WEB-026
write-env: .env.local for site/admin from the local stack (+ generated HMAC/VAPID/role JWTs), committed .env.example with every later key; never overwrites owner values
Evidence
From logs/evidence/WEB-026/. Click a thumbnail for the full image.
No evidence files in logs/evidence/WEB-026/.
Tests
$ node tools/web/write-env.mjs --check && git check-ignore -q apps/site/.env.local && git check-ignore -q apps/admin/.env.local && ! git check-ignore -q apps/site/.env.example && node tools/web/secrets-scan.mjsNotes
2026-10-04 14:51 UTC · tools/web/write-env.mjs (pnpm db:env): fills apps/{site,admin}/.env.local from `supabase status -o env` + generated REVALIDATE_SECRET (shared), VAPID keys (web-push), SITE_SERVER_JWT/JOB_WORKER_JWT (HS256, local secret, 10y); idempotent, never overwrites set values, keeps owner extras; writes committed .env.example with every later key (GITHUB_TOKEN, CLAUDE_CODE_OAUTH_TOKEN/ANTHROPIC_API_KEY, AI_ENABLED/AI_RUNNER, ADMIN_PUBLIC_URL/ALLOWED_ORIGINS, Google client id, gateway/public-api URLs). --check: required keys, equal HMAC, no admin secrets in the site env.
