Skip to content

List paths with -z so quoted paths are not skipped - #1

Open
WatchTree-19 wants to merge 1 commit into
automazeio:mainfrom
WatchTree-19:fix/quoted-paths
Open

WatchTree-19 wants to merge 1 commit into
automazeio:mainfrom
WatchTree-19:fix/quoted-paths

Conversation

@WatchTree-19

Copy link
Copy Markdown

StagedFiles, TrackedFiles, ManagedFiles and IgnoredManagedFiles read git output line by line. With Git's default core.quotePath, a path containing any non-ASCII byte comes back quoted, e.g. "services/caf\303\251/.env", so IsManagedName sees the name .env" and drops the file.

With services/café/.env holding SECRET=hunter2:

  • envapor verify prints "No managed .env files found." and exits 0. The same repo with services/cafe/.env fails verify with "plaintext secrets found".
  • With the filter not running, the pre-commit guard lets SECRET=hunter3 be committed in plaintext. With cafe it refuses.

After the change both paths behave like cafe: verify fails and the guard blocks the commit.

The fix adds a small runPaths helper that runs the listing with -z and splits on NUL, the same way check-attr is already called, and uses it for all four listings.

Test: TestPathListingsKeepNonASCIIPaths in internal/gitutil/git_test.go. It sets core.quotePath=true so a global Git setting can't hide the problem, and checks both ManagedFiles and StagedFiles. It fails on main and passes with the fix. go test ./..., go vet and gofmt are clean.

StagedFiles, TrackedFiles, ManagedFiles and IgnoredManagedFiles read
git output line by line. With core.quotePath (Git's default) any path
containing a non-ASCII byte comes back quoted, e.g.
"services/caf\303\251/.env", so IsManagedName saw the name `.env"` and
dropped the file. verify reported "No managed .env files found" and the
pre-commit guard let a plaintext .env in such a folder be committed.

Use -z and split on NUL, as check-attr already does.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant