Skip to content

fix: never take RAFTER_* settings from a project .env - #265

Merged
Rome-1 merged 1 commit into
mainfrom
mayor-agent/dotenv-credential-guard
Oct 2, 2026
Merged

Rome-1 merged 1 commit into
mainfrom
mayor-agent/dotenv-credential-guard

Conversation

@Rome-1

@Rome-1 Rome-1 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

A .env in the working directory may belong to a repository the operator does not control, so it must not supply rafter's own settings.

  • Node: the startup dotenv guard now drops every RAFTER_* variable that .env introduced (previously only RAFTER_DISABLE_* and RAFTER_HOOK_*). A value already present in the real environment is untouched, and non-RAFTER_* keys still load.
  • Python: resolve_key no longer calls load_dotenv(). Its search starts from the package install path, which reaches a repository's .env when the virtualenv lives inside that repository.
  • Docs: README, the Python README and the CLI spec no longer suggest putting the API key in .env. The supported sources are --api-key, the RAFTER_API_KEY environment variable, and the key stored in the global ~/.rafter/config.json.

Behavior change

Anyone who relied on RAFTER_API_KEY (or another RAFTER_* setting) in a project .env must move it to their shell environment or rafter agent config set.
The CLI then reports the key as missing instead of using the .env value.

Tests

  • node/tests/env-guard.test.ts: the case that asserted a .env RAFTER_API_KEY survives is replaced by one asserting .env cannot set the key, token, webhook or confirmation, while the operator's real value survives.
  • node/tests/e2e-cli.test.ts: the dotenv e2e case now asserts rafter usage ignores a .env key and reports it missing (isolated HOME).
  • python/tests/test_config_secret_handling.py: a .env that dotenv's search would find does not outrank the stored key.

Each fails on main and passes on this branch.
tsc clean. Python suite: 1754 passed, 1 skipped. Node suite: 2274 passed; the 3 Cursor hook tests that fail also fail on main in a local checkout and are unrelated.

The working directory can be an untrusted repository, so its .env must
not supply operator settings such as the API key, GitHub token, notify
webhook or paid-scan confirmation.

Node: the startup dotenv guard now drops every RAFTER_* variable that
.env introduced, not only the disable and hook switches. Values already
in the real environment are untouched.

Python: resolve_key no longer calls load_dotenv(). Its upward search
starts from the install path, which reaches a repository's .env when
the virtualenv lives inside it.

Docs no longer suggest putting the API key in .env; use the environment
or the global config file.
@Rome-1
Rome-1 merged commit c8e2c6a into main Oct 2, 2026
10 checks passed
@Rome-1
Rome-1 deleted the mayor-agent/dotenv-credential-guard branch October 2, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant