feat(env): enforce paired PayPal credentials in env validation
CI / check (push) Successful in 2m28s
CI / deploy (push) Successful in 1m28s
CI / publish-container (push) Successful in 47s

Add superRefine rule in src/env.ts ensuring that if one PayPal credential (PAYPAL_CLIENT_ID or PAYPAL_SECRET) is set in production, the other is also required, catching configuration drift at startup.
This commit is contained in:
openhands committed 2026-09-13 13:36:03 +02:00
1 parent cbf056838f
commit 7852e2f5fe
1 file changed
+16
+16
View File
@@ -112,6 +112,7 @@ const schema = z
})
.superRefine((data, ctx) => {
if (data.NODE_ENV !== "production") return;
// AUTH_SECRET
if (!data.AUTH_SECRET || data.AUTH_SECRET.length < 32) {
ctx.addIssue({
code: "custom",
@@ -120,6 +121,21 @@ const schema = z
path: ["AUTH_SECRET"],
});
}
// PayPal credentials must be paired.
if (data.PAYPAL_CLIENT_ID && !data.PAYPAL_SECRET) {
ctx.addIssue({
code: "custom",
message: "PAYPAL_SECRET is required when PAYPAL_CLIENT_ID is set",
path: ["PAYPAL_SECRET"],
});
}
if (!data.PAYPAL_CLIENT_ID && data.PAYPAL_SECRET) {
ctx.addIssue({
code: "custom",
message: "PAYPAL_CLIENT_ID is required when PAYPAL_SECRET is set",
path: ["PAYPAL_CLIENT_ID"],
});
}
});
type Env = z.infer<typeof schema>;