Skip to content

fix: treat blank environment-variable secrets as unset - #13198

Draft
yongpange wants to merge 1 commit into
deepset-ai:mainfrom
yongpange:fix/blank-env-secret-reopen
Draft

yongpange wants to merge 1 commit into
deepset-ai:mainfrom
yongpange:fix/blank-env-secret-reopen

Conversation

@yongpange

Copy link
Copy Markdown

Related Issues

Proposed Changes:

Secret.from_env_var used os.getenv and stopped at the first variable that was present, including "" and whitespace. A blank HF_TOKEN therefore blocked fallback to HF_API_TOKEN, and strict=True returned "" instead of raising.

The resolver now treats empty or whitespace-only values as unset, matching the usual "set means has a real value" contract for auth env vars.

How did you test it?

  • Added test_env_var_secret_treats_blank_values_as_unset
  • Reproduced on current main with a blank first candidate and a real fallback; after the fix the fallback is used and a strict blank-only secret raises ValueError

Notes for the reviewer

Same contract as #12723, rebased onto current main (the old branch was ~255 commits behind). I will sign the CLA immediately if the check is still pending.

Checklist

  • I have read the contributors guidelines and the code of conduct.
  • I have updated the related issue with new insights and changes.
  • I have added unit tests and updated the docstrings.
  • I've used one of the conventional commit types for my PR title: fix:, feat:, build:, chore:, ci:, docs:, style:, refactor:, perf:, test: and added ! in case the PR includes breaking changes.
  • I have documented my code.
  • I have added a release note file, following the contributors guidelines.
  • I have run pre-commit hooks and fixed any issue.

An empty or whitespace-only candidate was previously treated as configured and blocked fallback to later variables.
@yongpange
yongpange requested a review from a team as a code owner October 9, 2026 16:20
@yongpange
yongpange requested review from sjrl and removed request for a team October 9, 2026 16:20
@vercel

vercel Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@yongpange is attempting to deploy a commit to the deepset Team on Vercel.

A member of the Team first needs to authorize it.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@HaystackBot

Copy link
Copy Markdown
Contributor

Hi @yongpange, thanks a lot for your contribution! 🙏

We noticed that the Contributor License Agreement (CLA) check (license/cla) hasn't passed yet, so we've temporarily moved this PR to draft and paused the review assignment.

To get your PR reviewed, please sign the CLA via the link in the license/cla check below (or in the CLA bot comment). As soon as the check turns green, this PR will automatically be marked ready for review again and a reviewer will be re-assigned.

@HaystackBot
HaystackBot removed the request for review from sjrl October 9, 2026 17:27
@HaystackBot HaystackBot added the cla-pending PR is in draft until the contributor signs the CLA label Oct 9, 2026
@HaystackBot
HaystackBot marked this pull request as draft October 9, 2026 17:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-pending PR is in draft until the contributor signs the CLA topic:tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants