Skip to content

fix: protect implicitly loaded config from output overwrite - #376

Merged
rowkav09 merged 1 commit into
mainfrom
fix/default-config-protection
Oct 5, 2026
Merged

rowkav09 merged 1 commit into
mainfrom
fix/default-config-protection

Conversation

@rowkav09

@rowkav09 rowkav09 commented Oct 5, 2026

Copy link
Copy Markdown
Member

Without --config, the CLI still loads ./spec2mcp.config.json when it exists, but the output safety check only covered a config path passed explicitly. So generate --out . could overwrite the user's project settings. I now keep the default config path when the file exists and use it in the output safety checks and the generate and watch paths, the same as an explicit config.

The new CLI test puts a config in the folder, runs generate with --out set to that folder, expects the "output directory contains config input" error, and checks the config is unchanged. It fails on main and passes with the change. Full suite passes, typecheck passes.

Closes #375.

I retain the default config path when the file exists and include it in
output safety checks, matching explicitly selected config files.

I added a fail-first CLI regression for output targeting the directory
containing the implicitly loaded project settings.
@rowkav09
rowkav09 merged commit ac6b5db into main Oct 5, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

generate can overwrite the spec2mcp.config.json it loaded by default

1 participant