mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
xlib+users: centralize opencode server.env path
The path '/home/<user>/.config/opencode/server.env' was duplicated between users.nix (sops materialization) and home/modules/opencode.nix (programs.opencode.web.environmentFile). Drift between the two was a silent auth-bypass vector: if one moved, the systemd unit would either fail to find OPENCODE_SERVER_PASSWORD or skip EnvironmentFile entirely. Single source in lib/xlib/dirs.nix; both call sites now read from it.
This commit is contained in:
@@ -14,6 +14,7 @@ in
|
|||||||
server-home
|
server-home
|
||||||
services-mnt-folder
|
services-mnt-folder
|
||||||
;
|
;
|
||||||
|
opencode-server-env = "${user-home}/.config/opencode/server.env";
|
||||||
|
|
||||||
user-storage = "${user-home}/Storage";
|
user-storage = "${user-home}/Storage";
|
||||||
wsl-storage = "${wsl-home}/Storage";
|
wsl-storage = "${wsl-home}/Storage";
|
||||||
|
|||||||
+4
-1
@@ -111,8 +111,11 @@ in
|
|||||||
# Decrypted as a single dotenv file (no `key`) and consumed by the
|
# Decrypted as a single dotenv file (no `key`) and consumed by the
|
||||||
# systemd user unit opencode-web as EnvironmentFile.
|
# systemd user unit opencode-web as EnvironmentFile.
|
||||||
# Source: secrets/opencode.env (encrypted, see sops/age below).
|
# Source: secrets/opencode.env (encrypted, see sops/age below).
|
||||||
|
# Path is shared with home/modules/opencode.nix via xlib.dirs so the
|
||||||
|
# sops materialization and the systemd EnvironmentFile can never
|
||||||
|
# silently desync.
|
||||||
opencode_server = mkUserSecret {
|
opencode_server = mkUserSecret {
|
||||||
path = "${xlib.dirs.user-home}/.config/opencode/server.env";
|
path = xlib.dirs.opencode-server-env;
|
||||||
mode = "0600";
|
mode = "0600";
|
||||||
format = "dotenv";
|
format = "dotenv";
|
||||||
sopsFile = ../secrets/opencode.env;
|
sopsFile = ../secrets/opencode.env;
|
||||||
|
|||||||
Reference in New Issue
Block a user