fix(meta): PR #175 review round — all 14 findings addressed

H1 godot-cold-parse exit-code guard (+bonus: import-pass for cold checkouts, found live); H2 pr-watchlist-diff loud registry failure; H3/T1 deny list :* normalization (add-only) + uniform allow syntax; H4/T7 helper-script allows; H5 get_api_key env-only (config.json is tracked — no secret fallback); H6 TEAM.md active/standby split; H7 troblum solo-profiling note; H8 pr-review frontmatter Task->Agent; H9 conventions doc taxonomies fixed vs real tree; T2 ask-gate leash files (settings/hooks) in tracked settings; T3 R-013 cross-reference; T4 governance README index regenerated (pql decisions sync); T5 dudley briefing ACTIVE; T6 pr-process step 7 run-from-main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-13 22:11:36 +02:00
co-authored by Claude Fable 5
parent c9d9b56933
commit 6c078fbec4
12 changed files with 121 additions and 32 deletions
+13 -12
View File
@@ -75,24 +75,25 @@ def get_base_url(key: str, default: str) -> str:
return load_config().get(key, default)
def get_api_key(env_var: str, config_key: str) -> str:
"""Get an API key from the environment or config.json.
def get_api_key(env_var: str, config_key: str = "") -> str:
"""Get an API key from the environment — environment-only, by design.
Checks the ``env_var`` environment variable first, then ``config_key`` in
config.json. Prints a JSON error and exits 1 if neither is set — connector
scripts emit machine-readable JSON on all paths.
``tooling/db/config.json`` is a *tracked* file and holds endpoints only;
it must never carry secrets, so there is deliberately no config.json
fallback here (the old one steered users toward committing paid API keys).
``config_key`` is retained in the signature for caller compatibility but
is ignored. Prints a JSON error and exits 1 if the variable is unset —
connector scripts emit machine-readable JSON on all paths.
"""
key = os.environ.get(env_var)
if key:
return key
try:
with open(CONFIG_PATH) as f:
config = json.load(f)
return config.get(config_key, "")
except Exception:
pass
print(json.dumps({
"ok": False,
"error": f"No {env_var} found in environment or config.json"
"error": (
f"{env_var} not set. Export it in your shell or add it to the "
"machine-local .claude/settings.local.json env block (untracked). "
"Never put keys in tooling/db/config.json — it is tracked."
)
}, indent=2))
sys.exit(1)