feat(secrets): .env source-of-truth in ~/.claude + repo symlink

Move the real secret out of the git tree: the key lives in ~/.claude/.env
(outside the repo), and link.sh symlinks repo/.env -> ~/.claude/.env so
`source "$REPO/.env"` resolves transparently. The secret never enters git —
not as content (it's a link) and not by accident (gitignored).

link.sh: add link_env() — verify ~/.claude/.env exists + has MAGIC_API_KEY
(warn, never create/copy the secret), then create repo/.env -> ~/.claude/.env.
Defensive + idempotent: links only when repo/.env is absent or already the
right symlink; a residual REAL repo/.env is left untouched with a migrate hint
(never clobbered, so the secret can't be destroyed).

.gitignore: harden .env -> .env + .env.* + !.env.example (covers .env.local,
.env.bak, .env.save; keeps the template tracked).

Messages point at ~/.claude/.env (the canonical edit location) instead of the
ambiguous $REPO/.env: design-tool-gate.sh gate output, design-gate.md
(branch 3 + IMPORTANT), toggle-external.sh, install-plugins.sh.

Verified: shellcheck clean (link.sh, toggle-external.sh, design-tool-gate.sh);
link.sh created the symlink (1 change, idempotent re-run); repo/.env absent
from git status; magic-off path still exits 10 with the ~/.claude/.env hint.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Bastien Chanot
2026-06-21 11:44:47 +02:00
co-authored by Claude Opus 4.8
parent 2e6725e8bb
commit 131d0bcb5d
6 changed files with 35 additions and 7 deletions
+1 -1
View File
@@ -618,7 +618,7 @@ if [ -x "$REPO/lib/toggle-external.sh" ]; then
ok "magic MCP disabled (default)"
fi
if [ ! -f "$REPO/.env" ] || ! grep -q '^MAGIC_API_KEY=' "$REPO/.env" 2>/dev/null; then
warn "MAGIC_API_KEY not found in $REPO/.env — copy .env.example and set your key before enabling"
warn "MAGIC_API_KEY not found in ~/.claude/.env — copy .env.example there and set your key before enabling"
fi
else
warn "lib/toggle-external.sh not found or not executable — skipping"