Skip to content

Fix PWA 401: read auth env at runtime, not build time - #5

Merged
ralyodio merged 1 commit into
mainfrom
fix/web-runtime-env
Aug 11, 2026
Merged

ralyodio merged 1 commit into
mainfrom
fix/web-runtime-env

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

The deployed PWA returned 500 on every dynamic page. The underlying cause was a 401 from the API — while the exact same credentials returned 200 by curl, and the tokens on both services hashed identically.

Cause

Next.js statically replaces process.env.SOME_NAME during the build. The web image was built before the credentials were set, so this:

...(process.env.API_TOKEN ? { authorization: `Bearer ${process.env.API_TOKEN}` } : {}),

was baked in as undefined, the ternary collapsed to false, and the request went out with no auth headers at all — permanently, regardless of what the container environment said later. Setting the variables and redeploying could never have fixed it; only a rebuild would, and that would bake a secret into the image.

Reading through an accessor that indexes process.env with a non-literal key defeats the substitution, so the value is genuinely read from the running container:

function runtimeEnv(name: string): string | undefined {
  const key = String(name);
  return process.env[key];
}

NEXT_PUBLIC_* stays a direct reference, since inlining is the intent there.

Also: a 401 should not be a 500

The auth failure escaped as an unhandled error and Next rendered a generic 500, which tells an operator nothing. ApiAuthError is now distinct from ApiUnavailableError — one means bad credentials, the other means the service is down, and they have different fixes. Each screen renders the relevant explanation and names the variables to check.

Verification

Typecheck clean, next build clean, 265 tests pass.

🤖 Generated with Claude Code

Next.js statically replaces process.env.SOME_NAME during the build, so a
variable absent at build time is baked in as undefined forever. The image
was built before the credentials existed, so every auth header was dropped
by its own ternary and the deployed PWA got 401 on every request — while
the same credentials returned 200 by curl.

Reading through an accessor that indexes process.env with a non-literal key
defeats the substitution, so the value comes from the running container.

Also stops a 401 from crashing the page. It previously escaped as an
unhandled error and Next rendered a 500, which says nothing useful about a
misconfigured deployment; each screen now explains which variables to check.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio merged commit d7633ee into main Aug 11, 2026
8 checks passed
@ralyodio
ralyodio deleted the fix/web-runtime-env branch August 11, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant