-
Notifications
You must be signed in to change notification settings - Fork 50
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add possibility to pass variables from command line. #57
Conversation
cli.js
Outdated
if(typeof argv.v === 'string') | ||
variables.push(validateCmdVariable(argv.v)) | ||
else | ||
variables.push(...argv.v.map(validateCmdVariable)) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
can you follow the code style and put braces around these?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I update PR to reflect code style in project.
cli.js
Outdated
else | ||
variables.push(...argv.v.map(validateCmdVariable)) | ||
} | ||
var parsed = dotenv.parse(Buffer.from(variables.join('\n'))) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
can you put this closer to line 78? and maybe name parsedVariables
or something? It feels a bit generic
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I renamed the variable, but I didn't want to move it down, as I believe debug option should print the variables. And it should be after line 73 to overwrite variables from env files.
@@ -3,1387 +3,1502 @@ | |||
|
|||
|
|||
"@babel/code-frame@^7.0.0": |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I guess it doesn't matter but why did this file change?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I honestly don't know. I guess YARN uses some new format. It add integrity checks there and wrap some keys into ".
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Give me minute I will try to turn it back.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, when I run yarn locally, it removes the integrity changes again so I think that's best.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are you using yarn1 or yarn2? Maybe that's the issue. I just pushed version where keys are not escaped using ", but the integrity check is still there. Do we want to have it there?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm using yarn1, but I'll just reset the file before merging. The security problem is something that needs fixing though.
There is a security problem with the current implementation:
|
I changed validation to use regex, so no special symbol is allowed. |
See |
Should solve issue #56
I hope everything checks out. I used
dotenv.parse
in case there is some additional logic and/or validation.It worked for me on Windows.