Skip to content

docs(config): make .env.example match what the backend actually reads - #5

Merged
yougijain merged 1 commit into
mainfrom
claude/peaceful-tesla-77gfuy
Sep 17, 2026
Merged

yougijain merged 1 commit into
mainfrom
claude/peaceful-tesla-77gfuy

Conversation

@yougijain

@yougijain yougijain commented Sep 17, 2026 •

Copy link
Copy Markdown
Owner

Config-only change, found while wiring up the Supabase scenario store. No code touched.

The problem

backend/.env.example listed three Supabase variables:

SUPABASE_URL=https://gsfrghcurkixqmrqghaw.supabase.co
SUPABASE_ANON_KEY=sb_publishable_xxxxxxxxxxxxxxxxxxxx
SUPABASE_SERVICE_ROLE_KEY=

Nothing reads any of them. The backend's entire env surface is five variables:

$ grep -rn "os.environ\|os.getenv" backend/app/
main.py:59       LINELAB_CORS_ORIGINS
main.py:65       LINELAB_CORS_ORIGIN_REGEX
scenarios.py:32  LINELAB_DATA_DIR
chat.py:37       ANTHROPIC_API_KEY
db.py:48         SUPABASE_DB_URL

db.py connects as postgres over the pooler and bypasses RLS on its own, which its docstring already says — no service-role key is involved. So the example was instructing you to fetch and paste a high-privilege secret into a variable with no effect. That is a bad habit to encode in the file people copy first.

The change

.env.example now documents exactly the five variables the code reads, grouped by purpose, each saying what happens when it is left unset — and noting that SUPABASE_DB_URL contains the database password and belongs in host environment variables, never in vercel.json.

The README gains a short section on the scenario store: the schema is created on first connect via ensure_ready rather than a migration step, and public.scenarios runs RLS enabled with no policies on purpose. The API is the table's only client; leaving RLS off would make the table readable and writable by anyone holding the project's publishable key, which is public by design.

Database state

The LineLab Supabase project was restored from its paused state and provisioned to match db.py's SCHEMA constant, so the app's own create table if not exists is a no-op:

  • public.scenarios created, RLS enabled, no policies.
  • The five built-in teaching spots seeded; select ... order by builtin desc, created_at asc returns them in the order list_scenarios() expects.
  • Supabase security advisor returns no lints.

Setting SUPABASE_DB_URL in the Vercel dashboard is the only remaining step, and it is manual — it carries the database password, and the Vercel MCP server exposes no environment-variable tool.

The example listed SUPABASE_URL, SUPABASE_ANON_KEY and
SUPABASE_SERVICE_ROLE_KEY. Nothing reads any of them — the backend's only
Supabase input is SUPABASE_DB_URL. Worse, it instructed you to paste a
service_role key, a high-privilege secret, for a variable that has no effect.

The file now documents exactly the five variables the code reads
(LINELAB_CORS_ORIGINS, LINELAB_CORS_ORIGIN_REGEX, LINELAB_DATA_DIR,
SUPABASE_DB_URL, ANTHROPIC_API_KEY), each with what happens when it is unset.

Also documents the scenario store in the README: that the schema is created on
first connect rather than via a migration step, and why public.scenarios runs
RLS-enabled with no policies.
@vercel

vercel Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
linelab Ready Ready Preview Sep 17, 2026 4:33pm UTC
linelab-api Ready Ready Preview Sep 17, 2026 4:33pm UTC

@yougijain
yougijain marked this pull request as ready for review September 17, 2026 16:38
@yougijain
yougijain merged commit 47f38eb into main Sep 17, 2026
5 checks passed

This branch was successfully deployed

2 active deployments
Preview – linelab — f4d76836 Deployed Sep 17, 2026 by vercel[bot]
Preview – linelab-api — f4d76836 Deployed Sep 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant