feat: current state
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# Security model
|
||||
|
||||
Azure CLI discovers management-plane resources only. It does **not** grant
|
||||
PostgreSQL data-plane access. PostgreSQL connections use a separate username
|
||||
and password and must use certificate and hostname validated TLS.
|
||||
|
||||
## Secrets
|
||||
|
||||
- Connection profiles store metadata and an optional system-keychain reference;
|
||||
they never store a password.
|
||||
- A missing or unavailable keychain requires password entry for the current
|
||||
session. There is no clear-text fallback file or environment-variable store.
|
||||
- Existing PostgreSQL passwords cannot be recovered. Only a newly created or
|
||||
reset password can be offered once for copying.
|
||||
- The one-time copy action consumes the application-held credential regardless
|
||||
of whether the platform clipboard write succeeds. Clipboard history and other
|
||||
applications are outside the application's control.
|
||||
|
||||
## SQL and administration
|
||||
|
||||
The SQL workspace intentionally sends PostgreSQL SQL without an allowlist.
|
||||
The connected PostgreSQL role is the authorization boundary. Guided inserts use
|
||||
parameters and guided table deletion requires an exact qualified-name
|
||||
confirmation without `CASCADE`.
|
||||
|
||||
PostgreSQL requires a SQL password literal for role-password DDL. The role
|
||||
service therefore owns a narrow, zeroizing literal renderer used only for role
|
||||
creation and password reset. The application cannot control server-side audit
|
||||
logging or driver-internal transport buffers.
|
||||
Reference in New Issue
Block a user