Files
azure-database-tui/docs/security.md
Louis Frei 8dda5dcf23
validate / macos-arm64 (push) Canceled after 0s
validate / windows-x86_64 (push) Canceled after 0s
feat: current state
2026-08-13 20:18:30 +02:00

30 lines
1.4 KiB
Markdown

# Security model
Azure CLI discovers management-plane resources only. It does **not** grant
PostgreSQL data-plane access. PostgreSQL connections use a separate username
and password and must use certificate and hostname validated TLS.
## Secrets
- Connection profiles store metadata and an optional system-keychain reference;
they never store a password.
- A missing or unavailable keychain requires password entry for the current
session. There is no clear-text fallback file or environment-variable store.
- Existing PostgreSQL passwords cannot be recovered. Only a newly created or
reset password can be offered once for copying.
- The one-time copy action consumes the application-held credential regardless
of whether the platform clipboard write succeeds. Clipboard history and other
applications are outside the application's control.
## SQL and administration
The SQL workspace intentionally sends PostgreSQL SQL without an allowlist.
The connected PostgreSQL role is the authorization boundary. Guided inserts use
parameters and guided table deletion requires an exact qualified-name
confirmation without `CASCADE`.
PostgreSQL requires a SQL password literal for role-password DDL. The role
service therefore owns a narrow, zeroizing literal renderer used only for role
creation and password reset. The application cannot control server-side audit
logging or driver-internal transport buffers.