cloudflare / cloudflare/developer-platform

Workers silently accepts leading whitespace in secret variable names

Abierto
#71 3 comentarios 0 reacciones 1 asignado Reclamado por @dario-piotrowicz Ver en GitHub
Lenguaje dominante
Sin datos de lenguaje
Estrellas
1
Forks
0
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### What versions & operating system are you using?

Wrangler 4.118.0
Node.js 24.14.1
npm 11.11.0
Linux Docker container
Windows host with PowerShell 7.6.4

The affected secret was originally created through the "Workers & Pages" dashboard under "Settings" → "Variables and Secrets".

### Please provide a link to a minimal reproduction

N/A

### Describe the Bug

The Workers dashboard accepts secret variable names with accidental leading or trailing spaces.

For example, ` FIREBASE_SERVICE_ACCOUNT_JSON` is deployed as a different binding from `FIREBASE_SERVICE_ACCOUNT_JSON`, without any warning.

This is difficult to notice and causes the expected `env` binding to be `undefined`.

Please trim surrounding whitespace ` ` automatically, or reject the name with a clear validation message before deployment.

### Please provide any relevant error logs

```bash
$ npx wrangler secret list

[
{
"name": " FIREBASE_SERVICE_ACCOUNT_JSON",
"type": "secret_text"
},
{
"name": "OTHER_AUTH_SECRET_WITHOUT_WHITESPACE",
"type": "secret_text"
}
]
```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.