contrib: avoid echoing supplied RPC passwords #36433

pull superuser547 wants to merge 1 commits into bitcoin:master from superuser547:contrib/rpcauth-no-password-echo changing 2 files +37 −2
  1. superuser547 commented at 2:43 PM on October 4, 2026: none

    Motivation

    Printing a user-supplied password again exposes a secret without any benefit. This is especially unnecessary in getpass mode: the password is entered hidden, then printed to the screen.

    Changes

    Show the password only when rpcauth.py generated it. Do not echo positional or prompted passwords. JSON output and rpcauth generation remain unchanged; CLI output tests were added.

    Testing

    • python3 -m py_compile share/rpcauth/rpcauth.py
    • python3 -m py_compile test/functional/tool_rpcauth.py
    • ./ci/lint.py --lint=py_lint
    • tool_rpcauth.py in an Ubuntu 24.04 container
    • Manual checks for:
      • generated password output
      • positional password input
      • prompted password input (- / getpass)
      • --json output
  2. DrahtBot added the label Scripts and tools on Oct 4, 2026
  3. DrahtBot commented at 2:43 PM on October 4, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    External sites

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  4. contrib: avoid echoing supplied RPC passwords
    Currently, rpcauth.py echoes user-provided passwords in plain-text output.
    
    Print the password only when rpcauth.py generated it. Leave JSON output unchanged for machine use.
    3e824a3a69
  5. superuser547 force-pushed on Oct 4, 2026
  6. sedited commented at 11:58 AM on October 8, 2026: contributor

    To preserve the time of reviewers, this project requires authors to understand the code they are submitting. Given that the description is entirely LLM generated, I don't think that is the case, so I am closing this again. The change also doesn't seem too useful to me, given that this is a script specifically to create credentials, and not to transport or verify them.

  7. sedited closed this on Oct 8, 2026

  8. superuser547 deleted the branch on Oct 8, 2026

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-11 16:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me