fix(09): WR-13 read admin passwords from a prompt or stdin and deprecate the --password flag
This commit is contained in:
@@ -22,7 +22,7 @@ func RuntimeCommands(app *backpack.App) []bonfire.Command {
|
||||
Description: "Create an activated backend administrator",
|
||||
Flags: []bonfire.Flag{
|
||||
{Name: "email", Description: "Admin email"},
|
||||
{Name: "password", Description: "Admin password"},
|
||||
{Name: "password", Description: "Admin password (deprecated: visible in the process list and shell history; omit it to be prompted, or pipe it on stdin)"},
|
||||
{Name: "login", Description: "Login; defaults to the lower-cased email"},
|
||||
{Name: "superuser", Description: "Grant superuser", Bare: true},
|
||||
{Name: "role", Description: "Role code"},
|
||||
@@ -41,7 +41,7 @@ func RuntimeCommands(app *backpack.App) []bonfire.Command {
|
||||
}},
|
||||
Flags: []bonfire.Flag{{
|
||||
Name: "password",
|
||||
Description: "New password",
|
||||
Description: "New password (deprecated: visible in the process list and shell history; omit it to be prompted, or pipe it on stdin)",
|
||||
}},
|
||||
Run: func(ctx context.Context, in bonfire.Input, out bonfire.Output) error {
|
||||
return adminResetPassword(ctx, app, in, out)
|
||||
@@ -52,9 +52,12 @@ func RuntimeCommands(app *backpack.App) []bonfire.Command {
|
||||
|
||||
func adminCreate(ctx context.Context, app *backpack.App, in bonfire.Input, out bonfire.Output) error {
|
||||
email := strings.ToLower(strings.TrimSpace(flagValue(in, "email")))
|
||||
password := flagValue(in, "password")
|
||||
if email == "" || !strings.Contains(email, "@") || strings.TrimSpace(password) == "" {
|
||||
return errors.New("cabana: email and password are required")
|
||||
if email == "" || !strings.Contains(email, "@") {
|
||||
return errors.New("cabana: a valid email is required")
|
||||
}
|
||||
password, err := resolvePassword(in, out)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
login := strings.TrimSpace(flagValue(in, "login"))
|
||||
if login == "" {
|
||||
@@ -109,9 +112,12 @@ func adminResetPassword(ctx context.Context, app *backpack.App, in bonfire.Input
|
||||
if identifier == "" && len(in.Args()) > 0 {
|
||||
identifier = strings.TrimSpace(in.Args()[0])
|
||||
}
|
||||
password := flagValue(in, "password")
|
||||
if identifier == "" || strings.TrimSpace(password) == "" {
|
||||
return errors.New("cabana: identifier and password are required")
|
||||
if identifier == "" {
|
||||
return errors.New("cabana: an identifier is required")
|
||||
}
|
||||
password, err := resolvePassword(in, out)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return withAdminDB(ctx, app, func(gdb *gorm.DB) error {
|
||||
return gdb.WithContext(ctx).Transaction(func(tx *gorm.DB) error {
|
||||
@@ -143,6 +149,28 @@ func adminResetPassword(ctx context.Context, app *backpack.App, in bonfire.Input
|
||||
})
|
||||
}
|
||||
|
||||
// resolvePassword returns the password for admin:create and
|
||||
// admin:reset-password without putting it on the command line. Without
|
||||
// --password it is read through out.Secret: hidden on a terminal, one line from
|
||||
// stdin otherwise, so scripts can pipe it. --password still works, because the
|
||||
// documented usage and existing scripts pass it, but it is deprecated: the value
|
||||
// is visible in the process list and the shell history.
|
||||
func resolvePassword(in bonfire.Input, out bonfire.Output) (string, error) {
|
||||
password := flagValue(in, "password")
|
||||
if password != "" {
|
||||
out.Warning("--password is deprecated: the value is visible in the process list and the shell history. Omit it to be prompted, or pipe the password on stdin.")
|
||||
} else {
|
||||
var err error
|
||||
if password, err = out.Secret("Password"); err != nil {
|
||||
return "", err
|
||||
}
|
||||
}
|
||||
if strings.TrimSpace(password) == "" {
|
||||
return "", errors.New("cabana: a password is required (enter it at the prompt or pipe it on stdin)")
|
||||
}
|
||||
return password, nil
|
||||
}
|
||||
|
||||
func roleIDByCode(tx *gorm.DB, code string) (*uint, error) {
|
||||
if code == "" {
|
||||
return nil, nil
|
||||
|
||||
Reference in New Issue
Block a user