tiup icon indicating copy to clipboard operation
tiup copied to clipboard

tiup leaks password in output

Open mzhang77 opened this issue 1 year ago • 0 comments

Bug Report

Please answer these questions before submitting your issue. Thanks!

  1. What did you do?
$ tiup dumpling -o tmp -uroot -ptidb -Btest -F256Mib
Checking updates for component dumpling... Timedout (after 2s)
Starting component dumpling: /home/ec2-user/.tiup/components/dumpling/v7.6.0/dumpling -o tmp -uroot -ptidb -Btest -F256Mib
Release version: v7.6.0
  1. What did you expect to see? Password should not appear in command output. Because in a production system, this output often goes to a log file. And the log file may be viewed by people who are not supposed to know database password.

  2. What did you see instead? -ptidb

  3. What version of TiUP are you using (tiup --version)? $ tiup --version 1.14.0 v1.14.0-nightly-24 Go Version: go1.21.6 Git Ref: master GitHash: 38b6c96c2d27f16bbc7fd95644235010d319f6cc

mzhang77 avatar Feb 05 '24 21:02 mzhang77