Skip to content

fix(env): read empty .env values as unset instead of the next line - #236

Open
jamie-at-bunny wants to merge 11 commits into
mainfrom
claude/readenvvalue-newline-bug-0df7a3
Open

jamie-at-bunny wants to merge 11 commits into
mainfrom
claude/readenvvalue-newline-bug-0df7a3

Conversation

@jamie-at-bunny

Copy link
Copy Markdown
Member

Fixes readEnvValue so an empty line like BUNNY_DATABASE_URL= counts as unset instead of returning the next line.

Why

The old regex, ^KEY\s*=\s*["']?(.+?)["']?\s*$ with the m flag, let \s* match the newline. So on an empty value it read the following line (for example BUNNY_DATABASE_AUTH_TOKEN=) as the value. That is why database .env.example files have had to comment those lines out.

What changed

  • readEnvValue now uses parseEnvFile, the shared dotenv parser already imported in utils/env-file.ts, in place of the regex. It still walks up parent directories, and an empty value still counts as unset.
  • Added a regression test for the two-line database case.
  • Patch changeset for @bunny.net/cli.

Reviewer notes

The parser changes three other behaviours slightly:

  • Inline comments are stripped (KEY=val # dev reads as val).
  • export KEY=... lines are now found.
  • If a key appears twice, the last one wins, which matches what Bun loads at runtime. Before, the first one won.

🤖 Generated with Claude Code

@changeset-bot

changeset-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e480210

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
Name Type
@bunny.net/cli Patch
@bunny.net/cli-darwin-arm64 Patch
@bunny.net/cli-darwin-x64 Patch
@bunny.net/cli-linux-arm64 Patch
@bunny.net/cli-linux-x64 Patch
@bunny.net/cli-windows-x64 Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jamie-at-bunny
jamie-at-bunny marked this pull request as ready for review September 28, 2026 09:00
@bunnynet-devops

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T09:04:00.457988Z 4326660 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[High risk] Changes how environment variables are parsed from .env files.

The PR is not yet safe to merge because an existing unresolved token-replacement issue can reactivate an old credential.

Fix All in Claude CodeFindings

  1. P1 Old token becomes active again ▶

Summary

The PR reads .env values through the shared dotenv parser, adds database credential safeguards and regression coverage, and updates the patch changeset. Since the previous review, it narrows when removal strips a trailing carriage return.

Reviews (11) · Last reviewed commit: "fix(env): only strip the trailing CR whe..."

Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.test.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4326660f24

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts
Comment thread packages/cli/src/commands/db/credentials.ts
Comment on lines +98 to +100
} else if (unterminated[0]) {
lines.splice(unterminated[0].start, 0, line);
writeFileSync(target, lines.join("\n"), "utf-8");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Old token becomes active again If an unclosed quote hides an existing token line, this branch inserts the replacement above the quote but leaves the old line in place. If the user repairs the quote at its opening line, the old token becomes a later definition and wins, silently undoing the replacement.

Knowledge Base Used: CLI database commands

Fix in Claude Code

Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts Outdated
Comment thread packages/cli/src/utils/env-file.ts
Comment thread packages/cli/src/utils/env-file.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants