xlib+users: centralize opencode server.env path

The path '/home/<user>/.config/opencode/server.env' was duplicated
between users.nix (sops materialization) and home/modules/opencode.nix
(programs.opencode.web.environmentFile). Drift between the two was a
silent auth-bypass vector: if one moved, the systemd unit would either
fail to find OPENCODE_SERVER_PASSWORD or skip EnvironmentFile entirely.

Single source in lib/xlib/dirs.nix; both call sites now read from it.
This commit is contained in:
2026-10-07 11:36:55 +03:00
parent 534fa429e1
commit b2718fd1e7
2 changed files with 5 additions and 1 deletions
+4 -1
View File
@@ -111,8 +111,11 @@ in
# Decrypted as a single dotenv file (no `key`) and consumed by the
# systemd user unit opencode-web as EnvironmentFile.
# Source: secrets/opencode.env (encrypted, see sops/age below).
# Path is shared with home/modules/opencode.nix via xlib.dirs so the
# sops materialization and the systemd EnvironmentFile can never
# silently desync.
opencode_server = mkUserSecret {
path = "${xlib.dirs.user-home}/.config/opencode/server.env";
path = xlib.dirs.opencode-server-env;
mode = "0600";
format = "dotenv";
sopsFile = ../secrets/opencode.env;