Skip to content

feat(profile): clamp paragraph + reorder Top Voices above Open Question #134

feat(profile): clamp paragraph + reorder Top Voices above Open Question

feat(profile): clamp paragraph + reorder Top Voices above Open Question #134

name: Lint — no DEV_BYPASS_AUTH references outside src/auth/middleware.ts
# Plan reference:
# plans/2026-05-12-002-feat-managed-agents-full-migration-plan.md §10 + Step 4
#
# Why this exists:
# `DEV_BYPASS_AUTH=demo-a` is a local-only escape hatch that skips
# WorkOS sign-in during the migration's inner loop (Steps 6-10). It is
# read in exactly one place: `src/auth/middleware.ts:getDevBypassAuth()`.
# If a reference leaks into a server fn, route loader, or component,
# the bypass could grant production access on a misconfigured Vercel
# env var. This workflow fails the build if any other file mentions
# the literal string.
#
# Allowed references:
# - src/auth/middleware.ts (the canonical single read)
# - plan/docs files (explanatory references)
# - this workflow file (the literal name appears in error messages)
#
# Note: the separate `lint-no-stale-flag.yml` workflow (plan Step 12)
# guards the `USE_MANAGED_AGENTS` flag and starts failing on day 21
# post-cutover; this one is permanent.
on:
pull_request:
branches: [main]
push:
branches: [main]
permissions:
contents: read
jobs:
lint-no-dev-bypass-leak:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Scan for stray DEV_BYPASS_AUTH env-var reads
run: |
set -e
# Look for `process.env.DEV_BYPASS_AUTH` reads in src/test/scripts.
# The only legal read is in `src/auth/middleware.ts:getDevBypassAuth()`.
# Documentation mentions / error-message references of the literal name
# are allowed elsewhere.
OFFENDERS=$(grep -rln 'process\.env\.DEV_BYPASS_AUTH' src test scripts 2>/dev/null \
| grep -v '^src/auth/middleware\.ts$' \
|| true)
if [ -n "$OFFENDERS" ]; then
echo "::error::process.env.DEV_BYPASS_AUTH read outside src/auth/middleware.ts:"
echo "$OFFENDERS"
exit 1
fi
echo "OK: process.env.DEV_BYPASS_AUTH is only read in src/auth/middleware.ts."