Skip to content

Do not echo rejected connection parameter values - #21

Open
PingoLee wants to merge 1 commit into
JuliaDatabases:mainfrom
PingoLee:redact-rejected-connection-parameter-values
Open

PingoLee wants to merge 1 commit into
JuliaDatabases:mainfrom
PingoLee:redact-rejected-connection-parameter-values

Conversation

@PingoLee

Copy link
Copy Markdown
Contributor

A security-sensitive libpq keyword set to a value Postgres.jl cannot honor is rejected with an ArgumentError that printed key=value. For sslpassword that value is the client key passphrase, so it ended up in error messages, logs and stack traces:

Postgres.parse_dsn("host=h sslpassword=hunter2")
# ArgumentError: connection parameter "sslpassword=hunter2" is not supported by Postgres.jl and cannot be safely ignored

The URI form (?sslpassword=...) goes through the same check.

The error now names only the parameter, as the unrecognized-parameter error already does. This follows the rule from #5 that displaying connection options must never reveal a secret (ConnectionParams shows password=***). The value is dropped for every key rather than only sslpassword, so no list of secret keys has to be kept in sync. Which values are accepted or rejected is unchanged. No public API or runtime dependency changes; only the error text differs.

Malformed URIs can still echo credentials through URIs.jl's ParseError, and a mistyped scheme can reach the keyword parser's "missing '='" error. Both have a different cause and are left for a separate issue.

Validation:

  • New checks in "Connection String Parsing" cover the keyword and URI forms. With the src change reverted, the two "passphrase not in message" checks fail.
  • Pkg.test(): 5347 checks pass on Julia 1.12.7 and 5321 on Julia 1.10.12 (Linux x64).
  • Fork CI on d34c93a: tests pass on Linux, Windows and macOS (Julia min, 1 and pre), with Docker integration against PostgreSQL 14, 15, 17 and 18 and SCRAM and MD5 auth. Only the Codecov upload failed, because the fork has no token.

🤖 Generated with Claude Code

A security-sensitive libpq keyword set to a value this driver cannot honor
is rejected with an ArgumentError that printed "key=value". For sslpassword
that value is the client key passphrase, so it ended up in logs and stack
traces.

The error now names only the parameter, as the unrecognized-parameter error
already does. Which values are rejected is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant