From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Sam Steingold Newsgroups: gmane.emacs.devel Subject: Re: (sql-postgres-login-params): Add user and database defaults. Date: Tue, 11 Nov 2014 14:37:10 -0500 Message-ID: References: <487064807.437464.1415674152184.JavaMail.yahoo@jws10645.mail.bf1.yahoo.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Trace: ger.gmane.org 1415734655 21708 80.91.229.3 (11 Nov 2014 19:37:35 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Tue, 11 Nov 2014 19:37:35 +0000 (UTC) Cc: emacs-devel@gnu.org To: Michael Mauger Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Tue Nov 11 20:37:30 2014 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1XoHFp-0001yL-Px for ged-emacs-devel@m.gmane.org; Tue, 11 Nov 2014 20:37:29 +0100 Original-Received: from localhost ([::1]:50398 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XoHFp-0007GV-FT for ged-emacs-devel@m.gmane.org; Tue, 11 Nov 2014 14:37:29 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:40366) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XoHFZ-0007Bz-8Z for emacs-devel@gnu.org; Tue, 11 Nov 2014 14:37:14 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1XoHFY-0006Bz-B9 for emacs-devel@gnu.org; Tue, 11 Nov 2014 14:37:13 -0500 Original-Received: from mail-lb0-x231.google.com ([2a00:1450:4010:c04::231]:55575) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XoHFX-0006Bl-Vy for emacs-devel@gnu.org; Tue, 11 Nov 2014 14:37:12 -0500 Original-Received: by mail-lb0-f177.google.com with SMTP id z12so1373758lbi.8 for ; Tue, 11 Nov 2014 11:37:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type:content-transfer-encoding; bh=SiLcfnURtdu6NDB3WR2gs6bf8DOfh961Z1PpMuMPS6Y=; b=GwT/WZAlxMuwoPbtU7mEarLbH+Nq1oTqwIJONvHVMEpz/SK8jXQCcRLQmoA45t0ZPr 8cLBkg225UwJZOdPBa/gx2Jih3OyrREG+u2NwxWgcVGuCaQhXo5XBRjOXlfigplx+hTp 9FFVqIsY5rVB0W1mNwVwIUXFGXjhwmpnZn3b37zLvnU9iNJl+/iGCqU4CJPAe+fixedl UdpTf5tF+b055FV2pMy4ylPz1Tvo+HNTUFQgbfLDh+d2fn/rX367jz+/zDCWqiTvX1nc sLRojEvlaPk08kDwvG+mEpTBZWtPwy8LNnTty7AYUwNdNpMK0f5BJb+hL1envM4iX627 VJOA== X-Received: by 10.152.170.194 with SMTP id ao2mr38301083lac.60.1415734630766; Tue, 11 Nov 2014 11:37:10 -0800 (PST) Original-Received: by 10.112.131.72 with HTTP; Tue, 11 Nov 2014 11:37:10 -0800 (PST) In-Reply-To: <487064807.437464.1415674152184.JavaMail.yahoo@jws10645.mail.bf1.yahoo.com> X-Google-Sender-Auth: U9kQj8g5D7-esfvLNJ-WqGg7Szk X-detected-operating-system: by eggs.gnu.org: Error: Malformed IPv6 address (bad octet value). X-Received-From: 2a00:1450:4010:c04::231 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:176779 Archived-At: On Mon, Nov 10, 2014 at 9:49 PM, Michael Mauger wrote: > On Monday, November 10, 2014 4:15 PM, Sam Steingold wrote: >>> * Michael Mauger [2014-11-09 23:39:24 +0000]: >>>> On Friday, November 7, 2014 2:37 PM, Sam Steingold wrote= : >>>> Why did you add defaults to the sql-postgres-login-params option? >>>> No other sql--login-params have them. >>I don't think these defaults are useful (to put it mildly). > So, do you recommend removing the defaults entirely (as opposed to offeri= ng an alternative) for both username and database? yes, I recommend that they are set to the flat list like other products > Are there any others who would like to be heard on this topic? Without a= dditional feedback, I'll go ahead and remove the defaults. you sent your email to me only, not to the list. this reply goes to the list. > Again the lack of prompting/storing of the password is not due the the se= curity concern but because the password cannot be passed directly on the co= mmand line. MySql and Oracle support grab the password and pass the passwo= rd along with the username on the command line; resulting in the security b= ug submission. The implementation of passing passwords on the command line= pre-dates my involvement in sql.el, so while I can't accept blame for the = shortcoming, I do accept responsibilty for building a working solution. I'= m hacking on it currently. Thanks! Sam