Diff
1diff --git a/plugins/dotenv/README.md b/plugins/dotenv/README.md
2index f6612473123b9715b017f3feae7672173ed7df52..ab9d329f6f8dc11ac0bd0ebf8d6d1c7602625a1f 100644
3--- a/plugins/dotenv/README.md
4+++ b/plugins/dotenv/README.md
5@@ -53,24 +53,30 @@ Set `ZSH_DOTENV_PROMPT=false` in your zshrc file if you don't want the confirmat
6 You can also choose the `Always` option when prompted to always allow sourcing the .env file
7 in that directory. See the next section for more details.
8
9-### ZSH_DOTENV_ALLOWED_LIST
10+### ZSH_DOTENV_ALLOWED_LIST, ZSH_DOTENV_DISALLOWED_LIST
11
12 The default behavior of the plugin is to always ask whether to source a dotenv file. There's
13-a **Y**es, **N**o, and **A**lways option. If you choose Always, the directory of the .env file
14-will be added to an allowed list. If a directory is found in this list, the plugin won't ask
15-for confirmation and will instead source the .env file directly.
16+a **Y**es, **N**o, **A**lways and N**e**ver option. If you choose Always, the directory of the .env file
17+will be added to an allowed list; if you choose Never, it will be added to a disallowed list.
18+If a directory is found in either of those lists, the plugin won't ask for confirmation and will
19+instead either source the .env file or proceed without action respectively.
20
21-This allowed list is saved by default in `$ZSH_CACHE_DIR/dotenv-allowed.list`. If you want
22-to change that location, change the `$ZSH_DOTENV_ALLOWED_LIST` variable, like so:
23+The allowed and disallowed lists are saved by default in `$ZSH_CACHE_DIR/dotenv-allowed.list` and
24+`$ZSH_CACHE_DIR/dotenv-disallowed.list` respectively. If you want to change that location,
25+change the `$ZSH_DOTENV_ALLOWED_LIST` and `$ZSH_DOTENV_DISALLOWED_LIST` variables, like so:
26
27 ```zsh
28 # in ~/.zshrc, before Oh My Zsh is sourced:
29 ZSH_DOTENV_ALLOWED_LIST=/path/to/dotenv/allowed/list
30+ZSH_DOTENV_DISALLOWED_LIST=/path/to/dotenv/disallowed/list
31 ```
32
33-This file is just a list of directories allowed, separated by a newline character. If you want
34-to disallow a directory, just edit this file and remove the line for the directory you want to
35-disallow.
36+The file is just a list of directories, separated by a newline character. If you want
37+to change your decision, just edit the file and remove the line for the directory you want to
38+change.
39+
40+NOTE: if a directory is found in both the allowed and disallowed lists, the disallowed list
41+takes preference, _i.e._ the .env file will never be sourced.
42
43 ## Version Control
44
45diff --git a/plugins/dotenv/dotenv.plugin.zsh b/plugins/dotenv/dotenv.plugin.zsh
46index ac3210d7fdd7454ceb5a9bab365362a1393834c6..24f285df555de97a46abce8906a985d83718e36d 100644
47--- a/plugins/dotenv/dotenv.plugin.zsh
48+++ b/plugins/dotenv/dotenv.plugin.zsh
49@@ -5,6 +5,7 @@
50
51 # Path to the file containing allowed paths
52 : ${ZSH_DOTENV_ALLOWED_LIST:="${ZSH_CACHE_DIR:-$ZSH/cache}/dotenv-allowed.list"}
53+: ${ZSH_DOTENV_DISALLOWED_LIST:="${ZSH_CACHE_DIR:-$ZSH/cache}/dotenv-disallowed.list"}
54
55
56 ## Functions
57@@ -14,19 +15,26 @@ source_env() {
58 if [[ "$ZSH_DOTENV_PROMPT" != false ]]; then
59 local confirmation dirpath="${PWD:A}"
60
61- # make sure there is an allowed file
62+ # make sure there is an (dis-)allowed file
63 touch "$ZSH_DOTENV_ALLOWED_LIST"
64+ touch "$ZSH_DOTENV_DISALLOWED_LIST"
65+
66+ # early return if disallowed
67+ if grep -q "$dirpath" "$ZSH_DOTENV_DISALLOWED_LIST" &>/dev/null; then
68+ return;
69+ fi
70
71 # check if current directory's .env file is allowed or ask for confirmation
72 if ! grep -q "$dirpath" "$ZSH_DOTENV_ALLOWED_LIST" &>/dev/null; then
73 # print same-line prompt and output newline character if necessary
74- echo -n "dotenv: found '$ZSH_DOTENV_FILE' file. Source it? ([Y]es/[n]o/[a]lways) "
75+ echo -n "dotenv: found '$ZSH_DOTENV_FILE' file. Source it? ([Y]es/[n]o/[a]lways/n[e]ver) "
76 read -k 1 confirmation; [[ "$confirmation" != $'\n' ]] && echo
77
78 # check input
79 case "$confirmation" in
80 [nN]) return ;;
81 [aA]) echo "$dirpath" >> "$ZSH_DOTENV_ALLOWED_LIST" ;;
82+ [eE]) echo "$dirpath" >> "$ZSH_DOTENV_DISALLOWED_LIST"; return ;;
83 *) ;; # interpret anything else as a yes
84 esac
85 fi