This project is configured to fail closed for sensitive endpoints.
LT1_VOTE_ENABLED=falseby default.LT1_PRESENTER_CANCEL_ENABLED=falseby default.LT1_SUBMIT_ENABLED=trueby default.VITE_LT1_VOTE_ENABLED=falsehides the vote page in frontend.
SESSION_SECRET: minimum 32 bytes.DISCORD_CLIENT_SECRET: OAuth secret.DISCORD_WEBHOOK_URL: server-side only.
TRUST_PROXY=trueTRUSTED_PROXY_PROVIDER=vercelorcloudflareKV_REST_API_URLandKV_REST_API_TOKENfor atomic vote deduplication.
- Disable affected endpoints immediately:
- set
LT1_VOTE_ENABLED=false - set
LT1_PRESENTER_CANCEL_ENABLED=false - set
LT1_SUBMIT_ENABLED=falseif needed
- set
- Rotate secrets:
SESSION_SECRETDISCORD_CLIENT_SECRETDISCORD_WEBHOOK_URL
- Review provider logs:
- Vercel request logs
- Discord webhook access patterns
- Re-enable features only after root cause is confirmed.
.envmust never be committed.- Keep dependency and runtime updates current.