forked from bchanot/claude
job7 step A: MAGIC_API_KEY by reference, not by value (BDR-026 follow-up)
toggle-external.sh's `claude mcp add magic --env API_KEY="$MAGIC_API_KEY"`
materialized the key as plaintext into ~/.claude.json — a copy outside the
~/.claude/.env canonical, invisible to the repo's gitignore/allowlist reach.
Claude Code supports ${VAR} expansion in mcpServers config (docs confirmed),
so the fix is a reference, not a scrub.
- lib/toggle-external.sh: --env 'API_KEY=${MAGIC_API_KEY}' (single-quoted
literal reference, not bash-expanded) so future `enable magic` runs write
the safe form too.
- README: new "Adding an MCP server that needs a secret" section documenting
the --env pitfall and the wrapper pattern.
Out-of-repo companion changes (not in this commit): ~/.bashrc gained a
scoped claude() wrapper that sources ~/.claude/.env into a subshell before
exec'ing the real binary (verified: the var never reaches the ambient
interactive shell, only claude + children) — chosen over a global export to
keep the secret's surface minimal. ~/.claude.json's mcpServers.magic.env.API_KEY
was rewritten to the same "${MAGIC_API_KEY}" reference via a surgical jq
edit (never read directly, so the value never entered this session's
context). The 2 of 5 rotating ~/.claude/backups/.claude.json.backup.* files
still holding the old plaintext were scrubbed the same way.
Residual: this session predates the bashrc wrapper, so `claude mcp list`
currently warns "Missing environment variables: MAGIC_API_KEY" — expected,
resolves on next terminal + Claude Code restart. MAGIC_API_KEY rotation
still pending (user action, after this commit).
This commit is contained in:
@@ -188,8 +188,13 @@ enable_tool() {
|
||||
warn "magic already enabled"
|
||||
return 0
|
||||
fi
|
||||
# Reference, not value: Claude Code expands ${VAR} in mcpServers.env at
|
||||
# launch (job7/BDR-026) — MAGIC_API_KEY itself never lands in
|
||||
# ~/.claude.json. The check above still confirms the var IS set in
|
||||
# ~/.claude/.env before wiring the reference, so a missing key fails
|
||||
# here instead of silently at Claude Code startup.
|
||||
claude mcp add magic --scope user \
|
||||
--env API_KEY="$MAGIC_API_KEY" \
|
||||
--env 'API_KEY=${MAGIC_API_KEY}' \
|
||||
-- npx -y @21st-dev/magic@latest
|
||||
ok "magic enabled (user scope)"
|
||||
;;
|
||||
|
||||
Reference in New Issue
Block a user