fix: validate credential file keys against [A-Za-z0-9_]+

Keys with hyphens or other special characters would silently fail
substitution since _PLACEHOLDER_RE only matches word chars/digits/underscores.
Now mirrors the validation already applied to --credentials inline keys.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Joel Saß 2026-06-12 09:32:55 +02:00
parent 664d64a98c
commit 422d5a2403
Failed to extract signature

View file

@ -340,6 +340,12 @@ def _parse_credentials(
f"got {type(v).__name__} for key '{k}': '{credentials_file}'"
)
break # unreachable; satisfies type checker
if not re.fullmatch(r"[A-Za-z0-9_]+", k):
parser.error(
f"Invalid key '{k}' in '{credentials_file}': "
"keys must contain only letters, digits, and underscores."
)
break # unreachable
str_values[str(k)] = v
result.update(str_values)