Route BASE_URL through env module instead of reading process.env directly
All checks were successful
CI / checks (pull_request) Successful in 33s

server.ts was building callback URLs from raw process.env.BASE_URL at
lines 175 and 217, while env.ts already validates and exports BASE_URL
as a typed constant. This adds BASE_URL to the import from ./env.js and
replaces both direct process.env references so the callback URL cannot
drift from the validated value.
This commit is contained in:
Agent 2026-09-14 16:08:40 -04:00
parent c4b1a3fb4c
commit a0a284b0a3

View file

@ -1,7 +1,7 @@
import { instrument } from 'succinct-async' import { instrument } from 'succinct-async'
import express, { Request, Response, NextFunction } from 'express' import express, { Request, Response, NextFunction } from 'express'
import rateLimit from 'express-rate-limit' import rateLimit from 'express-rate-limit'
import { appSigner, BRAND_NAME, BRAND_ACCENT, BRAND_LOGO, EVENT_VIEWER_URL, CORS_ORIGIN } from './env.js' import { appSigner, BASE_URL, BRAND_NAME, BRAND_ACCENT, BRAND_LOGO, EVENT_VIEWER_URL, CORS_ORIGIN } from './env.js'
import { render } from './templates.js' import { render } from './templates.js'
import { confirmSubscriptionAction, unsubscribeAction, registerSubscription, ActionError } from './actions.js' import { confirmSubscriptionAction, unsubscribeAction, registerSubscription, ActionError } from './actions.js'
import { getSubscriptionById, insertEvent, getSubscriptionByKey, getSubscriptionByPubkey } from './database.js' import { getSubscriptionById, insertEvent, getSubscriptionByKey, getSubscriptionByPubkey } from './database.js'
@ -172,7 +172,7 @@ addRoute('get', '/subscription/email', async (req: Request, res: Response) => {
return res.status(404).json({ error: 'Subscription not found' }) return res.status(404).json({ error: 'Subscription not found' })
} }
const callback = `${process.env.BASE_URL}/notify/${sub.id}` const callback = `${BASE_URL}/notify/${sub.id}`
res.json({ res.json({
key: sub.key, key: sub.key,
@ -214,7 +214,7 @@ addRoute('put', '/subscription/email', async (req: Request, res: Response) => {
// Look up the actual subscription key from the DB // Look up the actual subscription key from the DB
const sub = await getSubscriptionByPubkey(pubkey) const sub = await getSubscriptionByPubkey(pubkey)
if (sub) { if (sub) {
const callback = `${process.env.BASE_URL}/notify/${sub.id}` const callback = `${BASE_URL}/notify/${sub.id}`
res.json({ key: sub.key, callback }) res.json({ key: sub.key, callback })
} else { } else {
console.error('Failed to register subscription:', error) console.error('Failed to register subscription:', error)