Say on stderr which settings came from a .env file - #588
Merged
Merged
Conversation
A .env file in the working directory can pick the server and turn off certificate validation for analyze and query-store. The CLI applied those settings without a word. Now it prints one line on stderr that names the file and the settings it supplied, never their values. A setting that a command-line option overrode is not listed. PasswordResolver asks for the .env password only when neither --password-stdin nor --password gave one, so the list is exact. Its doc comment and --password warning no longer mention a PLANVIEW_PASSWORD environment variable, which the CLI never read. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G625JBNh45iTR1hpT4CxNR
…characters Review round 1 on #588: - A PLANVIEW_ value with a control character now stops the command with an error that names the key and the file, never the value. The CLI prints the server and database later, and an escape sequence there could erase the notice. The file path and keys in the notice and the error show control characters as '?'. - Both commands merge the file through one EnvFile.Fill method. With no server, analyze runs offline and takes nothing from the file. The file's password is used only with a login, so the notice lists only settings that had an effect. - PasswordResolver.TryResolve takes an optional writer for its messages, so the tests no longer swap Console.Error. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G625JBNh45iTR1hpT4CxNR
|
Reviewed. This is a clean, well-scoped fix for a real issue (a repo-supplied A few things I checked closely and found correct:
No correctness, security, or convention issues found. Not applicable here: no T-SQL, no |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
The CLI reads a
.envfile from the working directory foranalyzeandquery-store. That file can pick the server and turn off certificate validation. The CLI applied those settings without a word. So if a cloned repo held a.envfile,planview analyzeconnected to the server that the file named, and nothing told the user.Now the CLI prints one line on stderr when the
.envfile supplies a setting. The line names the file and the settings, and it never shows their values:The line lists only the settings that had an effect:
analyzereads the plan file offline and takes nothing from the file.PLANVIEW_PASSWORDis used only with a login. Without a login, the command uses the credential store or Windows authentication, as before.If a
PLANVIEW_value holds a control character, the command stops. The error names the setting and the file, but not the value. The CLI prints the server and database names later. An escape sequence in them moves the cursor and erases text, such as the new line.No real setting needs a control character, but tab is allowed. The file path in the line and in the error shows any control character as
?.The automatic load does not change, so existing
.envfiles keep working. Apart from the new line and the control-character check, the commands behave as before.How it works:
ConnectionHelper.LoadEnvFilenow returns anEnvFileobject. Both commands call one method,EnvFile.Fill. It fills only the settings that the command line left out, and it records each key that it supplied.EnvFile.PasswordForgives the file's password only when there is a server and a login.PasswordResolver.TryResolvetakes the.envpassword as a function. It calls the function only when neither--password-stdinnor--passwordgave a password, so the list is exact. It also takes an optional writer for its messages, so the tests do not replaceConsole.Error.--passwordwarning said "PLANVIEW_PASSWORD env var". The CLI never read a process environment variable, only the.envfile. The text now says "PLANVIEW_PASSWORD in a .env file"..envfiles describes the new line, when the file's settings apply, and the control-character check.Which component(s) does this affect?
How was this tested?
EnvFileTests, 20 cases:--passwordstill writes its warning.PLANVIEW_TRUST_CERT=falsechanges nothing and is not listed. A folder with no.envfile supplies nothing.PLANVIEW_are not checked. A control character in the path shows as?.planview.exeran against SQL Server 2025 from folders with a.envfile:analyzewith every setting from the file listed all five keys, and the capture succeeded.analyzewith--serverand--trust-certlisted only the database, login and password.query-storelisted the login, trust-cert and password, and it analyzed a plan from Query Store.analyzewith exit code 1. Stderr held no escape character.analyzeof a.sqlplanfile, with no server in the.envfile, printed no line.Checklist
--no-incremental)dotnet test)🤖 Generated with Claude Code
https://claude.ai/code/session_01G625JBNh45iTR1hpT4CxNR