30 lines
1.4 KiB
Markdown
30 lines
1.4 KiB
Markdown
# Security model
|
|
|
|
Azure CLI discovers management-plane resources only. It does **not** grant
|
|
PostgreSQL data-plane access. PostgreSQL connections use a separate username
|
|
and password and must use certificate and hostname validated TLS.
|
|
|
|
## Secrets
|
|
|
|
- Connection profiles store metadata and an optional system-keychain reference;
|
|
they never store a password.
|
|
- A missing or unavailable keychain requires password entry for the current
|
|
session. There is no clear-text fallback file or environment-variable store.
|
|
- Existing PostgreSQL passwords cannot be recovered. Only a newly created or
|
|
reset password can be offered once for copying.
|
|
- The one-time copy action consumes the application-held credential regardless
|
|
of whether the platform clipboard write succeeds. Clipboard history and other
|
|
applications are outside the application's control.
|
|
|
|
## SQL and administration
|
|
|
|
The SQL workspace intentionally sends PostgreSQL SQL without an allowlist.
|
|
The connected PostgreSQL role is the authorization boundary. Guided inserts use
|
|
parameters and guided table deletion requires an exact qualified-name
|
|
confirmation without `CASCADE`.
|
|
|
|
PostgreSQL requires a SQL password literal for role-password DDL. The role
|
|
service therefore owns a narrow, zeroizing literal renderer used only for role
|
|
creation and password reset. The application cannot control server-side audit
|
|
logging or driver-internal transport buffers.
|