From b2718fd1e772bc976159a76a8d397310d98e6800 Mon Sep 17 00:00:00 2001 From: oqyude Date: Wed, 7 Oct 2026 11:36:55 +0300 Subject: [PATCH] xlib+users: centralize opencode server.env path The path '/home//.config/opencode/server.env' was duplicated between users.nix (sops materialization) and home/modules/opencode.nix (programs.opencode.web.environmentFile). Drift between the two was a silent auth-bypass vector: if one moved, the systemd unit would either fail to find OPENCODE_SERVER_PASSWORD or skip EnvironmentFile entirely. Single source in lib/xlib/dirs.nix; both call sites now read from it. --- lib/xlib/dirs.nix | 1 + modules/users.nix | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/lib/xlib/dirs.nix b/lib/xlib/dirs.nix index a2fd046..a3537a6 100644 --- a/lib/xlib/dirs.nix +++ b/lib/xlib/dirs.nix @@ -14,6 +14,7 @@ in server-home services-mnt-folder ; + opencode-server-env = "${user-home}/.config/opencode/server.env"; user-storage = "${user-home}/Storage"; wsl-storage = "${wsl-home}/Storage"; diff --git a/modules/users.nix b/modules/users.nix index 2c9b8f4..d14acc6 100644 --- a/modules/users.nix +++ b/modules/users.nix @@ -111,8 +111,11 @@ in # Decrypted as a single dotenv file (no `key`) and consumed by the # systemd user unit opencode-web as EnvironmentFile. # Source: secrets/opencode.env (encrypted, see sops/age below). + # Path is shared with home/modules/opencode.nix via xlib.dirs so the + # sops materialization and the systemd EnvironmentFile can never + # silently desync. opencode_server = mkUserSecret { - path = "${xlib.dirs.user-home}/.config/opencode/server.env"; + path = xlib.dirs.opencode-server-env; mode = "0600"; format = "dotenv"; sopsFile = ../secrets/opencode.env;