claude Code settings
CI / Architecture Guardrails (pull_request) Failing after 4m37s
CI / Lint (pull_request) Successful in 5m41s
CI / Assistant Split Regression (pull_request) Successful in 5m54s
CI / Typecheck (pull_request) Successful in 6m18s
CI / Build (pull_request) Skipped
CI / E2E Tests (pull_request) Skipped
CI / Fresh-Linux Docker Deploy (pull_request) Skipped
CI / Unit Tests (pull_request) Failing after 17m20s
CI / Release Images (pull_request) Skipped
.gitignore matched .env and .env.*.local but not the copies people and tools
actually leave behind — .env.bak-20260911, .env.save, .env.orig. Those carry
the identical secrets and showed up as untracked, one `git add .` away from
being committed. Patterns verified with git check-ignore.

The .claude/settings.json entry stops Claude Code prompting for confirmation
on every docker/docker compose invocation during local debugging.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-09-11 16:21:41 +02:00
Hartmutandclaude-flow f2910b0d0e fix(auth): fail fast when the auth secret is missing, in any environment
A dev server started from apps/web never loads the monorepo root .env, so it
came up with no AUTH_SECRET/NEXTAUTH_SECRET at all. getRuntimeEnvViolations()
returned early for every non-production NODE_ENV, so nothing complained —
Auth.js then answered *every* /api/auth/* route with an opaque 500 ("problem
with the server configuration"). The login form swallowed that silently and
bounced the user back to itself with no error, pointing nowhere near the cause.

Two checks now run regardless of NODE_ENV:

- An auth secret must be present. Its absence is fatal everywhere, because
  without it Auth.js cannot sign session JWTs and nothing about auth works.
  The production-only strength rules (length, entropy, known placeholders)
  are unchanged — a weak secret still only fails production.
- E2E_TEST_MODE must not be "true" when the deployment URL is https. An https
  URL means the instance is reachable off the machine whatever NODE_ENV says,
  and that flag disables login rate limiting and the concurrent-session
  registry. The production case stays with getDevBypassViolations().

assertSecureRuntimeEnv() can now fire outside production, so its message drops
the inaccurate "production".

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-09-11 16:21:29 +02:00
HartmutandClaude Sonnet 4.6 c885c89d06 chore: clean up claude-flow boilerplate — keep only project-relevant config
Removed ~160 files of irrelevant claude-flow framework templates:

AGENTS removed:
- flow-nexus/ (SaaS platform agents, wrong product)
- github/ (GitHub-specific, project uses Gitea)
- consensus/ (Raft/CRDT/Byzantine — no use case)
- payments/ (Ed25519 payment auth)
- specialized/ (React Native / mobile)
- sublinear/ (HFT trading, matrix math)
- data/ (ML model development)
- sona/ (LoRA fine-tuning infrastructure)
- browser/ (not needed)
- devops/ + development/ (GitHub Actions CI/CD)
- nested duplicates (analysis/code-review/, documentation/api-docs/)

COMMANDS removed:
- github/ (13 files — GitHub CLI, useless with Gitea)
- sparc/supabase-admin.md (uses Prisma, not Supabase)

SKILLS removed:
- github-* (5 dirs — GitHub-specific)
- v3-* (9 dirs — claude-flow v3 internal development)

HELPERS removed:
- github-safe.js, github-setup.sh (GitHub CLI wrappers)
- v3*.sh, ddd-tracker.sh, adr-compliance.sh, sync-v3-metrics.sh (V3 metrics)
- swarm-*.sh, learning-*.sh, daemon-manager.sh (unused swarm infra)
- statusline.js (duplicate of .cjs), guidance-hook*.sh etc.

WORKTREES: pruned + deleted .claude/worktrees/ (freed 1.3 GB)

Kept: hook-handler.cjs, auto-memory-hook.mjs, statusline.cjs, router.js,
session.js, memory.js, intelligence.cjs, settings.json, agents/core/,
agents/analysis/, agents/architecture/, agents/testing/, agents/v3/security-*,
all user-created commands (plan, implement, review, research, perf, visualaudit,
gitlooper).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-15 12:02:50 +02:00
HartmutandClaude Sonnet 4.6 f80808482d chore: restore .claude commands, agents, helpers & skills (lost in 1df208d)
Restores the entire .claude/ infrastructure that was accidentally deleted
in commit 1df208d ('feat(timeline): add pulse animation for in-flight drag
mutations'). Recovered via git checkout 1df208d^.

Restored:
- .claude/commands/ (gitlooper, sparc/, github/, automation/, monitoring/,
  optimization/, hooks/, plan, implement, research, review, perf, visualaudit)
- .claude/agents/ (core/, github/, sparc/, v3/, swarm/, templates/, ...)
- .claude/helpers/ (41 scripts incl. hook-handler.cjs, statusline.cjs)
- .claude/skills/ (20 skills incl. sparc-methodology, github-*, v3-*)
- .claude/settings.json (hooks configuration)

Also updated all CapaKraken → Nexus references in affected command files.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-15 11:43:52 +02:00