Repository navigation
Fix PWA 401: read auth env at runtime, not build time - #5
Merged
Merged
Conversation
Next.js statically replaces process.env.SOME_NAME during the build, so a variable absent at build time is baked in as undefined forever. The image was built before the credentials existed, so every auth header was dropped by its own ternary and the deployed PWA got 401 on every request — while the same credentials returned 200 by curl. Reading through an accessor that indexes process.env with a non-literal key defeats the substitution, so the value comes from the running container. Also stops a 401 from crashing the page. It previously escaped as an unhandled error and Next rendered a 500, which says nothing useful about a misconfigured deployment; each screen now explains which variables to check. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The deployed PWA returned 500 on every dynamic page. The underlying cause was a 401 from the API — while the exact same credentials returned 200 by curl, and the tokens on both services hashed identically.
Cause
Next.js statically replaces
process.env.SOME_NAMEduring the build. The web image was built before the credentials were set, so this:was baked in as
undefined, the ternary collapsed tofalse, and the request went out with no auth headers at all — permanently, regardless of what the container environment said later. Setting the variables and redeploying could never have fixed it; only a rebuild would, and that would bake a secret into the image.Reading through an accessor that indexes
process.envwith a non-literal key defeats the substitution, so the value is genuinely read from the running container:NEXT_PUBLIC_*stays a direct reference, since inlining is the intent there.Also: a 401 should not be a 500
The auth failure escaped as an unhandled error and Next rendered a generic 500, which tells an operator nothing.
ApiAuthErroris now distinct fromApiUnavailableError— one means bad credentials, the other means the service is down, and they have different fixes. Each screen renders the relevant explanation and names the variables to check.Verification
Typecheck clean,
next buildclean, 265 tests pass.🤖 Generated with Claude Code