From 295d0acc2f2eda44200ee492093fada55eb59ab1 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Wed, 23 Sep 2026 13:11:32 -0700 Subject: [PATCH] at: the Bluesky CLI reads the vault's env when at/.env is absent at/cli.mjs only loaded a .env from its own folder, which this machine never had, so the x MCP's bluesky_post (which shells out to it) failed with 'Set BSKY_IDENTIFIER and BSKY_APP_PASSWORD' while the credentials sat in vault/at/.env the whole time. It now falls back to the vault copy; the shell environment still wins over both. --- at/cli.mjs | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/at/cli.mjs b/at/cli.mjs index 4152dbb216..018f641ec7 100755 --- a/at/cli.mjs +++ b/at/cli.mjs @@ -6,7 +6,14 @@ // Follows the same pattern as memory/cli.mjs and papers/cli.mjs. import { config } from "dotenv"; -config(); // Load .env from at/ directory +import { dirname, resolve as resolvePath } from "node:path"; +import { fileURLToPath } from "node:url"; +// Credentials: at/.env when devault.fish has copied one here, otherwise the +// vault's own copy. dotenv never overrides a key that is already set, so the +// first file found wins and the shell environment beats both. +const here = dirname(fileURLToPath(import.meta.url)); +config({ path: resolvePath(here, ".env") }); +config({ path: resolvePath(here, "../vault/at/.env") }); const PDS_URL = process.env.PDS_URL || "https://at.aesthetic.computer"; // Two endpoints, not one. Reads go to the unauthenticated AppView; writes go -- 2.51.2