Skip to content

Don't reveal credentials in log and error output - #232

Merged
jgebal merged 1 commit into
developfrom
feature/prevent_logging_credentials
Sep 27, 2026
Merged

jgebal merged 1 commit into
developfrom
feature/prevent_logging_credentials

Conversation

@jgebal

@jgebal jgebal commented Sep 27, 2026

Copy link
Copy Markdown
Member

Closes #172

Summary

The password of the connect string could end up on screen in two ways:

  1. Args debug line. At startup the CLI logs its command line arguments at debug level, connect string included:

    DEBUG org.utplsql.cli.Cli -- Args: run, app/Sup3rSecretPw@//localhost:1521/FREEPDB1
    
  2. Passwords containing @. The connect-string parser ended an unquoted password at the first @. For app/p@ss@host, the password was taken as p and the connect string as ss@host. The connection failed, and part of the password appeared in the connection lines and in the driver's error message, printed on every run:

    jdbc:oracle:thin:****/****@ss@//localhost:1521/FREEPDB1: ORA-12261: ... connection string ss@//localhost:1521/FREEPDB1
    

Behaviour change

Passwords containing @ no longer have to be quoted, thought it's a good ide to keep it that way. Connect strings can not contain @ because everything up to the last @ is taken as the password.
This is fine as connect strings (EZConnect, TNS aliases, descriptors) don't normally contain @.

Added tests to confirm the solution.
Changed how credentials are parsed to avoid leaking passwords on unquoted passwords with multiple @ signs.
Cleanup, unification and refactoring of credentials masking.

Update of readme to include information about new behavior.
@sonarqubecloud

Copy link
Copy Markdown

@jgebal jgebal mentioned this pull request Sep 27, 2026
@jgebal
jgebal merged commit 63f91e1 into develop Sep 27, 2026
8 checks passed
@jgebal
jgebal deleted the feature/prevent_logging_credentials branch September 27, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hide password

1 participant