Stop printing the database password
The report opened with the connection string it was about to work on, taken straight from AIDND_DATABASE_URL. On the hosted deploy that string carries the Neon password, so the first line of every run put a live credential into the console — and from there into scrollback, a screenshot, or a pasted bug report. Nothing in the output said it was there to notice. It now prints scheme, user, host and database name. The query string goes whole: sslmode is the only part worth reading, and some drivers accept a password there as well. 631 green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tqgupw5CZGjSZrUTNUd4fW
This commit is contained in:
@@ -243,6 +243,23 @@ def test_the_rewrite_prompt_is_the_one_the_app_sends(db):
|
||||
|
||||
# --------------------------------------------------------------------- the tool
|
||||
|
||||
def test_the_database_line_carries_no_password():
|
||||
"""The report names the database it is about to rewrite. That line ends up
|
||||
in a console, a screenshot or a pasted bug report."""
|
||||
shown = rewrite_memories.safe_dsn(
|
||||
"postgresql://parth:hunter2@ep-cool-frost.us-east-1.aws.neon.tech/aidnd"
|
||||
"?sslmode=require")
|
||||
assert "hunter2" not in shown
|
||||
assert "sslmode" not in shown # a password can be passed there too
|
||||
assert shown == ("postgresql://parth@ep-cool-frost.us-east-1.aws.neon.tech"
|
||||
"/aidnd")
|
||||
|
||||
|
||||
def test_an_unparseable_database_url_shows_nothing_at_all():
|
||||
assert rewrite_memories.safe_dsn("not-a-url") == "(configured)"
|
||||
|
||||
|
||||
|
||||
def test_without_write_nothing_changes(db, monkeypatch):
|
||||
adventure = make_adventure(db)
|
||||
first, _ = fill_bank(db, adventure)
|
||||
|
||||
Reference in New Issue
Block a user