Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion src/connection_string.jl
Original file line number Diff line number Diff line change
Expand Up @@ -157,7 +157,8 @@ function check_ignored_param(key::String, value::String)
inert = get(SECURITY_SENSITIVE_IGNORED, key, nothing)
inert === nothing && return
value in inert && return
throw(ArgumentError("connection parameter \"$key=$value\" is not supported by Postgres.jl and cannot be safely ignored"))
# never echo the value: for sslpassword it is the client key passphrase
throw(ArgumentError("connection parameter \"$key\" is set to a value Postgres.jl does not support and cannot safely ignore"))
end

# An unrecognized key is almost always a typo, and silently dropping it is
Expand Down
12 changes: 12 additions & 0 deletions test/runtests.jl
Original file line number Diff line number Diff line change
Expand Up @@ -649,6 +649,18 @@ include("notification_deadlines.jl")
@test !occursin("top-secret", plain_shown)
@test occursin("password=***", shown)
@test occursin("password=***", plain_shown)
# Nor may an error rejecting an option: sslpassword is a key passphrase.
for dsn in ("host=h sslpassword=top-secret", "postgresql://u@h/db?sslpassword=top-secret")
err = try
Postgres.parse_dsn(dsn)
nothing
catch e
e
end
@test err isa ArgumentError
@test occursin("sslpassword", err.msg)
@test !occursin("top-secret", sprint(showerror, err))
end

# Malformed keyword DSNs must never degrade to a usable partial
# configuration. In particular, a discarded security option could
Expand Down
Loading