Skip to content

Fix/installer trim whitespace db inputs - #404

Merged
navneetkumar-pim-webkul merged 3 commits into
unopim:masterfrom
dripar-webkul:fix/installer-trim-whitespace-db-inputs
May 26, 2026
Merged

navneetkumar-pim-webkul merged 3 commits into
unopim:masterfrom
dripar-webkul:fix/installer-trim-whitespace-db-inputs

Conversation

@dripar-webkul

Copy link
Copy Markdown
Collaborator

Summary

  • php artisan unopim:install accepted whitespace in DB inputs and wrote DB_HOST="127.0.0.1 " to .env, causing getaddrinfo for "127.0.0.1" failed during migrations.
  • Only DB_PREFIX had transform: trim(...); every other text input passed the raw value straight through to envUpdate(), which quote-wraps anything containing whitespace.
  • Fix trims and validates DB_HOST, DB_PORT, DB_DATABASE, DB_USERNAME at the prompt level and again after the prompt array is built (defense-in-depth, mirrors the existing DB_PREFIX pattern). Same trim treatment extended to APP_NAME, APP_URL, every Elasticsearch text input, and the admin name/email inputs. Passwords intentionally left untrimmed.
  • Added validators that reject internal whitespace on host/database/username and non-numeric ports so the installer fails fast with a clear message instead of silently writing a broken .env.

Test plan

  • vendor/bin/pest packages/Webkul/Installer/tests/Feature/DatabaseInputTrimTest.php — 5 new tests, all passing (DB_HOST trailing whitespace, DB_HOST internal whitespace rejection, DB_PORT/DB_DATABASE/DB_USERNAME trim)
  • vendor/bin/pest --testsuite="Installer Feature Test" — 32 passed (134 assertions), no regressions in existing DatabasePrefixTrimTest, CommandTest, InstallerControllerTest, etc.
  • Manual repro: entering 127.0.0.1␠␠␠ at the host prompt now lands as DB_HOST=127.0.0.1 (unquoted) in .env; entering 127.0.0 .1 is rejected with "The database host cannot contain whitespace."

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the unopim:install interactive installer by trimming whitespace from user-entered .env values (especially DB settings) and adding prompt-level validation to prevent writing unusable connection details that can break migrations.

Changes:

  • Add trim transforms + whitespace/port validation for database prompts (host/port/name/username) and apply post-prompt trimming as an extra safeguard.
  • Extend trimming to other installer prompts (APP_* fields, Elasticsearch text inputs, admin name/email) while leaving passwords untrimmed.
  • Add new Pest feature tests covering trimming behavior for DB inputs and host whitespace rejection.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
packages/Webkul/Installer/src/Console/Commands/Installer.php Adds trimming and validation to installer prompt inputs (DB/app/Elasticsearch/admin) before writing to .env.
packages/Webkul/Installer/tests/Feature/DatabaseInputTrimTest.php Adds feature tests to verify DB prompt trimming and whitespace rejection behavior.
Comments suppressed due to low confidence (2)

packages/Webkul/Installer/src/Console/Commands/Installer.php:352

  • The empty-credentials guard uses negation on string values (e.g. ! $databaseDetails['DB_PASSWORD']), which treats the string '0' as falsey in PHP. That means a valid value like '0' for DB_DATABASE/DB_USERNAME/DB_PASSWORD would be incorrectly rejected. Prefer explicit empty-string checks (e.g. trim(...) === '') for these required inputs.
        if (
            ! $databaseDetails['DB_DATABASE']
            || ! $databaseDetails['DB_USERNAME']
            || ! $databaseDetails['DB_PASSWORD']
        ) {
            return $this->error('Please enter the database credentials.');
        }

packages/Webkul/Installer/src/Console/Commands/Installer.php:611

  • $input ?: $defaultValue treats the string '0' as empty/falsey and will unexpectedly replace it with the default. If you want to only fall back when the user truly provided an empty string, use a strict empty check ($input === '') or the null-coalescing pattern depending on what text() returns.
        $input = text(
            label: $question,
            default: $defaultValue,
            required: true,
            transform: trim(...),
        );

        $this->envUpdate($key, $input ?: $defaultValue);
    }

Comment thread packages/Webkul/Installer/tests/Feature/DatabaseInputTrimTest.php Outdated
@dripar-webkul
dripar-webkul changed the base branch from master to 2.1 May 25, 2026 12:39
@dripar-webkul
dripar-webkul changed the base branch from 2.1 to master May 25, 2026 13:53
@navneetkumar-pim-webkul
navneetkumar-pim-webkul merged commit 6ae4797 into unopim:master May 26, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants