// server-only github app config, read from worker bindings or $env/dynamic/private. // GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET and GITHUB_APP_SLUG identify the app, and the // oauth callback url is /_internal/github/callback. // GITHUB_SESSION_SECRET seals the connection cookie; at least 32 random bytes, and // rotating it signs every existing connection out. never prefix these with VITE_/PUBLIC_. import { env as privateEnv } from "$env/dynamic/private"; export interface GitHubEnv { clientId: string; clientSecret: string; secret: string; appSlug: string; publicOrigin: string; apiOrigin: string; avatarsOrigin: string; } // workers provide bindings via platform.env while $env/dynamic/private is empty export const githubEnv = (platform?: App.Platform): GitHubEnv => { const bound = platform?.env as Record | undefined; const read = (key: string) => privateEnv[key as keyof typeof privateEnv]?.trim() || bound?.[key]?.trim() || ""; const origin = (key: string, fallback: string) => (read(key) || fallback).replace(/\/+$/, ""); return { clientId: read("GITHUB_CLIENT_ID"), clientSecret: read("GITHUB_CLIENT_SECRET"), secret: read("GITHUB_SESSION_SECRET"), appSlug: read("GITHUB_APP_SLUG"), publicOrigin: origin("GITHUB_PUBLIC_ORIGIN", "https://github.com"), apiOrigin: origin("GITHUB_API_ORIGIN", "https://api.github.com"), avatarsOrigin: origin("GITHUB_AVATARS_ORIGIN", "https://avatars.githubusercontent.com") }; }; export const hostOf = (origin: string) => new URL(origin).hostname;