Relationships
#3101 Shell steps: a vault.get on a continuation line of a multi-line double-quoted string inside a here-doc is wrapped in quotes
Opened by stack72 · 10/6/2026· Shipped 10/6/2026
Problem
swamp-club#3089 (PR #2881) places each vault.get() reference by its own quote context. Inside an unquoted here-document body it reads only the quotes earlier on the same line. When the secret sits on a continuation line of a double-quoted string that spans lines, that line has no open quote, so the reference is wrapped in quotes.
Reproduction
Run string:
cat <<EOF
echo ~line1
${{ vault.get(v,k) }}~
EOF(with ~ standing for a double quote)
- Before #2881: the here-doc output is the string with the value inside the original quotes.
- After #2881: the reference becomes a quoted reference inside the user's open quote, so the generated text closes and reopens the string and the value sits unquoted in the script the here-doc produces (word-splitting and globbing move one level down).
Found by the CI adversarial review on PR #2881; reproduced against merge-base c4c1ed56.
Expected
Inside an unquoted here-doc body, a vault.get reference takes the form main gave it: quote characters counted from the start of the command, evaluated at each use. Double means a bare reference, anything else a quoted one.
Fix
In posixVaultQuote (src/domain/vaults/vault_secret_bag.ts), for heredoc and heredoc-literal contexts use getQuoteContext over the whole command at that position instead of the line prefix. Add the multi-line case to the unit tests and the main-vs-fix matrix.
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.