Repository navigation
Keep credentials out of malformed connection-string errors - #24
Merged
Merged
Conversation
Validate keyword names before emitting syntax diagnostics and handle URI syntax/decoding separately from known-option validation. Raise the replacement after leaving catch so the original input-bearing exception cannot remain in the displayed chain. Cover public parsing, connection and pool entry points. AI disclosure: This work was prepared with assistance from OpenAI Codex.
Member
Author
|
Merged normally as The one expected coverage upload was explicitly accepted for this repository and merge SHA. The public report is complete with one session and 89.29% coverage. The merged tree matches the tested head; issue #22 closed at merge. AI disclosure: This work was prepared with assistance from OpenAI Codex. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Malformed connection strings can expose a password in the exception message. A typo URI scheme is treated as a keyword token, and URI parsing or percent-decoding can include credential fragments in its errors. For example,
postgresql://u:s3cr%zzt@h/dbcurrently reports the raw user info.Validate keyword names before emitting syntax errors and omit unrecognized raw names. Parse/decode URI components separately from existing connection-option validation, then throw a credential-safe
ArgumentErrorafter leaving the catch. This also removes the original input-bearing exception from Julia's displayed cause chain. Known-option errors retain their parameter names, and accepted inputs and ignored-option defaults retain their values.Validation:
All 16 exact-head checks pass, including the complete 14-job CI run, real PostgreSQL 14/15/16/17/18 integration, SCRAM/MD5 authentication, minimum/current/prerelease Julia, all three operating systems, and strict docs. The one expected upload is accepted at the correct repository/head SHA; its public report is complete at 89.29%.
After normal merge as
b53a1e5f67bbd6d55aecf765e8e2c58ca5d6dfbd, all 14 jobs in the exact-main run also pass. Its one expected coverage upload is accepted for the correct repository and merge SHA, with a complete one-session report at 89.29%. The merged source tree is identical to the tested head. Issue #22 closed at merge.Fixes #22.
Co-authored by Codex
AI disclosure: This work was prepared with assistance from OpenAI Codex.