Re: [pgadmin-hackers] Re: BUG #10250: pgAdmin III 1.16.1 stores unescaped plaintext password

From: Akshay Joshi <akshay(dot)joshi(at)enterprisedb(dot)com>
To: Dave Page <dpage(at)pgadmin(dot)org>
Cc: Stephen Frost <sfrost(at)snowman(dot)net>, Heikki Linnakangas <hlinnakangas(at)vmware(dot)com>, dlo(at)isam(dot)kiwi, Pg Bugs <pgsql-bugs(at)postgresql(dot)org>, pgadmin-hackers <pgadmin-hackers(at)postgresql(dot)org>
Subject: Re: [pgadmin-hackers] Re: BUG #10250: pgAdmin III 1.16.1 stores unescaped plaintext password
Date: 2014-05-08 09:04:04
Message-ID: CANxoLDfP-hBK=mE5yZuw9ixgqG9WkPOLtvoGGC+MVT+WQNqArw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgadmin-hackers pgsql-bugs

Sure.

On Thu, May 8, 2014 at 1:37 PM, Dave Page <dpage(at)pgadmin(dot)org> wrote:

> Akshay, can you look into the quoting problem please.
>
> On Thu, May 8, 2014 at 1:07 AM, Stephen Frost <sfrost(at)snowman(dot)net> wrote:
> > * Heikki Linnakangas (hlinnakangas(at)vmware(dot)com) wrote:
> >> (forwarding to pgadmin-hackers)
> >
> > Ah.
> >
> >> On 05/07/2014 06:44 PM, Stephen Frost wrote:
> >> >* dlo(at)isam(dot)kiwi (dlo(at)isam(dot)kiwi) wrote:
> >> >>but when the credential contains the delimiter (colon) it fails to be
> >> >>read back out and app responds with "invalid credentials".
> >> >>
> >> >>x.x.x.x:5432:*:username:password:with:colons
> >> >
> >> >Per the fine documentation, you need to escape any such usage with a
> >> >backslash. Please review:
> >>
> >> Stephen, you missed the context. pgadmin3 saves .pgpass, when you
> >> check the "store password" checkbox in the connection dialog. And
> >> apparantly pgadmin3 doesn't do that escaping properly.
> >
> > Wow, that's pretty rough. Hopefully they'll be able to fix it soon. :)
> >
> > Thanks,
> >
> > Stephen
>
>
>
> --
> Dave Page
> Blog: http://pgsnake.blogspot.com
> Twitter: @pgsnake
>
> EnterpriseDB UK: http://www.enterprisedb.com
> The Enterprise PostgreSQL Company
>

--
*Akshay Joshi*
*Principal Software Engineer *

*Phone: +91 20-3058-9517Mobile: +91 976-788-8246*

In response to

Responses

Browse pgadmin-hackers by date

  From Date Subject
Next Message Dave Page 2014-05-09 14:16:05 pgAdmin III commit: Support PG 9.4 without bleating.
Previous Message Dave Page 2014-05-08 08:07:49 Re: Re: [BUGS] BUG #10250: pgAdmin III 1.16.1 stores unescaped plaintext password

Browse pgsql-bugs by date

  From Date Subject
Next Message Leif Jensen 2014-05-08 13:59:09 Re: Server process crash - Segmentation fault
Previous Message Dave Page 2014-05-08 08:07:49 Re: Re: [BUGS] BUG #10250: pgAdmin III 1.16.1 stores unescaped plaintext password