scanKeys static method
The .env keys source reads by literal name, whether it also reads
keys it computes at runtime (then no complete allow-list can be
proven), and every KEY_LIKE string literal in it, which is how computed
keys are usually spelled (e.g. a switch returning 'CONNECTION_STRING_PROD').
Implementation
static ({Set<String> keys, bool dynamic, Set<String> literals}) scanKeys(
String source) {
final literals = RegExp(r'''(['"])([A-Z][A-Z0-9_]*)\1''')
.allMatches(source)
.map((m) => m.group(2)!)
.toSet();
final keys =
_literalRead.allMatches(source).map((m) => m.group(2)!).toSet();
final dynamic = _dynamicRead.hasMatch(source) ||
_everyDefined.hasMatch(source) ||
_wholeEnv.hasMatch(source);
return (keys: keys, dynamic: dynamic, literals: literals);
}