fix(security): validate required env vars (SMB_ADDRESS, CORS_ORIGIN) at startup - #346
Conversation
… at startup Fail fast at boot if SMB_ADDRESS or CORS_ORIGIN is unset instead of silently falling back to defaults. The check runs inside the startServer startup path before the server begins listening. Closes #232 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Code Review — Verdict: Needs ChangesSelf-authored PR; verdict recorded as a marker (GitHub blocks state-bearing self-review by the author's own account). Blocking
Warnings
Note: requiring Moving issue #232 back to Ready for a follow-up commit on this same branch. |
…ESS default Extract the required-env check from the startServer IIFE into an exported validateRequiredEnv() so it can be unit-tested, and only auto-start the server when server.ts is run directly (require.main === module) rather than when imported. Add Jest coverage asserting exit(1) on missing/empty SMB_ADDRESS and CORS_ORIGIN, and no exit when both are set. Also reconcile the contradictory SMB_ADDRESS handling: drop the misleading localhost default and "using defaults" warning now that SMB_ADDRESS is required, and guard the URL-parse warning against an unset value. Switch the validation error from raw console.error to the project Log() logger. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Code Review — Verdict: LGTM (self-authored PR; recorded as marker since GitHub blocks state-bearing self-review by the author's own account)The follow-up commit adds Non-blocking: making Awaiting a human with a different account to approve + merge (required review; automation account cannot self-approve). |
PR #346 made CORS_ORIGIN a required env var, so instances on Eyevinn Open Source Cloud (where arbitrary per-instance env vars can't be set) failed to boot. Resolve the allowed origin from CORS_ORIGIN first, then fall back to the OSC-injected OSC_HOSTNAME, and only fail fast when neither is set. Closes #383 Co-authored-by: birme <birme@eyevinn.se>
Summary
The server previously started even when critical environment variables were unset, silently falling back to defaults. This adds fail-fast startup validation for
SMB_ADDRESSandCORS_ORIGIN: if either is missing, the process logs which variable is missing and exits with code 1 before the server begins listening.The check is placed at the top of the
startServer()startup path insrc/server.ts(beforedbManager.connect()andserver.listen()), so it only triggers on actual boot and does not affect module-import behavior.DB_CONNECTION_STRINGis intentionally excluded (tracked separately in #225).Test plan
npm run typecheckpassesnpm testshows no regressions from this change (identical pass/fail counts vs. cleanmain; the 94 pre-existing failures are an unrelated@fastify/cookiedynamic-import issue from a recent dependency bump)SMB_ADDRESSorCORS_ORIGINunset, startup exits 1 with a clear message; with both set, boot proceeds normallyCloses #232