Skip to content

Use protected password input for seed workflows #534

Description

@coderabbitai

Summary

The seed workflows pass PASS on Make command lines and Python process arguments. This can expose passwords in command output and process inspection. Shell expansion can also alter a password before the seed script receives it.

Required changes

  • Update server/scripts/seed-users.py and server/scripts/seed-kus.py to read passwords through protected input instead of command-line password arguments.
  • Update Docker seed targets and local-development seed targets in Makefile.
  • Suppress recipe echoing for every target that handles password input, including aggregate targets such as seed-all and dev-seed-all.
  • Preserve the existing username, database, API URL, and Docker/local workflow behaviour.
  • Update DEVELOPMENT.md and the quickstart documentation for the revised seed interface.

Rationale

This work changes both the Docker and local-development seed interfaces. It requires a deliberate, documented interface decision outside PR #526.

Affected areas

  • Makefile
  • server/scripts/seed-users.py
  • server/scripts/seed-kus.py
  • DEVELOPMENT.md
  • Quickstart documentation

Acceptance criteria

  • No seed target passes a password as a command-line argument.
  • Seed recipes that handle password input do not echo secret-bearing commands.
  • Both Docker and local seed workflows work with the protected-input interface.
  • Documentation describes the new invocation method.

Backlinks

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions