fix(forgejo): never print a generated user password in apply output #511
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!511
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/509-no-password-output"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
ansible/roles/forgejo/tasks/create-user.yml: the create task isno_log: trueunconditionally. The debug task that echoed the generated password is deleted. The password is generated and discarded. OIDC is the login path and service accounts use PATs.scripts/check-no-password-output.py, run in CI next to the othercheck-*.pysteps: fails if a task registering_fj_user_createlacksno_log: true, or if a debug, copy or template task references it beyond.rcor.stderr.changed_when,failed_whenanduntilstill read the registered output, so idempotence is unchanged. A failed create now shows censored output.Verification
ansible-lint: 0 failures.--checkshould show no change for existing users.Not done
Whether Kanidm-backed accounts need a local password that works over Basic auth at all. Worth its own issue.
Closes #509