镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

util.parseEnv creates keys from invalid, newline-separated lines #56775

Description

@jonschlinkert

Version

v23.6.1

Platform

Darwin Mac.lan1 24.1.0 Darwin Kernel Version 24.1.0: Thu Oct 10 21:03:11 PDT 2024; root:xnu-11215.41.3~2/RELEASE_ARM64_T6020 arm64

Subsystem

No response

What steps will reproduce the bug?

Do:

import { parseEnv } from 'node:util';

Then create a string with some invalid lines:

foo


bar
baz=whatever

And parse it:

const input = `      foo


bar
baz=whatever
`;

const env = parseEnv(input);
console.log(env);
// Outputs => { 'foo\n\n\nbar\nbaz': 'whatever' }

How often does it reproduce? Is there a required condition?

Tested on node versions v21x-v23.6.1

What is the expected behavior? Why is that the expected behavior?

Expected behavior, IMHO, would be throw an invalid syntax error.

What do you see instead?

Invalid output.

Additional information

No response

Activity

  1. anonrig commented on Jan 26, 2025

    @anonrig
    Member

    How does dotenv handle this? I think this is expected behavior.

  2. added
    dotenvIssues and PRs related to .env file parsing.
    on Jan 26, 2025
  3. AugustinMauroy commented on Jan 26, 2025

    @AugustinMauroy
    Member

    IMO node should output:

    {
      foo: true,
      bar: true,
      baz: 'whatever',
    }

    and dotenv do that

    const dotenv = require('dotenv');
    
    const input = `      foo
    
    
    bar
    baz=whatever
    `;
    
    const output = dotenv.parse(input);
    
    console.log(output); // => { baz: 'whatever' }

    Tested on v24.0.0-pre

  4. anonrig commented on Jan 26, 2025

    @anonrig
    Member

    I think dotenv's behavior is more correct. But dotenv also supports multiline arguments. I think we shouldn't accept newline characters when parsing key's

  5. AugustinMauroy commented on Jan 26, 2025

    @AugustinMauroy
    Member

    supports multiline arguments

    I never heard about that. Could you give me an example.

    you mean that ?

  6. anonrig commented on Jan 26, 2025

    @anonrig
    Member

    supports multiline arguments

    I never heard about that. Could you give me an example.

    you mean that ?

    Line 72 of https://github.com/nodejs/node/blob/main/test/parallel/test-dotenv.js

  7. AugustinMauroy commented on Jan 26, 2025

    @AugustinMauroy
    Member

    +1 for Dotenv behavior. We should use same fixtures

    Can I fix this issue ? i know the answers is yes But I mean is it an easy task.
    And where is the affected code ?

  8. anonrig commented on Jan 26, 2025

    @anonrig
    Member

    +1 for Dotenv behavior. We should use same fixtures

    Can I fix this issue ? i know the answers is yes But I mean is it an easy task.
    And where is the affected code ?

    Yes, node_dotenv.cc

  9. jonschlinkert commented on Jan 27, 2025

    @jonschlinkert
    Author

    But dotenv also supports multiline arguments

    I think multiline arguments are more common than multiline keys

  10. jonschlinkert commented on Jan 27, 2025

    @jonschlinkert
    Author

    IMO node should output:

    {
    foo: true,
    bar: true,
    baz: 'whatever',
    }

    I'll go with whatever the consensus is, but IMHO foo and bar in that example shouldn't set to true, since there is no =. sign. It seems like stricter behavior would be safer.

  11. jonschlinkert commented on Jan 27, 2025

    @jonschlinkert
    Author

    Since one doesn't exist, I thought i would get a spec started for .env: https://github.com/env-lang/env/blob/main/env.md

    I'm open to any level of contributions if anyone is interested.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.dotenvIssues and PRs related to .env file parsing.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions