Skip to content

fix(cli): strip inline comments when parsing .env values - #10101

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
amartinawi:fix/env-inline-comment-quota-driver
Aug 13, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
amartinawi:fix/env-inline-comment-quota-driver

Conversation

@amartinawi

Copy link
Copy Markdown
Contributor

Closes #10100.

loadEnvFile() takes everything after the first =, so KEY=value # note stores the comment text as part of the value. The shipped .env / .env.example do exactly that, so every install runs with:

$ tr '\0' '\n' < /proc/<pid>/environ | grep QUOTA_STORE_DRIVER
QUOTA_STORE_DRIVER=sqlite              # sqlite | redis

$ curl -s -H "authorization: Bearer $KEY" localhost:20128/api/settings/quota-store
{"driver":"sqlite              # sqlite | redis",...}

Why it matters beyond cosmetics

storeFactory.ts compares exactly:

const driver = dbSettings.driver ?? process.env.QUOTA_STORE_DRIVER ?? "sqlite";
if (driver === "redis") { … }

A user who follows the annotation in your own .env.example and writes QUOTA_STORE_DRIVER=redis # sqlite | redis gets driver !== "redis", falls through to SQLite, and sees no warning — the existing QUOTA_STORE_DRIVER=redis but no Redis URL configured warning lives inside the redis branch, so it never fires. Their Redis quota store just never engages. The same trap applies to any variable annotated inline, which the example file encourages.

Change

  • New parseEnvValue() with dotenv-compatible semantics: quoted values verbatim (a # inside quotes is data), unquoted values cut at the first whitespace-preceded # — so pass#word and https://host/page#frag survive.
  • .env.example moves the annotation to its own line.

Tests

New tests/unit/cli-env-inline-comment-10100.test.ts (5 cases): inline comments stripped, # without preceding whitespace preserved, quoted values verbatim incl. a trailing comment after the closing quote, plain values unchanged, plus a guard asserting .env.example never reintroduces an unquoted inline comment on any variable.

node --import tsx/esm --test tests/unit/cli-env-inline-comment-10100.test.ts  -> 5 pass
npx prettier --check                                                          -> clean

loadEnvFile() took everything after the first '=', so 'KEY=value  # note' stored
the comment text as part of the value. The shipped .env/.env.example do exactly
that for QUOTA_STORE_DRIVER, so every install ran with
QUOTA_STORE_DRIVER='sqlite              # sqlite | redis'.

Consumers compare with '===' (storeFactory.ts), so a user following the
annotation in .env.example and writing 'QUOTA_STORE_DRIVER=redis  # ...' got
driver !== 'redis', fell through to SQLite, and saw no warning — the existing
'no Redis URL configured' warning is inside the redis branch and never fires.

parseEnvValue() adopts dotenv semantics: quoted values verbatim (a '#' inside
quotes is data), unquoted values cut at the first whitespace-preceded '#', so
'pass#word' survives. .env.example moves the annotation to its own line.

Closes #10100
@diegosouzapw
diegosouzapw merged commit 92a27f2 into diegosouzapw:release/v3.8.50 Aug 13, 2026
3 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…w#10101)

loadEnvFile() took everything after the first '=', so 'KEY=value  # note' stored
the comment text as part of the value. The shipped .env/.env.example do exactly
that for QUOTA_STORE_DRIVER, so every install ran with
QUOTA_STORE_DRIVER='sqlite              # sqlite | redis'.

Consumers compare with '===' (storeFactory.ts), so a user following the
annotation in .env.example and writing 'QUOTA_STORE_DRIVER=redis  # ...' got
driver !== 'redis', fell through to SQLite, and saw no warning — the existing
'no Redis URL configured' warning is inside the redis branch and never fires.

parseEnvValue() adopts dotenv semantics: quoted values verbatim (a '#' inside
quotes is data), unquoted values cut at the first whitespace-preceded '#', so
'pass#word' survives. .env.example moves the annotation to its own line.

Closes diegosouzapw#10100
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(cli): .env loader keeps inline comments in values — shipped QUOTA_STORE_DRIVER is corrupted

2 participants