From fd1531c4610ea7c99bd5c5fc626654d4b5244575 Mon Sep 17 00:00:00 2001 From: Raphael Abayomi Date: Fri, 28 Aug 2026 16:16:52 +0100 Subject: [PATCH] fix: reject a whitespace-only value in isBoolean() filter_var() with FILTER_VALIDATE_BOOLEAN trims its input before matching, so a value that is only spaces or tabs has nothing left to match and is treated as the valid boolean false - it is not a 'failure' that FILTER_NULL_ON_FAILURE would catch. isBoolean() only guarded against the exact empty string ('' === $value), so a value that is empty only after trimming slipped past that guard and was then accepted as false by filter_var(). A genuinely empty value already failed correctly, since '' === '' is true. Trim before the empty check, mirroring the guard notEmpty() already uses, so a whitespace-only value is rejected the same way an empty one is. --- src/Validator.php | 5 ++++- tests/Dotenv/ValidatorTest.php | 1 + tests/fixtures/env/booleans.env | 1 + 3 files changed, 6 insertions(+), 1 deletion(-) diff --git a/src/Validator.php b/src/Validator.php index efea1220..ebfb4f36 100644 --- a/src/Validator.php +++ b/src/Validator.php @@ -101,7 +101,10 @@ public function isBoolean() { return $this->assertNullable( static function (string $value) { - if ($value === '') { + // filter_var() trims its input before matching, so a value that + // is empty only after trimming (eg. whitespace-only) would + // otherwise be treated as the valid boolean false. + if (\trim($value, " \n\r\t\0\x0B") === '') { return false; } diff --git a/tests/Dotenv/ValidatorTest.php b/tests/Dotenv/ValidatorTest.php index 7d4ed3b5..c9654678 100644 --- a/tests/Dotenv/ValidatorTest.php +++ b/tests/Dotenv/ValidatorTest.php @@ -269,6 +269,7 @@ public static function invalidBooleanValuesDataProvider() ['INVALID_SOMETHING'], ['INVALID_EMPTY'], ['INVALID_EMPTY_STRING'], + ['INVALID_WHITESPACE'], ['INVALID_NULL'], ['INVALID_NUMBER_POSITIVE'], ['INVALID_NUMBER_NEGATIVE'], diff --git a/tests/fixtures/env/booleans.env b/tests/fixtures/env/booleans.env index 522ac456..9fbf00c7 100644 --- a/tests/fixtures/env/booleans.env +++ b/tests/fixtures/env/booleans.env @@ -25,6 +25,7 @@ VALID_YESNO_MIXEDCASE_FALSE=No INVALID_SOMETHING=something INVALID_EMPTY= INVALID_EMPTY_STRING="" +INVALID_WHITESPACE=" " INVALID_NULL=null INVALID_NUMBER_POSITIVE=2 INVALID_NUMBER_NEGATIVE=-2