dvGeneratePublicEnvLibrary function

DVPublicEnvLibrary dvGeneratePublicEnvLibrary(
  1. Map<String, String> environment
)

The public part of environment, as a Dart library.

Only PUBLIC_-prefixed names are emitted, and that filter is the whole of structural guarantee one: everything else stays in the environment of the process that runs the code, whether or not any analysis runs.

Values are stored XOR-scrambled. That is not secrecy and the generated file says so -- the key is written beside the data -- it only keeps a configuration string from turning up in a plain scan over the built bundle.

Output is deterministic: the same environment gives byte-identical source, in sorted order, however the incoming map was built. The key used to come from DateTime.now(), so every regeneration rewrote the file with different numbers for identical input, and a generated file that churns on its own teaches people to ignore its diffs.

Implementation

DVPublicEnvLibrary dvGeneratePublicEnvLibrary(Map<String, String> environment) {
  final List<String> skipped = <String>[];
  final Map<String, String> emitted = <String, String>{};

  final List<String> names = environment.keys.toList()..sort();
  for (final String name in names) {
    if (!name.startsWith('PUBLIC_')) continue;
    // The names come out of a .env file, which the build reads without any
    // review. A name carrying a quote would close the string it is
    // interpolated into and turn the rest of the line into code in a
    // generated library; a name with a dash would simply not compile.
    if (!_isPublicIdentifier(name)) {
      skipped.add(name);
      continue;
    }
    emitted[name] = environment[name]!;
  }

  final StringBuffer out = StringBuffer()
    ..writeln('// GENERATED CODE - DO NOT MODIFY BY HAND')
    ..writeln('// ignore_for_file: non_constant_identifier_names, '
        'unused_element')
    ..writeln('library dartvel_client_env;')
    ..writeln('')
    ..writeln('/// Environment variables the application ships to the client.')
    ..writeln('///')
    ..writeln('/// Only PUBLIC_-prefixed variables are here. Everything else '
        'stays in the')
    ..writeln('/// environment of the process that runs the backend, because '
        'a value')
    ..writeln('/// compiled into this file reaches every visitor.')
    ..writeln('class Env {')
    ..writeln('  /// Unpacks a value from the scrambled code units below.')
    ..writeln('  ///')
    ..writeln('  /// Not a cipher: the key sits in this file beside the data, '
        'and these')
    ..writeln('  /// are values chosen to be public anyway. It keeps them out '
        'of a plain')
    ..writeln('  /// scan over the built bundle, and buys nothing else. Do '
        'not put a')
    ..writeln('  /// real secret behind the PUBLIC_ prefix on the strength of '
        'it.')
    ..writeln('  static String _d(List<int> c, int k) =>')
    ..writeln('      String.fromCharCodes(c.map((x) => x ^ k));');

  for (final MapEntry<String, String> entry in emitted.entries) {
    out
      ..writeln('')
      ..writeln('  /// Value of the ${entry.key} environment variable.')
      ..writeln('  static String get ${entry.key} => '
          '${_scramble(entry.value)};');
  }

  out
    ..writeln('}')
    ..writeln('')
    ..writeln('/// Every public environment variable, by name.')
    ..writeln('final Map<String, String> dvPublicEnv = <String, String>{');
  for (final String name in emitted.keys) {
    out.writeln("  '$name': Env.$name,");
  }
  out
    ..writeln('};')
    ..writeln('')
    ..writeln('/// Public environment variable lookup.')
    ..writeln('class DartvelEnv {')
    ..writeln('  /// Map of all public environment variables.')
    ..writeln('  static final Map<String, String> public = dvPublicEnv;')
    ..writeln('')
    ..writeln('  /// Gets a public environment variable by name.')
    ..writeln('  static String? get(String key) => dvPublicEnv[key];')
    ..writeln('}');

  return DVPublicEnvLibrary(source: out.toString(), skipped: skipped);
}