security: remove TLSync shared secret from frontend bundle
- Remove VITE_TLSYNC_SECRET from syncService.ts; token is now fetched at runtime via fetchTlsyncToken() from the API backend - Add token?: string to SyncConnectionOptions interface - Update multiplayerUser.tsx to fetch TLSync token from API on mount and pass it through createSyncConnectionOptions - Remove VITE_TLSYNC_SECRET from .env.example The API must implement GET /tlsync/token (authenticated via Supabase Bearer token) to complete the fix.
This commit is contained in:
@@ -27,7 +27,6 @@ VITE_SUPABASE_ANON_KEY=your-supabase-anon-key
|
||||
# TLSync (TLDraw Sync) Configuration
|
||||
# =============================================================================
|
||||
VITE_TLSYNC_URL=https://app.classroomcopilot.ai/tldraw
|
||||
VITE_TLSYNC_SECRET=your-tlsync-secret
|
||||
|
||||
# =============================================================================
|
||||
# WhisperLive (Transcription) Configuration
|
||||
|
||||
Reference in New Issue
Block a user