From 56282c508064893bd029bae3e028f41faca96b78 Mon Sep 17 00:00:00 2001 From: Eric Date: Wed, 27 May 2026 14:33:42 -0700 Subject: [PATCH] [eric] build: stop shipping the dead google client id/secret that nothing reads at runtime --- scripts/build-app-win.ps1 | 17 ++++------------- scripts/build-app.sh | 22 ++++------------------ 2 files changed, 8 insertions(+), 31 deletions(-) diff --git a/scripts/build-app-win.ps1 b/scripts/build-app-win.ps1 index 1ac8c5cd..ad7b47b5 100644 --- a/scripts/build-app-win.ps1 +++ b/scripts/build-app-win.ps1 @@ -367,27 +367,18 @@ if (Test-Path $EnvExampleSrc) { # so extraResources can substitute ${arch} (matches the mac build). # Production .env: OAuth helper base URL + Google credentials. See -# scripts/build-app.sh for the rationale; v1.0.29 cloud-proxied the OAuth flow, -# but the bundled google_workspace_mcp still needs CLIENT_SECRET at startup. -# v1.0.30 plans to fork or replace that MCP and drop the secret here. +# Google client_id/secret are no longer shipped: nothing reads them at runtime, +# so we don't bake a secret into the .env. $ShipOauthBaseUrl = if ($env:OPENSWARM_OAUTH_BASE_URL_OVERRIDE) { $env:OPENSWARM_OAUTH_BASE_URL_OVERRIDE } else { 'https://api.openswarm.com' } -$GoogleClientIdShip = $env:GOOGLE_OAUTH_CLIENT_ID -$GoogleClientSecretShip = $env:GOOGLE_OAUTH_CLIENT_SECRET -if (-not $GoogleClientIdShip -or -not $GoogleClientSecretShip) { - Write-Host "ERROR: GOOGLE_OAUTH_CLIENT_ID/SECRET missing in backend\.env -- required for Google MCP." -ForegroundColor Red - exit 1 -} $ShipEnvPath = Join-Path $Staging 'backend\.env' New-Item -ItemType Directory -Force -Path (Split-Path $ShipEnvPath -Parent) | Out-Null @( - "# OAuth helper base URL + Google OAuth credentials.", - "OPENSWARM_OAUTH_BASE_URL=$ShipOauthBaseUrl", - "GOOGLE_OAUTH_CLIENT_ID=$GoogleClientIdShip", - "GOOGLE_OAUTH_CLIENT_SECRET=$GoogleClientSecretShip" + "# OAuth helper base URL.", + "OPENSWARM_OAUTH_BASE_URL=$ShipOauthBaseUrl" ) | Set-Content -Path $ShipEnvPath Write-Host "Staged production .env" diff --git a/scripts/build-app.sh b/scripts/build-app.sh index 2f33e15a..086509e1 100755 --- a/scripts/build-app.sh +++ b/scripts/build-app.sh @@ -401,28 +401,14 @@ rsync -a \ # would strip it. The top-level backend/.env is still excluded (it's # (re)generated at the production .env step below). -# Production .env: OAuth helper base URL + Google client_id and client_secret. -# v1.0.29 moved the *OAuth flow* (auth-code exchange + refresh) to the Fly -# cloud-proxy, so the OAuth flow itself no longer reads client_secret on the -# desktop. But the bundled google_workspace_mcp Python package still requires -# CLIENT_SECRET at startup to do its own token refresh per Google API call -# (see backend/apps/tools_lib/tools_lib.py for the deferred-fix note). -# Until we fork or replace that MCP in v1.0.30, the secret still ships here. +# Production .env: just the OAuth helper base URL. Google client_id/secret are no +# longer shipped: nothing in backend/ or frontend/ reads GOOGLE_OAUTH_CLIENT_{ID, +# SECRET} at runtime, so we don't bake a secret into the packaged app. SHIP_OAUTH_BASE_URL="${OPENSWARM_OAUTH_BASE_URL_OVERRIDE:-https://api.openswarm.com}" -GOOGLE_CLIENT_ID_SHIP="${GOOGLE_OAUTH_CLIENT_ID:-}" -GOOGLE_CLIENT_SECRET_SHIP="${GOOGLE_OAUTH_CLIENT_SECRET:-}" -if [[ -z "$GOOGLE_CLIENT_ID_SHIP" || -z "$GOOGLE_CLIENT_SECRET_SHIP" ]]; then - echo "ERROR: GOOGLE_OAUTH_CLIENT_ID/SECRET missing in $ENV_FILE — required for Google MCP." - exit 1 -fi mkdir -p "$STAGING_DIR/backend" cat > "$STAGING_DIR/backend/.env" <