Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Postgres credentials can only be supplied in argv, and are echoed unredacted

Aperta
#106 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
55/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
csharp, postgresql

Direzione di ricerca

Start at the DataProviderMigrate migrate command and trace --output handling and every place the connection string is displayed. Review the accepted libpq, Npgsql key=value, and SQLAlchemy URL forms, then define environment-variable precedence and ensure credentials are redacted in startup, progress, and error output. Done means Postgres can run without a secret in argv and no supported output leaks the password.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

DataProviderMigrate migrate can only be given a Postgres connection string as
a command-line argument:

--output, -o   Path to output database file (SQLite) or connection string (Postgres)

For Postgres that string normally contains a password. Passing a credential in
argv has three consequences that no amount of care at the call site can avoid:

  1. It is in the process table. Any local process can read the full
    connection string for as long as the migration runs.
  2. It reaches shell history and command logs. Any tooling that records the
    invocation records the password with it.
  3. It can be echoed back. When the tool prints the invocation it is
    printing the credential.

The usual guidance for CLIs that take secrets is to accept them from the
environment or a file, and to redact them anywhere the command is displayed.

Request

  1. Accept the connection string from an environment variable — for example
    DATAPROVIDER_CONNECTION_STRING, with --output kept for SQLite paths and
    for non-secret cases. Precedence and naming are yours to pick; the point is
    that a caller should be able to run a Postgres migration with no credential
    in argv at all.
  2. Redact credentials wherever the tool echoes the connection string —
    startup banners, progress output, and error messages alike. Printing the
    host and database is useful; printing the password never is. Masking the
    password portion of a libpq URL, an Npgsql key=value string and a
    SQLAlchemy URL would cover the formats the tool already accepts.

Why it matters to us

We drive DataProviderMigrate against a managed Postgres from a make migrate
target, and our own standards forbid a DSN reaching a log. Today we cannot hold
that line, because the only supported input is argv. We would rather not work
around it locally — a wrapper that hides the argument from one code path still
leaves it in the process table.

Happy to send a PR if you would like the env-var form added; say which variable
name and precedence you would prefer.

Lingua principale
C#
Stelle
67
Fork
4
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Nimblesite/DataProvider

Tutte le issue di Nimblesite/DataProvider

Issue simili

Altre issue su C#

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.