forgejo: user creation prints a live generated password in the apply output #509

Stängd
öppnade 2026-10-01 12:04:46 +00:00 av supernaut · 0 kommentarer
Ägare

Problem

ansible/roles/forgejo/tasks/create-user.yml prints a newly generated Forgejo password in the playbook output ("Generated credentials … copy now, shown only once"). The file's own header says the account gets "a random local password nobody is given", because OIDC through Kanidm is the real login path.

The printed password is a live credential. Web password sign-in is off (ENABLE_INTERNAL_SIGNIN = false), but HTTP Basic authentication stays on for git and the API, and the account has no second factor. Anyone who reads the apply output, a saved log or a pasted transcript can authenticate as that user until the password changes.

This happened on 2026-10-01: an apply created test-passkey-check (declared in #484) and printed its password. The password was rotated by hand to an unprinted random value right after, and the old one now returns 401.

Fix

  • For forgejo_users (Kanidm-backed people), never print the generated password. Mark the create task no_log unconditionally, and drop the debug task or restrict it to an explicit opt-in.
  • Service accounts authenticate with PATs only, so they do not need the password either.
  • Consider whether Kanidm-backed accounts need a local password that works over Basic auth at all.

Done when

An apply that creates a user prints no password. A check in CI or a lint guard fails if the debug task comes back.

## Problem `ansible/roles/forgejo/tasks/create-user.yml` prints a newly generated Forgejo password in the playbook output ("Generated credentials … copy now, shown only once"). The file's own header says the account gets "a random local password nobody is given", because OIDC through Kanidm is the real login path. The printed password is a live credential. Web password sign-in is off (`ENABLE_INTERNAL_SIGNIN = false`), but HTTP Basic authentication stays on for git and the API, and the account has no second factor. Anyone who reads the apply output, a saved log or a pasted transcript can authenticate as that user until the password changes. This happened on 2026-10-01: an apply created `test-passkey-check` (declared in #484) and printed its password. The password was rotated by hand to an unprinted random value right after, and the old one now returns 401. ## Fix - For `forgejo_users` (Kanidm-backed people), never print the generated password. Mark the create task `no_log` unconditionally, and drop the debug task or restrict it to an explicit opt-in. - Service accounts authenticate with PATs only, so they do not need the password either. - Consider whether Kanidm-backed accounts need a local password that works over Basic auth at all. ## Done when An apply that creates a user prints no password. A check in CI or a lint guard fails if the debug task comes back.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#509
Ingen beskrivning angiven.