Skip to content

Do not echo rejected connection parameter values - #21

Merged
quinnj merged 1 commit into
JuliaDatabases:mainfrom
PingoLee:redact-rejected-connection-parameter-values
Oct 3, 2026
Merged

quinnj merged 1 commit into
JuliaDatabases:mainfrom
PingoLee:redact-rejected-connection-parameter-values

Conversation

@PingoLee

Copy link
Copy Markdown
Contributor

A security-sensitive libpq keyword set to a value Postgres.jl cannot honor is rejected with an ArgumentError that printed key=value. For sslpassword that value is the client key passphrase, so it ended up in error messages, logs and stack traces:

Postgres.parse_dsn("host=h sslpassword=hunter2")
# ArgumentError: connection parameter "sslpassword=hunter2" is not supported by Postgres.jl and cannot be safely ignored

The URI form (?sslpassword=...) goes through the same check.

The error now names only the parameter, as the unrecognized-parameter error already does. This follows the rule from #5 that displaying connection options must never reveal a secret (ConnectionParams shows password=***). The value is dropped for every key rather than only sslpassword, so no list of secret keys has to be kept in sync. Which values are accepted or rejected is unchanged. No public API or runtime dependency changes; only the error text differs.

Malformed URIs can still echo credentials through URIs.jl's ParseError, and a mistyped scheme can reach the keyword parser's "missing '='" error. Both have a different cause and are left for a separate issue.

Validation:

  • New checks in "Connection String Parsing" cover the keyword and URI forms. With the src change reverted, the two "passphrase not in message" checks fail.
  • Pkg.test(): 5347 checks pass on Julia 1.12.7 and 5321 on Julia 1.10.12 (Linux x64).
  • Fork CI on d34c93a: tests pass on Linux, Windows and macOS (Julia min, 1 and pre), with Docker integration against PostgreSQL 14, 15, 17 and 18 and SCRAM and MD5 auth. Only the Codecov upload failed, because the fork has no token.

🤖 Generated with Claude Code

A security-sensitive libpq keyword set to a value this driver cannot honor
is rejected with an ArgumentError that printed "key=value". For sslpassword
that value is the client key passphrase, so it ended up in logs and stack
traces.

The error now names only the parameter, as the unrecognized-parameter error
already does. Which values are rejected is unchanged.

Co-Authored-By: Claude Opus 5.5 <[email protected]>

@quinnj quinnj left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full diff at d34c93a and traced both keyword and URI options through the shared rejection check. This fixes the passphrase leak at its source while keeping unsupported options rejected.

Local validation on Julia 1.12.6: 5,347 package checks passed (Docker integration skipped locally), plus 225 comparisons with the base parser across every security-sensitive ignored option and its accepted defaults. The old parser exposes the test value; this head removes it. All 16 current PR checks are successful, including PostgreSQL version/auth integration lanes.

AI disclosure: This work was prepared with assistance from OpenAI Codex.

@quinnj
quinnj merged commit df11aeb into JuliaDatabases:main Oct 3, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants