From 140c608f8f1cac20844e73f8c33a0053c4e1f119 Mon Sep 17 00:00:00 2001 From: Suriyakumarvijayanayagam Date: Fri, 28 Aug 2026 17:14:23 +0530 Subject: [PATCH] Stop tracking .env; the ignore rules already exclude it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit .gitignore excludes .env and .env.*, with !.env.example negating it for the documented template. Those rules are correct — the comment above them records a previous fix to a "#env" line that was commented out and so matched nothing. But .env was committed while that typo was live, and an ignore rule does not untrack a file that is already in the index. The result is that everyone's local backend choice shows up as a modification to a committed file: M .env VITE_API_PROXY_TARGET: production → 127.0.0.1:8080 Nothing secret is in there today; it holds URLs. The risk is the next value that is not a URL, committed by someone who had no reason to think that file was tracked. .env.example stays, so a fresh checkout still knows what to fill in. The file itself is untouched on disk. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g --- .env | 19 ------------------- 1 file changed, 19 deletions(-) delete mode 100644 .env diff --git a/.env b/.env deleted file mode 100644 index 838819a..0000000 --- a/.env +++ /dev/null @@ -1,19 +0,0 @@ -# Local development against the deployed backend. -# -# The dev server proxies /api and /health to VITE_API_PROXY_TARGET, so the app -# talks to the deployment through its own origin — which is what keeps the -# session cookie (Secure, SameSite=Lax, host-scoped) working in the browser. -VITE_API_BASE_URL=/api/v1 -VITE_API_PROXY_TARGET=https://mcp.krowforce.com - -# Owliver's agent endpoint. -# -# Relative FOR DEVELOPMENT ONLY: vite proxies it to VITE_API_PROXY_TARGET above. -# The production image cannot use a relative value — nginx serves it as a static -# path and answers a run POST with 405 — so Dockerfile passes an absolute URL as -# a build arg instead. Changing this file does not change what ships. -# -# Empty is what it was, and an empty value is not a broken panel: the provider -# answers every question with "Owliver is not configured on this deployment", -# deliberately, because a panel that quietly does nothing is harder to diagnose. -VITE_AGENT_API=/api/v1