What
render_default_toml() (src/pythonnative/project/config.py:589) interpolates the
project name into the generated file with an f-string:
name = "{name}"
display_name = "{display}"
Nothing escapes it, so a name containing a double quote produces a config that
can't be parsed:
$ pn init 'bad"name'
$ head -6 bad"name/pythonnative.toml
name = "bad"name"
display_name at :608 and the commented url_schemes example at :614 derive from
the same string, so they're affected too. Control characters have the same effect —
a newline in the name splits the value across lines.
Notes
This predates #21: the name has always flowed straight into the config, and it was
reachable before that change too. _app_id_from_name() strips everything outside
[a-z0-9_] for the app id, so the id, the directory name, and the name field can
end up representing three different things.
Possible directions
Either escape string values when rendering, or define and validate a supported
project-name character set in pn init before anything is written. The second is
probably the better fix but it's a product decision about what names are legal,
which is why I didn't take it on in #27.
Raised in #27; opening here at @owenthcarey's suggestion.
What
render_default_toml() (src/pythonnative/project/config.py:589) interpolates the
project name into the generated file with an f-string:
name = "{name}" display_name = "{display}"Nothing escapes it, so a name containing a double quote produces a config that
can't be parsed:
display_name at :608 and the commented url_schemes example at :614 derive from
the same string, so they're affected too. Control characters have the same effect —
a newline in the name splits the value across lines.
Notes
This predates #21: the name has always flowed straight into the config, and it was
reachable before that change too. _app_id_from_name() strips everything outside
[a-z0-9_] for the app id, so the id, the directory name, and the name field can
end up representing three different things.
Possible directions
Either escape string values when rendering, or define and validate a supported
project-name character set in pn init before anything is written. The second is
probably the better fix but it's a product decision about what names are legal,
which is why I didn't take it on in #27.
Raised in #27; opening here at @owenthcarey's suggestion.