Skip to main content

is_pre_quoted_passthrough_enabled

Function is_pre_quoted_passthrough_enabled 

Source
pub fn is_pre_quoted_passthrough_enabled() -> bool
Expand description

Whether the legacy pre-quoted passthrough heuristic is active.

Older versions treated a value that happened to start and end with a quote character as “already quoted” and spliced it into the command as shell syntax, so the value '/My Documents/x' reached the command as /My Documents/x - the quotes vanished. sh does the opposite: "$var" always yields the value verbatim, quote characters included, which is also what Bun’s $, zx and execa do. Worse, the heuristic could hand the shell unbalanced quotes, and an injected command ran (issue #41).

The heuristic is therefore off by default; set COMMAND_STREAM_PREQUOTED_PASSTHROUGH=1 to restore it for code that relies on hand-quoted values. Even then only values that stay balanced are passed through, so the injection above can no longer happen.