all messages for Emacs-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: Michael Mauger <mmaug@yahoo.com>
Subject: Re: sql-mode password display
Date: Thu, 3 Mar 2005 20:51:20 +0000 (UTC)	[thread overview]
Message-ID: <loom.20050303T211709-226@post.gmane.org> (raw)
In-Reply-To: kx9vf8a9e9x.fsf@panix5.panix.com

rb writes:
> 
> When I use sql mode:
> 

I'm the current maintainer of sql-mode.  I'll assume that you are using
the latest version of sql.el (available at http://savannah.gnu.org/cgi-
bin/viewcvs/emacs/emacs/lisp/progmodes/sql.el).  Prior versions were
similar so most of this will apply.

> M-x sql-msql, then follow prompts, 
> 
> I get the interactive sql buffer which works very well for me. The only
> problem is that when I list the processes, the mysql process shows my
> password, and I would like to know if there is something I can do to
> conceal it?
> 
> rb <at> antonio 102% ps -ef | grep sql
>       rb      29562      29372  0 08:44:27 pts/4   0:00 grep sql
>       rb      29717      15897  0 08:43:34 pts/8   0:00
>       /usr/freeware/bin/mysql --user=rb --password=my_password
>       --host=sanmarco test
> 
> I was trying to find wheter there was a customizable variable to
> conceal/display password and with M-x customize-apropos, I discovered
> that the password was displayed in the customization buffer as well:
> 

The problem here is that mysql accepts the password as a 
command line parameter and the `ps' shows all command line
parameters.  

The alternative is to use the `--password' (or `-p') option without a 
value and allow `mysql' to prompt you for it.  The current version
omits the `--password' option entirely if `sql-password' is an empty
string.

Take a look at the function `sql-connect-mysql' (or `sql-mysql' in
older versions).  There is a chunk of code like this:

   (if (not (string= "" sql-password))
       (setq params (append (list (concat "--password=" sql-password)) params)))

Try changing it to:

   (if (not (string= "" sql-password))
       (setq params (append (list (concat "--password=" sql-password)) params))
     (setq params (append '("--password") params)))

and remove your sql-password customization.  You will now be required 
to enter your password each time you start sql-mysql.

I don't use mysql at all so I'm not sure if this is globally appropriate.
Is it possible to connect to mysql without a password at all?  Do we need
to distinguish between prompt me for a password and there is no password?

> Sql Password: Hide my_password
>    State: this option has been changed outside the customize buffer.
> Default password. More
> Parent groups: Sql
> 

Having the password visible in custom is not something that can be 
controlled (that I know of...).  With the above change, obviously 
this becomes moot.

> If I start an ineractive mysql session at the command line in an xwsh
> shell, I get the following (password not displayed):
> 
> rb <at> antonio 101% ps -ef | grep sql
>       rb      29598      29535  0 08:31:14 pts/6   0:00 mysql -h
>       sanmarco -u rb -p test
> 
> Also, working in shell-mode within emacs, to process a batch file, my
> password is displayed in the *shell* buffer, and is retained in the
> command history list.
> 
> >From Emacs shell buffer:
> 
> rb <at> antonio 98% mysql -vv -h sanmarco -u rb -p < dbs.sql > dbs.out0222
> mysql -vv -h sanmarco -u rb -p < dbs.sql > dbs.out0222
> Enter password: my_password
> 
> Within the shell, any other commands requiring a password (ssh, rlogin,
> su, etc), the password is properly not displayed.
> 

If you modify sql.el as described above, sql-interactive-mode should
capture the password prompt and ask for your password in the minibuffer.

> This is GNU Emacs 21.3.1. Thank you, sorry if there's an obvious or
> known solution...
> 
> rb

I hope this helps.  Let me know how it turns out.  If you have any other 
suggestions concerning mysql support please send them along.

-- Michael Mauger
(Please CC: mmaug <at> yahoo <dot> com because I don't follow this 
list carefully...)

  parent reply	other threads:[~2005-03-03 20:51 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-03-02 16:57 sql-mode password display rb
2005-03-02 18:31 ` Kevin Rodgers
2005-03-02 20:35   ` rb
2005-03-03 19:42     ` Kevin Rodgers
2005-03-03 20:51 ` Michael Mauger [this message]
     [not found] ` <mailman.2522.1109885280.32256.help-gnu-emacs@gnu.org>
2005-03-03 23:15   ` rb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=loom.20050303T211709-226@post.gmane.org \
    --to=mmaug@yahoo.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/emacs.git
	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.