From a0a284b0a33fac06c663627df0003350f7b3d7c1 Mon Sep 17 00:00:00 2001 From: Agent Date: Mon, 14 Sep 2026 16:08:40 -0400 Subject: [PATCH] Route BASE_URL through env module instead of reading process.env directly server.ts was building callback URLs from raw process.env.BASE_URL at lines 175 and 217, while env.ts already validates and exports BASE_URL as a typed constant. This adds BASE_URL to the import from ./env.js and replaces both direct process.env references so the callback URL cannot drift from the validated value. --- src/server.ts | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/server.ts b/src/server.ts index be88a56..0e9220e 100644 --- a/src/server.ts +++ b/src/server.ts @@ -1,7 +1,7 @@ import { instrument } from 'succinct-async' import express, { Request, Response, NextFunction } from 'express' import rateLimit from 'express-rate-limit' -import { appSigner, BRAND_NAME, BRAND_ACCENT, BRAND_LOGO, EVENT_VIEWER_URL, CORS_ORIGIN } from './env.js' +import { appSigner, BASE_URL, BRAND_NAME, BRAND_ACCENT, BRAND_LOGO, EVENT_VIEWER_URL, CORS_ORIGIN } from './env.js' import { render } from './templates.js' import { confirmSubscriptionAction, unsubscribeAction, registerSubscription, ActionError } from './actions.js' import { getSubscriptionById, insertEvent, getSubscriptionByKey, getSubscriptionByPubkey } from './database.js' @@ -172,7 +172,7 @@ addRoute('get', '/subscription/email', async (req: Request, res: Response) => { return res.status(404).json({ error: 'Subscription not found' }) } - const callback = `${process.env.BASE_URL}/notify/${sub.id}` + const callback = `${BASE_URL}/notify/${sub.id}` res.json({ key: sub.key, @@ -214,7 +214,7 @@ addRoute('put', '/subscription/email', async (req: Request, res: Response) => { // Look up the actual subscription key from the DB const sub = await getSubscriptionByPubkey(pubkey) if (sub) { - const callback = `${process.env.BASE_URL}/notify/${sub.id}` + const callback = `${BASE_URL}/notify/${sub.id}` res.json({ key: sub.key, callback }) } else { console.error('Failed to register subscription:', error)