Repository navigation
Conversation
A key defined twice (within one file, or redefined by a later cascade file) is almost always an editing mistake, and the merge is dict-based: the later value silently wins. Nothing crashed, nothing warned, and the failure mode is a silently flipped default discovered in production. The merge semantics are unchanged (last-wins, python-dotenv's own dict behavior); each duplicate now logs a WARNING naming the file, the key, and both values at load time. Within-file detection tokenizes with python-dotenv's own parse_stream (quote- and multiline-aware; a KEY= line inside a quoted multi-line value cannot false-positive), imported lazily inside the detector under a guarded import: dotenv.parser is not public API, so a future python-dotenv may break it - the worst case is that the warning degrades to silence, never an import-time break (the hermetic-loading pin documents the sanctioned exception). Fixes #80
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #80.
What
A key defined more than once in the .env cascade now logs a WARNING at load time, naming the file, the key, and both values:
Duplicate key 'A' in /path/.env: the later value wins. Remove the stale occurrence.Key 'SHARED' redefined in /path/.env.dev: 'base' (earlier file) is overridden by 'dev-specific' (this file).The merge semantics are unchanged (last-wins, python-dotenv's own dict behavior) — this only makes the flip visible instead of silent.
How
Within-file detection tokenizes with python-dotenv's own
parse_stream(one binding per occurrence, quote- and multiline-aware — aKEY=line inside a quoted multi-line value cannot false-positive), imported lazily inside the detector under a guarded import:dotenv.parseris not public API, so a future python-dotenv may break it — the worst case is that the warning degrades to silence, never an import-time break.TestNoDotenvInternalsdocuments the sanctioned exception and still fails on any module-leveldotenv.*import.Tests
tests/test_duplicate_keys.py(5): within-file warn + last-wins unchanged; clean files never warn; quoted multi-line values do not false-positive (and the real duplicate is the only one named); cross-cascade redefinition names both values; three occurrences warn once per key.Full suite: 1,433 passed; ruff clean.