From 71526236611fc11d0e1a5451e23f972b422bc4d4 Mon Sep 17 00:00:00 2001 From: KellyMichels Date: Thu, 23 Jul 2026 22:44:04 -0500 Subject: [PATCH] fix: exclude .env secrets from python/vite deploy zips (not backups) Only nextjs-kind excluded .env* from the deploy archive; python and vite did not - so a project's local .env at its root got zipped and shipped to the server on every deploy, planting local secrets over the server's own (the operator-file restore only wins for files it preserved). Add .env/.env.local/.env.production to the python and vite deploy excludes, matching nextjs. Kept DEPLOY-only (like `uploads`): backups still capture .env so a source backup stays complete. Bash + PowerShell. Note: this covers a ROOT .env. A nested secret (e.g. DocketMail's backend/.env) is handled separately via deploy.preserve in the project's zconfig. --- ZHelpers.ps1 | 10 ++++++++-- bash/zhelpers.sh | 7 +++++-- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/ZHelpers.ps1 b/ZHelpers.ps1 index 7bd7467..a5127d4 100644 --- a/ZHelpers.ps1 +++ b/ZHelpers.ps1 @@ -177,10 +177,16 @@ function Get-ArchiveExcludes { $byKind = switch ([string]$Project.kind) { "python" { $list = @(".venv", "venv", "__pycache__", ".pytest_cache", ".nicegui", "archive", "dist", "build", "htmlcov") - if (-not $ForBackup) { $list += "uploads" } # deploys exclude user uploads; backups keep them + # Deploys exclude user uploads + local .env secrets (server keeps its + # own, preserved across deploys); backups keep both for completeness. + if (-not $ForBackup) { $list += @("uploads", ".env", ".env.local", ".env.production") } + $list + } + "vite" { + $list = @("node_modules", "dist") + if (-not $ForBackup) { $list += @(".env", ".env.local", ".env.production") } $list } - "vite" { @("node_modules", "dist") } "nextjs" { @("node_modules", ".next", ".env", ".env.local", ".env.production", ".vercel", "coverage", "out", "build", "next-env.d.ts") } default { @() } } diff --git a/bash/zhelpers.sh b/bash/zhelpers.sh index 81d2ae6..9586d57 100644 --- a/bash/zhelpers.sh +++ b/bash/zhelpers.sh @@ -217,8 +217,11 @@ z_archive_excludes() { case "$kind" in python) printf '%s\n' .venv venv __pycache__ .pytest_cache .nicegui archive dist build htmlcov - [ "$for_backup" -eq 1 ] || printf '%s\n' uploads ;; # deploys exclude user uploads; backups keep them - vite) printf '%s\n' node_modules dist ;; + # deploys exclude user uploads + local .env secrets; backups keep both + [ "$for_backup" -eq 1 ] || printf '%s\n' uploads .env .env.local .env.production ;; + vite) + printf '%s\n' node_modules dist + [ "$for_backup" -eq 1 ] || printf '%s\n' .env .env.local .env.production ;; nextjs) printf '%s\n' node_modules .next .env .env.local .env.production .vercel coverage out build next-env.d.ts ;; esac jq -r --arg k "$key" '.projects[$k].deploy.exclude // [] | .[]' "$ZCONFIG"