Skip to content

fix(tabs): mask passwords in the script Users & Roles opens in the query editor - #3212

Open
datlechin wants to merge 3 commits into
mainfrom
fix/principal-editor-leaks-passwords
Open

datlechin wants to merge 3 commits into
mainfrom
fix/principal-editor-leaks-passwords

Conversation

@datlechin

@datlechin datlechin commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Users & Roles Open in Query Editor wrote the plaintext password of a staged create or password change into a query tab that tab persistence saves to disk, and into query history once the script ran. Root cause: the button flattened the review statements to strings, which dropped the carriesCredentials flag the Apply path reads to keep those statements out of history, so nothing kept the password out of the editor.

Tests

  • PrincipalOpenInEditorTests (new): a staged create for alice with s3cret and a staged password change for bob give editor scripts with <password> in place of the password; Apply still carries the real password and the carriesCredentials flag; a create without a password is unchanged; statements keep their execution order. Four view-model cases stage changes through UsersRolesViewModel on an injected MySQL principal driver and check the script Review hands Open in Query Editor, the review sheet's notice that the script holds <password>, no notice without a password, and that Discard clears both. The password and view-model cases fail without the fix: built from the unmasked statements, the scripts contain s3cret and n3w-s3cret and no notice appears.
  • PrincipalStatementGeneratorTests: a driver that never writes the password (as Typesense does) reports nothing hidden, so the sheet does not announce a placeholder that is not in the script.
  • PrincipalChangeManagerTests covers the staged-create fold, which now shares the password-replacing initializer.

No UI test: the review sheet needs a live MySQL or PostgreSQL server with Users & Roles, which the UI test runner does not have. The editor text and the notice are decided in the view model, which the unit tests cover.

Docs

The docs rewrite branch covers the user-facing text for Users & Roles.

CI fixes

The failed Package Tests job was SyncRecordMapperTests.unknownWireValueFailsClosed. Its duplicate decoder treated an unknown Safe Mode value as Off. Sync decoding now uses SafeModeLevel(wireValue:isReadOnly:), requiring confirmation and preserving legacy read-only restrictions. Added regressions for unknown read-only values and renames that preserve an unknown wire value.

Integrated main at 3cf419ce1, keeping both Security changelog entries. Also corrected the confirmed SurrealDB compile defect from main: its callers still passed text length after the JSON helper became a property. The helper once again accepts text length, keeping valid display truncation and full export text.

Validation for these fixes:

  • Full TableProCore package tests: passed, including 1,239 Swift Testing tests plus XCTest.
  • Isolated SwiftPM build of all SurrealDB driver sources and the actual driver test file: 50 tests in 8 suites passed.
  • The identical corrected helper passed an AllPlugins Xcode build on feat(plugins): remember row import column mappings per table and add Match by Name and Match by Position #3183.
  • Project regeneration: passed.
  • SwiftLint on the changed Swift files: zero violations. The helper still reports four existing stale documentation paths (TableProApp/rust-dameng, Contents/MacOS, Contents/Helpers, /Applications/Xcode-beta.app).

Pushing this commit triggers fresh GitHub Actions runs.

Unit-test compile correction

The unit-test build exposed three fixtures still calling the old one-argument cell API: two in Typesense and one in Elasticsearch. They now explicitly pass length: .display, retaining their expected display truncation and write-refusal behavior.

Both fixture files are identical on all four updated branches. The complete test target built on #3183, with all 87 selected storage and write-refusal tests passing. Separately, an isolated SwiftPM build of all Elasticsearch and Typesense driver sources and the actual driver test files passed 175 tests in 14 suites on this branch. SwiftLint found no violations in the two fixture files.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant