erplibre/script/todo
Mathieu Benoit 3f97b0a49c [FIX] security: the KeePass password leaves the command line too
Same exposure as the master password, same fix. kdbx_manager put the Odoo
password straight into the web_login command; /proc/<pid>/cmdline is
readable by every user on the machine, and no downstream filter reaches
that.

The command now carries the NAME of an environment variable, never the
value. One name per entry, because several credentials go out in a single
"parallel" call and a single variable could not tell them apart.
get_extra_command_user therefore returns (fragments, variables), and the
two call sites hand the variables to exec_command_live, which already
merged an environment.

Two things found on the way. web_login re-sent config.default_password_auth
when it retried after dismissing a modal, ignoring whatever the caller had
passed -- the retry silently fell back to "admin". And install_forgejo
printed the admin password back to the terminal, hence into the install log
and any CI capture; its own header already documents the default.

A test pins the guarantee: the fragment must not contain the password.

--- FR ---

Même exposition que pour le mot de passe maître, même correctif.
kdbx_manager mettait le mot de passe Odoo directement dans la commande
web_login ; /proc/<pid>/cmdline est lisible par tout utilisateur de la
machine, et aucun filtre en aval ne l'atteint.

La commande porte désormais le NOM d'une variable d'environnement, jamais
la valeur. Un nom par entrée, car plusieurs identifiants partent dans un
seul appel « parallel » et une variable unique ne saurait les distinguer.
get_extra_command_user rend donc (fragments, variables), et les deux
appelants confient les variables à exec_command_live, qui fusionnait déjà
un environnement.

Deux trouvailles en chemin. web_login renvoyait config.default_password_auth
à la reprise après une modale, ignorant ce que l'appelant avait fourni — la
reprise retombait en silence sur « admin ». Et install_forgejo réaffichait
le mot de passe administrateur, donc dans le journal d'installation et
toute capture de CI ; son propre en-tête documente déjà le défaut.

Un test verrouille la garantie : le fragment ne doit pas porter le secret.

Assisted-by: Claude Opus 5
2026-08-23 02:11:50 -04:00
..
mail [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
auto_ask.py [ADD] migration: announce the countdown, and cycle three panel states 2026-08-22 07:23:59 -04:00
database_manager.py [ADD] analyse: inspect an Odoo database without restoring it 2026-08-10 03:10:50 -04:00
kdbx_manager.py [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
logo_ascii.txt [IMP] bot assistant TODO 2025-04-27 02:40:20 -04:00
migration_form.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
migration_stats.py [ADD] migration: see and repair the website COW views 2026-08-10 03:10:50 -04:00
migration_status.py [ADD] migration state: read the server log so nobody has to 2026-08-22 07:23:59 -04:00
migration_status_tui.py [FIX] migration state: open the quality screen in its own process 2026-08-22 07:23:59 -04:00
qemu_deploy_form.py [ADD] todo qemu: build and test the mobile app, and fail the VM if it breaks 2026-08-23 02:07:42 -04:00
qemu_hardware.py [ADD] qemu : régler le mode CPU, les écrans et le réseau d'une VM 2026-08-23 02:07:42 -04:00
qemu_install_monitor.py [ADD] script todo: dire depuis quand un journal d'installation est muet 2026-08-23 02:07:42 -04:00
README.base.md [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
README.fr.md [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
README.md [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
source_todo.sh [ADD] install: mise as Python provider, pyenv as fallback 2026-08-16 23:33:49 -04:00
textual_setup.py [ADD] todo: install Textual on demand 2026-08-07 03:22:26 -04:00
todo.json [ADD] todo: QEMU/KVM menu 2026-08-07 03:22:26 -04:00
todo.py [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
todo_example.json [UPD] TODO: simplify code by reusing method and support same command 2025-04-28 00:35:27 -04:00
todo_file_browser.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
todo_i18n.py [UPD] analyse: give every "go further" entry an icon, and guard it 2026-08-23 02:09:59 -04:00
todo_prefs.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
todo_telemetry.py [ADD] todo: navigation telemetry 2026-08-07 03:22:26 -04:00
todo_upgrade.py [ADD] filestore: purge once at the end, tidy at the restore, see the 30 MB 2026-08-23 02:09:59 -04:00
version_manager.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00

TODO is an assistant robot to use ERPLibre Execute it with ./script/todo/todo.py or make todo.

For a new project, copy todo_example.json to private/todo/todo_override.json | private/todo/todo_override_private.json and edit it.

The mail/ package is the mail client reachable from Assistant > Mail: several IMAP/SMTP accounts, a local cache, and a Textual TUI. See ../../doc/EMAIL.md.