mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
fix: exclude .env secrets from python/vite deploy zips (not backups)
Only nextjs-kind excluded .env* from the deploy archive; python and vite did not - so a project's local .env at its root got zipped and shipped to the server on every deploy, planting local secrets over the server's own (the operator-file restore only wins for files it preserved). Add .env/.env.local/.env.production to the python and vite deploy excludes, matching nextjs. Kept DEPLOY-only (like `uploads`): backups still capture .env so a source backup stays complete. Bash + PowerShell. Note: this covers a ROOT .env. A nested secret (e.g. DocketMail's backend/.env) is handled separately via deploy.preserve in the project's zconfig.
This commit is contained in:
parent
4ebde3ebcf
commit
7152623661
10
ZHelpers.ps1
10
ZHelpers.ps1
@ -177,10 +177,16 @@ function Get-ArchiveExcludes {
|
|||||||
$byKind = switch ([string]$Project.kind) {
|
$byKind = switch ([string]$Project.kind) {
|
||||||
"python" {
|
"python" {
|
||||||
$list = @(".venv", "venv", "__pycache__", ".pytest_cache", ".nicegui", "archive", "dist", "build", "htmlcov")
|
$list = @(".venv", "venv", "__pycache__", ".pytest_cache", ".nicegui", "archive", "dist", "build", "htmlcov")
|
||||||
if (-not $ForBackup) { $list += "uploads" } # deploys exclude user uploads; backups keep them
|
# Deploys exclude user uploads + local .env secrets (server keeps its
|
||||||
|
# own, preserved across deploys); backups keep both for completeness.
|
||||||
|
if (-not $ForBackup) { $list += @("uploads", ".env", ".env.local", ".env.production") }
|
||||||
|
$list
|
||||||
|
}
|
||||||
|
"vite" {
|
||||||
|
$list = @("node_modules", "dist")
|
||||||
|
if (-not $ForBackup) { $list += @(".env", ".env.local", ".env.production") }
|
||||||
$list
|
$list
|
||||||
}
|
}
|
||||||
"vite" { @("node_modules", "dist") }
|
|
||||||
"nextjs" { @("node_modules", ".next", ".env", ".env.local", ".env.production", ".vercel", "coverage", "out", "build", "next-env.d.ts") }
|
"nextjs" { @("node_modules", ".next", ".env", ".env.local", ".env.production", ".vercel", "coverage", "out", "build", "next-env.d.ts") }
|
||||||
default { @() }
|
default { @() }
|
||||||
}
|
}
|
||||||
|
|||||||
@ -217,8 +217,11 @@ z_archive_excludes() {
|
|||||||
case "$kind" in
|
case "$kind" in
|
||||||
python)
|
python)
|
||||||
printf '%s\n' .venv venv __pycache__ .pytest_cache .nicegui archive dist build htmlcov
|
printf '%s\n' .venv venv __pycache__ .pytest_cache .nicegui archive dist build htmlcov
|
||||||
[ "$for_backup" -eq 1 ] || printf '%s\n' uploads ;; # deploys exclude user uploads; backups keep them
|
# deploys exclude user uploads + local .env secrets; backups keep both
|
||||||
vite) printf '%s\n' node_modules dist ;;
|
[ "$for_backup" -eq 1 ] || printf '%s\n' uploads .env .env.local .env.production ;;
|
||||||
|
vite)
|
||||||
|
printf '%s\n' node_modules dist
|
||||||
|
[ "$for_backup" -eq 1 ] || printf '%s\n' .env .env.local .env.production ;;
|
||||||
nextjs) printf '%s\n' node_modules .next .env .env.local .env.production .vercel coverage out build next-env.d.ts ;;
|
nextjs) printf '%s\n' node_modules .next .env .env.local .env.production .vercel coverage out build next-env.d.ts ;;
|
||||||
esac
|
esac
|
||||||
jq -r --arg k "$key" '.projects[$k].deploy.exclude // [] | .[]' "$ZCONFIG"
|
jq -r --arg k "$key" '.projects[$k].deploy.exclude // [] | .[]' "$ZCONFIG"
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user