fix(security): reject invalid optional bundle values

This commit is contained in:
2026-07-12 11:53:15 +02:00
parent 449a333365
commit f67d2c97d8
3 changed files with 13 additions and 5 deletions
+1 -1
View File
@@ -85,7 +85,7 @@ read_bundle_secret() {
END { if (!found) exit 5 }
' "$bundle_path") || {
echo "$bundle_key is unavailable in secret bundle" >&2
return 2
return 3
}
if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then
echo "$bundle_key must contain no whitespace" >&2