Summary
The security fixes left two pieces of dead code. Removing them stops a future change from reviving a closed path by accident.
Where
Fix plan
- Delete
createDirectMessageChannel.ts and its line in apps/webapp/src/api/rpc/index.ts.
- Delete the
NEXT_PUBLIC_ELASTIC_APM_SECRET_TOKEN line. If NEXT_PUBLIC_ELASTIC_APM_SERVER_URL (:343) also has no reader, delete it too.
Acceptance criteria
Summary
The security fixes left two pieces of dead code. Removing them stops a future change from reviving a closed path by accident.
.env.exampleWhere
apps/webapp/src/api/rpc/createDirectMessageChannel.tsand its re-export atapps/webapp/src/api/rpc/index.ts:2. The RPC is service-role only since Carry the production function revokes in the Supabase migrations #397, and no code imports the wrapper..env.example:344—NEXT_PUBLIC_ELASTIC_APM_SECRET_TOKEN=. No code reads it. TheNEXT_PUBLIC_prefix would inline a secret into the client bundle the day code reads it (same reason Keep server secrets out of the webapp and admin-dashboard containers #403 removedNEXT_PUBLIC_SPACES_SECRET).Fix plan
createDirectMessageChannel.tsand its line inapps/webapp/src/api/rpc/index.ts.NEXT_PUBLIC_ELASTIC_APM_SECRET_TOKENline. IfNEXT_PUBLIC_ELASTIC_APM_SERVER_URL(:343) also has no reader, delete it too.Acceptance criteria
grep -rn "createDirectMessageChannel\|ELASTIC_APM" apps packagesreturns nothing.bun run --filter @docs.plus/webapp typecheckand lint pass.