Repository navigation
fix(storage): secrets can be removed on edit, SSH secrets go with the tunnel, a failed save restores them all (#1311) - #1330
Merged
Conversation
… tunnel, a failed save restores them all (#1311) - An edit form has Remove the saved password; a blank field still keeps it. Test Connection honours it. - Saving a connection without a tunnel removes its SSH password, key and passphrase from the keyring instead of leaving them there. - A failed secret write restores the SSH secrets too (they are written key by key), not only the password and connection string.
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1311
Problem
writeForConnectionwrote SSH secrets only when one was non-null: turning the tunnel off left its password, private key and passphrase in the keyring until the connection was deleted.updateConnectionrestored the row and the password / connection string but not the SSH secrets, which are written key by key and may be half replaced.Fix
ConnectionRow.removeSavedPassword(never stored). PostgreSQL, MySQL, MongoDB and Redis edit forms get a Remove the saved password checkbox (edit mode only; it disables the field).mergeSecretsForConnectionUpdatedrops the saved password for it (a password typed with the request still replaces); Test Connection then tests without the saved one.updateConnectionclears the four SSH secrets when the saved row has no enabled tunnel and brings none.updateConnectionsnapshots the SSH secrets with the other ones and restores all of them when a write fails.Tests (
local_db_secrets_test.dart): a blank field keeps, the request removes (and the store really loses it), a typed password with the request replaces; a connection saved without a tunnel has no SSH secret left; a write failing on the fourth key restores the previous SSH password and key (with a backend that fails on the Nth write).