fix(config): treat empty KOSLI_* env vars as unset, not as set - #1089
Conversation
An environment variable set to the empty string reports as present via os.LookupEnv, and two hand-rolled reads took that as evidence the user had supplied a value. KOSLI_CONFIG_FILE="" replaced the default config path with "", so no config file was loaded at all and org, api-token and every other configured default vanished silently. KOSLI_API_TOKEN="" was read as "the token came from the environment, so it is plaintext", which skipped decryption of the config-file token. Anyone who stored their token with `kosli config --api-token` holds ciphertext, so the ciphertext was sent as the API token and authentication failed with nothing pointing at the skipped decryption step. Both now require a non-empty value, matching how viper already treats every other bound KOSLI_* variable. Making an empty variable an error is left to the wider AllowEmptyEnv work, so they all change together rather than two of them diverging again.
|
Claude finished @JonJagger's task in 1m 51s —— View job Code Review: treat empty
|
kosli-cli 2.36.6 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre># Bug fixes - Empty `--attachments` or `--template` elements (e.g. from unset shell variables) are now rejected with a clear error instead of being silently dropped. - An empty `KOSLI_CONFIG_FILE` environment variable no longer suppresses config file loading; it is treated as unset and falls back to the default. - An empty `KOSLI_API_TOKEN` environment variable no longer skips decryption of a config-file token. - A boolean flag given an empty value (e.g. `--compliant ""` or `--new-compliance-status ""`) is now rejected with a clear error naming the flag, preventing the opposite compliance verdict from being recorded silently. - Config file or environment values that cannot be applied to a flag now produce an error naming the flag and its source, instead of silently failing. ## What's Changed * fix(attest): always serialise commits in pull request attestations by @dangrondahl in kosli-dev/cli#1083 * fix(docs): correct invalid regex in snapshot ecs help examples by @dangrondahl in kosli-dev/cli#1080 * fix(config): treat empty KOSLI_* env vars as unset, not as set by @JonJagger in kosli-dev/cli#1089 * fix(config): report config values that cannot be applied to their flag by @JonJagger in kosli-dev/cli#1090 * fix(flags): reject an empty element in a multi-value flag by @JonJagger in kosli-dev/cli#1092 * fix(flags): reject an empty value written after a boolean flag by @JonJagger in kosli-dev/cli#1091 * chore(deps): bump the github-actions-dependencies group with 3 updates by @dependabot[bot] in kosli-dev/cli#1084 * chore(deps): bump the go-dependencies group with 9 updates by @dependabot[bot] in kosli-dev/cli#1085 * chore(deps): bump anthropics/claude-code-action from 1.0.189 to 1.0.191 in the github-actions-dependencies group by @dependabot[bot] in kosli-dev/cli#1094 * chore(deps): bump the go-dependencies group with 7 updates by @dependabot[bot] in kosli-dev/cli#1095 * chore(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 by @dependabot[bot] in kosli-dev/cli#1096 **Full Changelog**: https://github.com/kosli-dev/cli/compare/v2.36.5...v2.36.6</pre> <p>View the full release notes at <a href="https://github.com/kosli-dev/cli/releases/tag/v2.36.6">https://github.com/kosli-dev/cli/releases/tag/v2.36.6</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!16566
An environment variable set to the empty string reports as present via
os.LookupEnv, and two hand-rolled reads took that as evidence the user had
supplied a value.
KOSLI_CONFIG_FILE="" replaced the default config path with "", so no config
file was loaded at all and org, api-token and every other configured default
vanished silently.
KOSLI_API_TOKEN="" was read as "the token came from the environment, so it is
plaintext", which skipped decryption of the config-file token. Anyone who
stored their token with
kosli config --api-tokenholds ciphertext, so theciphertext was sent as the API token and authentication failed with nothing
pointing at the skipped decryption step.
Both now require a non-empty value, matching how viper already treats every
other bound KOSLI_* variable. Making an empty variable an error is left to the
wider AllowEmptyEnv work, so they all change together rather than two of them
diverging again.
Checklist
charts/k8s-reporter/) updated, if needed. Note: these changes live in a separate PR