Conversation
During vite dev, backend functions can now read unprefixed credentials from Vite's .env, .env.local, .env.[mode] and .env.[mode].local files through process.env, with shell variables taking precedence. Keys with Vite's envPrefix stay frontend-only, and DD_*/DATADOG_* keys are ignored with a warning, since the plugin resolves its own settings from the shell. Values from an earlier load are dropped on restart so edits apply. Backend builds keep envFile: false and envPrefix: [], so loaded values are never inlined. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
✅ All CI checks and tests passed. 🎉 All green!🧪 All tests passed 🔗 Commit SHA: 202fbc2 | Docs | View more details | Give us feedback! |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation is consistent with the stated design and has comprehensive regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Adds Vite .env credential loading for locally executed backend functions while preserving shell precedence and build-time secret protections.
Changes:
- Loads eligible
.envvalues intoprocess.envduring local development. - Excludes frontend-prefixed and Datadog configuration keys.
- Adds unit, integration, build-safety tests, and documentation.
| File | Description |
|---|---|
packages/plugins/apps/src/vite/index.ts |
Integrates credential loading into dev-server startup. |
packages/plugins/apps/src/vite/index.test.ts |
Tests startup loading, authentication precedence, and dev:verify. |
packages/plugins/apps/src/vite/dotenv-credentials.ts |
Implements .env loading, filtering, and restart cleanup. |
packages/plugins/apps/src/vite/dotenv-credentials.test.ts |
Covers precedence, filtering, reloads, and cleanup. |
packages/plugins/apps/src/vite/dev-server.integration.test.ts |
Supplies Vite’s environment loader to integration tests. |
packages/plugins/apps/src/vite/build-config.test.ts |
Verifies credentials remain runtime reads in backend bundles. |
packages/plugins/apps/README.md |
Documents local credential behavior and restrictions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 461c886d4e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ed config Vite expands .env references against process.env while resolving a restarted server's config, before configureServer runs, so a public key referencing an edited credential kept its old value. The config hook now drops the previous load in serve mode. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Motivation
process.env..env/.env.localfiles instead of a Datadog-specific credential file, with shell variables taking precedence.envPrefix(VITE_by default) throughimport.meta.env, and it throws onenvPrefix: ''.process.env.envFile: falseandenvPrefix: [].Architecture
Changes
8 changes across dotenv-credentials.ts, index.ts, README.md, and tests
.env-file keys intoprocess.envwith the user's own ViteloadEnv, without overriding shell variablesdotenv-credentials.ts,dotenv-credentials.test.tsenvPrefixto Vite, so the frontend never sees a value that's one restart staledotenv-credentials.ts,dotenv-credentials.test.tsDD_*/DATADOG_*keys in any case with a names-only warning, since the plugin resolves its site and auth from the shell before the dev server startsdotenv-credentials.ts,index.ts,index.test.ts.envloading indev:verify, which runs backend functions in the cloudindex.ts,index.test.tsdotenv-credentials.ts,dotenv-credentials.test.tsconfighook too, so Vite expands a restarted config's.envreferences (VITE_X=$SECRET) against the edited fileindex.ts,index.test.ts,dotenv-credentials.tsprocess.envread instead of inlining itbuild-config.test.tsenvPrefixand Datadog-key rules, anddev:verifyREADME.mdQA Instructions
Manual QA — real dev server against staging (dd.datad0g.com)
vite.config.tsimports this branch's built plugin (packages/published/vite-plugin/dist/src/index.mjs, rebuilt at 461c886):POST /__dd/executeActionafter the page has loaded the.backend.tsmodule:.envwhile the server runs:VITE_QA_DOTENV_PUBLIC=public-b, and addDATADOG_SITE=datadoghq.eu:QA_DOTENV_FILE_KEY=oneandVITE_QA_DOTENV_PUBLIC=$QA_DOTENV_FILE_KEY, thenQA_DOTENV_FILE_KEYedited totwo:Blast Radius
vite buildand cloud execution don't load.envfiles for backend functions..envfiles now exposes their unprefixed keys to backend functions duringvite dev, the same as dotenv or Next.js on the server.process.env, so a key that Node or a tool reads at runtime applies to the whole dev server, as with dotenv.Out of Scope / Follow-ups
5 items deferred
.envfiles in one Node process share oneprocess.env, so the second load replaces the first's valuesprocess.env.envvalues reach the whole dev server'sprocess.env, not only backend functionsprocess.envproxy #523 removesvite.configitself is evaluated before any plugin hook, so a config that reads unprefixedprocess.envvalues (e.g. intodefine) sees the previous load on a restart but not on first startprocess.envitself, dev bundle onlyinfo, below the defaultwarnlog level.envedits to it apply only after a full restartprocess.envDocumentation
🤖 Generated with Claude Code