Skip to content

Keep credentials out of malformed connection-string errors - #24

Merged
quinnj merged 1 commit into
mainfrom
maintenance/dsn-safe-errors
Oct 4, 2026
Merged

quinnj merged 1 commit into
mainfrom
maintenance/dsn-safe-errors

Conversation

@quinnj

@quinnj quinnj commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Malformed connection strings can expose a password in the exception message. A typo URI scheme is treated as a keyword token, and URI parsing or percent-decoding can include credential fragments in its errors. For example, postgresql://u:s3cr%zzt@h/db currently reports the raw user info.

Validate keyword names before emitting syntax errors and omit unrecognized raw names. Parse/decode URI components separately from existing connection-option validation, then throw a credential-safe ArgumentError after leaving the catch. This also removes the original input-bearing exception from Julia's displayed cause chain. Known-option errors retain their parameter names, and accepted inputs and ignored-option defaults retain their values.

Validation:

  • On actual Julia 1.10.12 and 1.13.1, 112 public parser/connection/pool checks change from 40 passes and 72 failures on the current main to all passes on this head. They cover the reported inputs, typo URIs with queries, malformed password fragments, percent decoding, and full exception-chain output.
  • An independent comparison with current main passes 118 accepted complete-field checks and 48 unchanged known-option diagnostics on both runtimes.
  • Full Linux suites pass 5,433 checks on Julia 1.10.12 and 5,459 on Julia 1.13.0, with bounds checks and two threads. These local test containers skip Docker integration; the hosted PostgreSQL version/authentication runs subsequently passed.
  • The strict Documenter build passes. A private review of the complete frozen source/test change found no blocker; this does not provide GitHub approval.

All 16 exact-head checks pass, including the complete 14-job CI run, real PostgreSQL 14/15/16/17/18 integration, SCRAM/MD5 authentication, minimum/current/prerelease Julia, all three operating systems, and strict docs. The one expected upload is accepted at the correct repository/head SHA; its public report is complete at 89.29%.

After normal merge as b53a1e5f67bbd6d55aecf765e8e2c58ca5d6dfbd, all 14 jobs in the exact-main run also pass. Its one expected coverage upload is accepted for the correct repository and merge SHA, with a complete one-session report at 89.29%. The merged source tree is identical to the tested head. Issue #22 closed at merge.

Fixes #22.

Co-authored by Codex

AI disclosure: This work was prepared with assistance from OpenAI Codex.

Validate keyword names before emitting syntax diagnostics and handle URI syntax/decoding separately from known-option validation. Raise the replacement after leaving catch so the original input-bearing exception cannot remain in the displayed chain. Cover public parsing, connection and pool entry points.

AI disclosure: This work was prepared with assistance from OpenAI Codex.
@quinnj
quinnj merged commit b53a1e5 into main Oct 4, 2026
16 checks passed
@quinnj

quinnj commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Merged normally as b53a1e5f67bbd6d55aecf765e8e2c58ca5d6dfbd. All 14 jobs in the exact-main CI run pass, including the real PostgreSQL version and authentication tests, all three operating systems, minimum/current/prerelease Julia, and strict documentation.

The one expected coverage upload was explicitly accepted for this repository and merge SHA. The public report is complete with one session and 89.29% coverage. The merged tree matches the tested head; issue #22 closed at merge.

AI disclosure: This work was prepared with assistance from OpenAI Codex.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Connection string parse errors can include the password

1 participant