forgejo: user creation prints a live generated password in the apply output #509
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#509
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Problem
ansible/roles/forgejo/tasks/create-user.ymlprints a newly generated Forgejo password in the playbook output ("Generated credentials … copy now, shown only once"). The file's own header says the account gets "a random local password nobody is given", because OIDC through Kanidm is the real login path.The printed password is a live credential. Web password sign-in is off (
ENABLE_INTERNAL_SIGNIN = false), but HTTP Basic authentication stays on for git and the API, and the account has no second factor. Anyone who reads the apply output, a saved log or a pasted transcript can authenticate as that user until the password changes.This happened on 2026-10-01: an apply created
test-passkey-check(declared in #484) and printed its password. The password was rotated by hand to an unprinted random value right after, and the old one now returns 401.Fix
forgejo_users(Kanidm-backed people), never print the generated password. Mark the create taskno_logunconditionally, and drop the debug task or restrict it to an explicit opt-in.Done when
An apply that creates a user prints no password. A check in CI or a lint guard fails if the debug task comes back.