Bug report #20662

Processing modeler: PostgreSQL execute and load SQL saves password in cleartext

Added by Samuel Oester about 1 year ago. Updated 12 months ago.

Status:Closed
Priority:Normal
Assignee:-
Category:Processing/Core
Affected QGIS version:3.4.2 Regression?:No
Operating System:MacOS 10.11.6 Easy fix?:No
Pull Request or Patch supplied:No Resolution:no timely feedback
Crashes QGIS or corrupts data:No Copied to github as #:28482

Description

If using a Postgres Layer with authentication stored in authentication DB as input in 'PostgreSQL execute and load SQL', credentials are stored in cleartext in output layer.
Auth DB id is not used.

History

#1 Updated by Victor Olaya about 1 year ago

I dont understand the error. The algorithm that you mention does not take a layer as input. Instead, it takes a DB connection (just identified with its name), and then a SQL sentence.

I just checked that, for other algorithms that take vector layers, if the layer is based on a PostGIS connection, it adds the authid as param in the log, not the credentials

#2 Updated by Giovanni Manghi about 1 year ago

  • Status changed from Open to Feedback

#3 Updated by Giovanni Manghi 12 months ago

  • Resolution set to no timely feedback
  • Status changed from Feedback to Closed

Closing for lack of feedback.

Also available in: Atom PDF