feat(tlsync): fetch short-lived token from API before multiplayer connect
app-ci-deploy / test-build-deploy (push) Has been cancelled

- Remove VITE_TLSYNC_SECRET from browser env (no longer exposed to bundle)
- Add useTlsyncToken hook that fetches /api/tlsync/token with Supabase auth
- Extract TldrawCanvas sub-component: only renders after token is ready
- Pass API-issued short-lived token to createSyncConnectionOptions
- Add vite.config.ts blocklist to prevent secret leak (defense-in-depth)
- Remove VITE_TLSYNC_SECRET from .env.example (server-side only now)

Related: t_a69128a1 (API token endpoint), t_41a844a7 (this task)
This commit is contained in:
2026-05-28 18:00:43 +01:00
parent 0db53bfd9c
commit 67e47fc47f
4 changed files with 161 additions and 80 deletions
+4 -4
View File
@@ -15,6 +15,7 @@ export interface SyncConnectionOptions {
color: string;
roomId?: string;
baseUrl: string;
token?: string;
}
export function createSyncConnectionOptions(options: SyncConnectionOptions) {
@@ -22,8 +23,8 @@ export function createSyncConnectionOptions(options: SyncConnectionOptions) {
userId,
displayName,
roomId = 'multiplayer',
baseUrl
baseUrl,
token
} = options;
// Ensure we have valid user info
@@ -72,8 +73,7 @@ export function createSyncConnectionOptions(options: SyncConnectionOptions) {
roomId: effectiveRoomId
});
const token = import.meta.env.VITE_TLSYNC_SECRET ?? ''
const tokenParam = token ? `?token=${encodeURIComponent(token)}` : ''
const tokenParam = token ? `?token=${encodeURIComponent(token)}` : '';
return {
uri: `${baseUrl}/connect/${effectiveRoomId}${tokenParam}`,