diff --git a/src/connection_string.jl b/src/connection_string.jl index 47766e0..ddff7fb 100644 --- a/src/connection_string.jl +++ b/src/connection_string.jl @@ -157,7 +157,8 @@ function check_ignored_param(key::String, value::String) inert = get(SECURITY_SENSITIVE_IGNORED, key, nothing) inert === nothing && return value in inert && return - throw(ArgumentError("connection parameter \"$key=$value\" is not supported by Postgres.jl and cannot be safely ignored")) + # never echo the value: for sslpassword it is the client key passphrase + throw(ArgumentError("connection parameter \"$key\" is set to a value Postgres.jl does not support and cannot safely ignore")) end # An unrecognized key is almost always a typo, and silently dropping it is diff --git a/test/runtests.jl b/test/runtests.jl index e8d63f2..1ba3543 100644 --- a/test/runtests.jl +++ b/test/runtests.jl @@ -649,6 +649,18 @@ include("notification_deadlines.jl") @test !occursin("top-secret", plain_shown) @test occursin("password=***", shown) @test occursin("password=***", plain_shown) + # Nor may an error rejecting an option: sslpassword is a key passphrase. + for dsn in ("host=h sslpassword=top-secret", "postgresql://u@h/db?sslpassword=top-secret") + err = try + Postgres.parse_dsn(dsn) + nothing + catch e + e + end + @test err isa ArgumentError + @test occursin("sslpassword", err.msg) + @test !occursin("top-secret", sprint(showerror, err)) + end # Malformed keyword DSNs must never degrade to a usable partial # configuration. In particular, a discarded security option could