Safe parser for config.env and .env #5

Closed
opened 2026-10-05 07:47:57 +02:00 by Tirsvad · 0 comments
Owner

Read KEY=VALUE lines without source or eval; accept only whitelisted keys, strip optional quotes, reject control characters, and validate that service URLs are well-formed https and that credentials are non-empty. Warn when .env is readable by other users.

Phase: MIL-001

Read `KEY=VALUE` lines without `source` or `eval`; accept only whitelisted keys, strip optional quotes, reject control characters, and validate that service URLs are well-formed `https` and that credentials are non-empty. Warn when `.env` is readable by other users. Phase: MIL-001
Tirsvad added this to the MIL-001 Foundation milestone 2026-10-05 07:47:57 +02:00
Sign in to join this conversation.