fix(forgejo): never print a generated user password in apply output #511

Sammanfogat
supernaut sammanfogade 3 incheckningar från fix/509-no-password-output in i main 2026-10-01 19:50:30 +00:00
Ägare

What

  • ansible/roles/forgejo/tasks/create-user.yml: the create task is no_log: true unconditionally. The debug task that echoed the generated password is deleted. The password is generated and discarded. OIDC is the login path and service accounts use PATs.
  • scripts/check-no-password-output.py, run in CI next to the other check-*.py steps: fails if a task registering _fj_user_create lacks no_log: true, or if a debug, copy or template task references it beyond .rc or .stderr.

changed_when, failed_when and until still read the registered output, so idempotence is unchanged. A failed create now shows censored output.

Verification

  • ansible-lint: 0 failures.
  • Guard against the pre-fix file: exit 1 with both messages. Against this branch: exit 0.
  • No apply needed until the next user is created. The next apply's --check should show no change for existing users.

Not done

Whether Kanidm-backed accounts need a local password that works over Basic auth at all. Worth its own issue.

Closes #509

## What - `ansible/roles/forgejo/tasks/create-user.yml`: the create task is `no_log: true` unconditionally. The debug task that echoed the generated password is deleted. The password is generated and discarded. OIDC is the login path and service accounts use PATs. - `scripts/check-no-password-output.py`, run in CI next to the other `check-*.py` steps: fails if a task registering `_fj_user_create` lacks `no_log: true`, or if a debug, copy or template task references it beyond `.rc` or `.stderr`. `changed_when`, `failed_when` and `until` still read the registered output, so idempotence is unchanged. A failed create now shows censored output. ## Verification - `ansible-lint`: 0 failures. - Guard against the pre-fix file: exit 1 with both messages. Against this branch: exit 0. - No apply needed until the next user is created. The next apply's `--check` should show no change for existing users. ## Not done Whether Kanidm-backed accounts need a local password that works over Basic auth at all. Worth its own issue. Closes #509
supernaut lade till 3 incheckningar 2026-10-01 19:11:30 +00:00
Mark the create-user task no_log unconditionally and drop the debug task that echoed the generated password. Basic auth stays on for git and the API, so the password is a live credential.

Closes #509
Fail the lint job if a task registering _fj_user_create lacks no_log or if any task prints it. Also reflow a header comment line.

Refs #509
style(ci): drop an f-string prefix with no placeholders
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m1s
86a5410db4
Refs #509
supernaut sammanfogade incheckning ab23eeea2d till main 2026-10-01 19:50:30 +00:00
supernaut tog bort grenen fix/509-no-password-output 2026-10-01 19:50:30 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!511
Ingen beskrivning angiven.