Skip to content

fix(nodeenv): read quoted config values and mirror credentials - #426

Merged
ekalinin merged 1 commit into
masterfrom
fix/mirror-quotes-credentials
Oct 3, 2026
Merged

ekalinin merged 1 commit into
masterfrom
fix/mirror-quotes-credentials

Conversation

@ekalinin

Copy link
Copy Markdown
Owner

Fixes #321

What happens

  • ConfigParser keeps quotes as part of the value. The README shows the config values quoted (node = 'latest', jobs = '2'), so mirror = 'https://...' became the URL 'https://...' and failed with unknown url type: 'https. node = 'latest' broke the same way.
  • urllib takes user:password@ in a URL for a part of the host. --mirror=https://user:pass@host/... ended in an uncaught http.client.InvalidURL: nonnumeric port traceback, or in a DNS error when the URL had a port. The request never reached the mirror, and the error message printed the password.

What changes

  • Config._load strips one matching pair of quotes from string values.
  • main() cuts user:password@ off src_base_url with the new split_url_auth(), percent-decodes it and keeps it as a Basic Authorization header in src_auth, the way certifi_context is built once. urlopen() adds the header only to URLs under the mirror, so the npm registry does not get it, and as an unredirected header, so a redirect (for example to a presigned storage URL) does not carry it either. Since src_base_url holds no password any more, the error messages do not show it.

This differs from #322 in two points: install_opener there is bypassed when _urlopen passes context= (--ignore-ssl-certs, --with-certifi), and the quotes were stripped for mirror only.

Tests

All six new tests fail on master and pass with the fix:

  • quoted values in the config file are read without the quotes;
  • main() against a local HTTP server that asks for Basic auth, with a plain and a percent-encoded user:password@;
  • a redirect from the mirror does not carry the password;
  • the password stays out of the error message when the mirror is unreachable;
  • a request to another host does not get the header.

ConfigParser keeps quotes, so the values quoted as in the README
(`mirror = 'https://...'`) broke with "unknown url type: 'https".
Config._load() now strips one matching pair of quotes.

urllib takes user:password@ in a URL for a part of the host, so a
mirror behind a login could not be used. main() now cuts it off
src_base_url and urlopen() sends it as a Basic Authorization header,
only to URLs under the mirror and not along redirects. The password
no longer shows up in error messages either.

Fixes #321
@ekalinin
ekalinin merged commit 9678813 into master Oct 3, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Mirror with configuration files does not support quoting, or credentials

1 participant