From 422d5a240309c57a5411d427767e5d4f6ee93840 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Joel=20Sa=C3=9F?= Date: Fri, 12 Jun 2026 09:32:55 +0200 Subject: [PATCH] fix: validate credential file keys against [A-Za-z0-9_]+ Keys with hyphens or other special characters would silently fail substitution since _PLACEHOLDER_RE only matches word chars/digits/underscores. Now mirrors the validation already applied to --credentials inline keys. Co-Authored-By: Claude Sonnet 4.6 --- strix/interface/main.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/strix/interface/main.py b/strix/interface/main.py index 2c0649c5..1334a453 100644 --- a/strix/interface/main.py +++ b/strix/interface/main.py @@ -340,6 +340,12 @@ def _parse_credentials( f"got {type(v).__name__} for key '{k}': '{credentials_file}'" ) break # unreachable; satisfies type checker + if not re.fullmatch(r"[A-Za-z0-9_]+", k): + parser.error( + f"Invalid key '{k}' in '{credentials_file}': " + "keys must contain only letters, digits, and underscores." + ) + break # unreachable str_values[str(k)] = v result.update(str_values)