Repository navigation
docs(config): make .env.example match what the backend actually reads - #5
Merged
Merged
Conversation
The example listed SUPABASE_URL, SUPABASE_ANON_KEY and SUPABASE_SERVICE_ROLE_KEY. Nothing reads any of them — the backend's only Supabase input is SUPABASE_DB_URL. Worse, it instructed you to paste a service_role key, a high-privilege secret, for a variable that has no effect. The file now documents exactly the five variables the code reads (LINELAB_CORS_ORIGINS, LINELAB_CORS_ORIGIN_REGEX, LINELAB_DATA_DIR, SUPABASE_DB_URL, ANTHROPIC_API_KEY), each with what happens when it is unset. Also documents the scenario store in the README: that the schema is created on first connect rather than via a migration step, and why public.scenarios runs RLS-enabled with no policies.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
yougijain
marked this pull request as ready for review
September 17, 2026 16:38
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Config-only change, found while wiring up the Supabase scenario store. No code touched.
The problem
backend/.env.examplelisted three Supabase variables:Nothing reads any of them. The backend's entire env surface is five variables:
db.pyconnects aspostgresover the pooler and bypasses RLS on its own, which its docstring already says — no service-role key is involved. So the example was instructing you to fetch and paste a high-privilege secret into a variable with no effect. That is a bad habit to encode in the file people copy first.The change
.env.examplenow documents exactly the five variables the code reads, grouped by purpose, each saying what happens when it is left unset — and noting thatSUPABASE_DB_URLcontains the database password and belongs in host environment variables, never invercel.json.The README gains a short section on the scenario store: the schema is created on first connect via
ensure_readyrather than a migration step, andpublic.scenariosruns RLS enabled with no policies on purpose. The API is the table's only client; leaving RLS off would make the table readable and writable by anyone holding the project's publishable key, which is public by design.Database state
The
LineLabSupabase project was restored from its paused state and provisioned to matchdb.py'sSCHEMAconstant, so the app's owncreate table if not existsis a no-op:public.scenarioscreated, RLS enabled, no policies.select ... order by builtin desc, created_at ascreturns them in the orderlist_scenarios()expects.Setting
SUPABASE_DB_URLin the Vercel dashboard is the only remaining step, and it is manual — it carries the database password, and the Vercel MCP server exposes no environment-variable tool.