Skip to content

use secrets for fab users --use-random-password generation - #72092

Merged
vincbeck merged 1 commit into
apache:mainfrom
Samin061:fab-random-password-secrets
Aug 26, 2026
Merged

vincbeck merged 1 commit into
apache:mainfrom
Samin061:fab-random-password-secrets

Conversation

@Samin061

Copy link
Copy Markdown
Contributor

_create_password builds the --use-random-password value with random.choices, the Mersenne Twister PRNG that Python documents as unfit for security use, so the generated web-login credential comes from a reconstructable stream, and string.printable also seeds it with whitespace and control characters that land in the stored password (roughly 63% of generated values). Switch to secrets.choice over the printable non-whitespace alphabet, matching the generation already used in the teradata provider's encryption_utils and the kubernetes and ssh helpers. Added a regression test asserting the CSPRNG is used and that no whitespace reaches the password.


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

random.choices draws from the Mersenne Twister PRNG that Python documents as unfit for security use, so the generated web-login credential is predictable, and string.printable also seeds the value with whitespace and control characters that land in the stored password.
@vincbeck
vincbeck merged commit 21332ea into apache:main Aug 26, 2026
76 of 77 checks passed
imrichardwu pushed a commit to imrichardwu/airflow that referenced this pull request Sep 11, 2026
…72092)

random.choices draws from the Mersenne Twister PRNG that Python documents as unfit for security use, so the generated web-login credential is predictable, and string.printable also seeds the value with whitespace and control characters that land in the stored password.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants