From 940a9bf229c66eb340fa8feadee9a348f01e9c38 Mon Sep 17 00:00:00 2001 From: Kresna <13603341+slaveofcode@users.noreply.github.com> Date: Sun, 27 Sep 2026 12:23:08 +0700 Subject: [PATCH] fix(report): hardcode real Turnstile site key default (build-var-proof) --- src/config.ts | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/src/config.ts b/src/config.ts index 0f19dc9..3c175ba 100644 --- a/src/config.ts +++ b/src/config.ts @@ -37,6 +37,10 @@ export const NOINDEX = * Falls back to 'dev' for local/dev where it isn't set. Public, non-secret. */ export const BUILD_SHA = import.meta.env.PUBLIC_BUILD_SHA || 'dev'; -/** Cloudflare Turnstile PUBLIC site key (not a secret). Defaults to Cloudflare's - * always-pass test key so self-host/staging work before a real key is set. */ -export const TURNSTILE_SITE_KEY = import.meta.env.PUBLIC_TURNSTILE_SITE_KEY || '1x00000000000000000000AA'; +/** Cloudflare Turnstile PUBLIC site key (not a secret — it renders in every + * visitor's page). Hardcoded as the default like GA_ID, because Cloudflare build + * vars have been dropped in prod before; the PUBLIC_ override still wins if set. + * The matching Secret Key lives in the TURNSTILE_SECRET Worker secret. Forks/ + * self-host can override with PUBLIC_TURNSTILE_SITE_KEY (Cloudflare test key + * 1x00000000000000000000AA always passes). */ +export const TURNSTILE_SITE_KEY = import.meta.env.PUBLIC_TURNSTILE_SITE_KEY || '0x4AAAAAAFE6EiMkO_xbnWQL';