Skip to content

fix: warn when the environment overrides a .env setting - #57

Merged
davidmckayv merged 1 commit into
CopilotKit:mainfrom
asasemahmed:fix/env-shadowed-warning
Sep 25, 2026
Merged

davidmckayv merged 1 commit into
CopilotKit:mainfrom
asasemahmed:fix/env-shadowed-warning

Conversation

@asasemahmed

Copy link
Copy Markdown
Contributor

What changed

process.loadEnvFile(".env") never overrides variables that are already set. A stale shell export or a system-wide variable therefore silently wins over .env. In practice, a system-wide OPENAI_API_KEY for OpenAI gets sent to the OPENAI_BASE_URL gateway instead of the gateway key in .env. The only symptom is a provider authentication error in chat ("Missing Authentication header" from OpenRouter), which points nowhere near the cause.

On startup, the server now logs the .env keys whose value is replaced by a different environment value:

[OpenMuse] Using OPENAI_API_KEY from the environment instead of .env. Unset it to use the .env value.

Only key names are logged, never values. Loading precedence is unchanged.

Verification

  • A new tests/config.test.ts case covers a different value, an identical value, a key present only in .env, and an empty .env value.
  • On a Windows machine with a system-wide OPENAI_API_KEY and a different gateway key in .env, the warning printed with the key name only.
  • pnpm typecheck and pnpm build:server pass. Biome reports no issues for the changed files.
  • pnpm test: 162 passed, 1 failed. The failure is Docker subprocess uses literal argv…, which fails on Windows with or without this change.

Integration limits

pnpm dev:browser loads .env with node --env-file, which has the same precedence; this change only covers the API and task worker.

process.loadEnvFile never overrides variables that are already set, so
a stale shell export or a system-wide variable silently wins over
.env. For example, a system-wide OPENAI_API_KEY for OpenAI gets sent
to an OPENAI_BASE_URL gateway instead of the gateway key in .env, and
the only symptom is a provider authentication error.

On startup, name the .env keys whose value is replaced by a different
environment value. Only key names are logged, never values. Loading
precedence is unchanged.
@davidmckayv
davidmckayv merged commit 71036e4 into CopilotKit:main Sep 25, 2026
7 checks passed
jerelvelarde added a commit to jerelvelarde/openmuse-1 that referenced this pull request Sep 29, 2026
Resolve tests/config.test.ts: keep both the Jev mode test and main's
shadowed-.env test (CopilotKit#57).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants