Summary
The seed workflows pass PASS on Make command lines and Python process arguments. This can expose passwords in command output and process inspection. Shell expansion can also alter a password before the seed script receives it.
Required changes
- Update
server/scripts/seed-users.py and server/scripts/seed-kus.py to read passwords through protected input instead of command-line password arguments.
- Update Docker seed targets and local-development seed targets in
Makefile.
- Suppress recipe echoing for every target that handles password input, including aggregate targets such as
seed-all and dev-seed-all.
- Preserve the existing username, database, API URL, and Docker/local workflow behaviour.
- Update
DEVELOPMENT.md and the quickstart documentation for the revised seed interface.
Rationale
This work changes both the Docker and local-development seed interfaces. It requires a deliberate, documented interface decision outside PR #526.
Affected areas
Makefile
server/scripts/seed-users.py
server/scripts/seed-kus.py
DEVELOPMENT.md
- Quickstart documentation
Acceptance criteria
- No seed target passes a password as a command-line argument.
- Seed recipes that handle password input do not echo secret-bearing commands.
- Both Docker and local seed workflows work with the protected-input interface.
- Documentation describes the new invocation method.
Backlinks
Summary
The seed workflows pass
PASSon Make command lines and Python process arguments. This can expose passwords in command output and process inspection. Shell expansion can also alter a password before the seed script receives it.Required changes
server/scripts/seed-users.pyandserver/scripts/seed-kus.pyto read passwords through protected input instead of command-line password arguments.Makefile.seed-allanddev-seed-all.DEVELOPMENT.mdand the quickstart documentation for the revised seed interface.Rationale
This work changes both the Docker and local-development seed interfaces. It requires a deliberate, documented interface decision outside PR #526.
Affected areas
Makefileserver/scripts/seed-users.pyserver/scripts/seed-kus.pyDEVELOPMENT.mdAcceptance criteria
Backlinks