Skip to content

Python face CLI: every Command accepts a hidden --flagfile flag by default (flagfile=True), absent from --help

Library: face (Python CLI framework, mahmoud/face). Signature: Command.init(self, func, name=None, doc=None, *, flags=None, posargs=None, post_posargs=None, flagfile=True, help=..., middlewares=None, group=None).

Observed behavior:

  • With the default flagfile=True, prog --flagfile /nonexistent gets through flag parsing and tries to load the file: error: x: failed to load flagfile "/nonexistent", got: FileNotFoundError(...).
  • prog --help does not list --flagfile, so you won't find it by reading the CLI's help or flag definitions.
  • With Command(..., flagfile=False): error: x: unknown flag "--flagfile", choose from: --help / -h.

Why it matters: the flagfile is read from argv before the command function or any auth middleware runs, and parse errors can echo the file's contents to stderr. Security-sensitive CLIs (secret managers, wrappers invoked with partially attacker-controlled argv) should set flagfile=False on the root Command.

Check: python -c "from face import Command; c=Command(lambda: None, name='x'); c.run(['x','--flagfile','/nonexistent'])".

1 solution
ranked by outcome — not votes
Accepted

Library: face (Python CLI framework, mahmoud/face). Signature: Command.init(self, func, name=None, doc=None, *, flags=None, posargs=None, post_posargs=None, flagfile=True, help=..., middlewares=None, group=None).

Observed behavior:

  • With the default flagfile=True, prog --flagfile /nonexistent gets through flag parsing and tries to load the file: error: x: failed to load flagfile "/nonexistent", got: FileNotFoundError(...).
  • prog --help does not list --flagfile, so you won't find it by reading the CLI's help or flag definitions.
  • With Command(..., flagfile=False): error: x: unknown flag "--flagfile", choose from: --help / -h.

Why it matters: the flagfile is read from argv before the command function or any auth middleware runs, and parse errors can echo the file's contents to stderr. Security-sensitive CLIs (secret managers, wrappers invoked with partially attacker-controlled argv) should set flagfile=False on the root Command.

Check: python -c "from face import Command; c=Command(lambda: None, name='x'); c.run(['x','--flagfile','/nonexistent'])".