Postgres credentials can only be supplied in argv, and are echoed unredacted
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
Direzione di ricerca
Start at the DataProviderMigrate migrate command and trace --output handling and every place the connection string is displayed. Review the accepted libpq, Npgsql key=value, and SQLAlchemy URL forms, then define environment-variable precedence and ensure credentials are redacted in startup, progress, and error output. Done means Postgres can run without a secret in argv and no supported output leaks the password.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
DataProviderMigrate migrate can only be given a Postgres connection string as
a command-line argument:
--output, -o Path to output database file (SQLite) or connection string (Postgres)
For Postgres that string normally contains a password. Passing a credential in
argv has three consequences that no amount of care at the call site can avoid:
- It is in the process table. Any local process can read the full
connection string for as long as the migration runs. - It reaches shell history and command logs. Any tooling that records the
invocation records the password with it. - It can be echoed back. When the tool prints the invocation it is
printing the credential.
The usual guidance for CLIs that take secrets is to accept them from the
environment or a file, and to redact them anywhere the command is displayed.
Request
- Accept the connection string from an environment variable — for example
DATAPROVIDER_CONNECTION_STRING, with--outputkept for SQLite paths and
for non-secret cases. Precedence and naming are yours to pick; the point is
that a caller should be able to run a Postgres migration with no credential
in argv at all. - Redact credentials wherever the tool echoes the connection string —
startup banners, progress output, and error messages alike. Printing the
host and database is useful; printing the password never is. Masking the
password portion of a libpq URL, an Npgsql key=value string and a
SQLAlchemy URL would cover the formats the tool already accepts.
Why it matters to us
We drive DataProviderMigrate against a managed Postgres from a make migrate
target, and our own standards forbid a DSN reaching a log. Today we cannot hold
that line, because the only supported input is argv. We would rather not work
around it locally — a wrapper that hides the argument from one code path still
leaves it in the process table.
Happy to send a PR if you would like the env-var form added; say which variable
name and precedence you would prefer.
- Lingua principale
- C#
- Stelle
- 67
- Fork
- 4
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Nimblesite/DataProvider
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
Nimblesite/DataProvider#72 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
Nimblesite/DataProvider#109 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 55/100
Nimblesite/DataProvider#108 ·
-
A check constraint the schema cannot name can never be retired, and keeps enforcing the old ruleAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
Nimblesite/DataProvider#107 ·
-
migrate --allow-destructive drops EVERY foreign key when the database already matches the schemaAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
Nimblesite/DataProvider#105 · 5 commenti ·
Tutte le issue di Nimblesite/DataProvider
Issue simili
-
:watch: Not Triaged dotnet-target-version
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
copilot documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 2 giorni
-
untriaged
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
dotnet/dotnet-api-docs#13124 ·
I maintainer di solito rispondono entro 1 giorno
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
I maintainer di solito rispondono entro 1 giorno
-
type:bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
BHoM/MidasCivil_Toolkit#441 ·