Skip to content

Support marking commands and variables as secret #8

Description

@MalloyDelacroix

Some stored commands and especially variables (API tokens, credentials embedded in commands, sensitive paths, usernames, etc.) should not be included in exports and should not be freely visible when listing or displaying entries. CmdBox needs a way to mark a command or variable as a secret and have that respected throughout the app.

Security level is currently undecided. The levels being considered are:

  1. Export exclusion only. Secrets are omitted from export files but otherwise stored and displayed normally.
  2. Export exclusion and display masking. Secrets are also masked (e.g. ******) when listed or shown in addition to being excluded from export.
  3. Reference only, no stored value. Instead of storing secret values, store a reference to an environment variable and resolve it at runtime from the shell environment. No plaintext value is ever stored.
  4. External secret manager. Store a reference to a secret in a tool like 1Password CLI or Vault and fetch the value at execution time. Secret entries are never stored and CmdBox never even sees them.
  5. Encrypted via a cryptography library. Secrets are encrypted before being written to the database.
    • User password or stored key?
    • Where is key stored?
    • Master key or key per value?
  6. OS keychain integration. Secrets are stored in the platform's native credential store.
    • Due to the differences in how different platforms handle secrets, this solution is very unlikely.

Considerations:

  • Ensure secrets are not shown in history.
  • Secret commands/variables nested inside of non-secret commands/variables need to retain secrecy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions