()
| 354 | // operator-set value must fit the shared grammar and avoid reserved root |
| 355 | // segments (api, mcp, login, …) — a colliding slug would shadow real routes. |
| 356 | const resolveOrgSlug = (): string => { |
| 357 | const slug = process.env.EXECUTOR_ORG_SLUG; |
| 358 | if (!slug) return "default"; |
| 359 | if (!isValidOrgSlug(slug) && slug !== "default") { |
| 360 | // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: a colliding org slug would shadow app routes; refuse to boot |
| 361 | throw new Error( |
| 362 | `EXECUTOR_ORG_SLUG ${JSON.stringify(slug)} is not usable as a URL slug (2-48 chars of [a-z0-9-], not a reserved path segment like "api" or "login")`, |
| 363 | ); |
| 364 | } |
| 365 | return slug; |
| 366 | }; |
| 367 | |
| 368 | // EXECUTOR_TOOLS_SYNC_TTL_MS — how long a remote tool catalog (an MCP server's |
| 369 | // tool set, which changes server-side with no executor-visible signal) stays |
no test coverage detected