Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@
import getpass
import json
import os
import random
import re
import secrets
import string
from typing import Any

Expand Down Expand Up @@ -113,7 +113,8 @@ def user_reset_password(args):

def _create_password(args):
if args.use_random_password:
password = "".join(random.choices(string.printable, k=16))
characters = string.ascii_letters + string.digits + string.punctuation
password = "".join(secrets.choice(characters) for _ in range(16))
elif args.password:
password = args.password
else:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,17 @@
# under the License.
from __future__ import annotations

import argparse
import json
import os
import re
import secrets
import string
import tempfile
from contextlib import redirect_stdout
from importlib import reload
from io import StringIO
from unittest import mock

import pytest

Expand All @@ -39,6 +43,18 @@
TEST_USER3_EMAIL = "test-user3@example.com"


@mock.patch(
"airflow.providers.fab.auth_manager.cli_commands.user_command.secrets.choice",
side_effect=secrets.choice,
)
def test_create_password_uses_csprng_without_whitespace(mock_choice):
args = argparse.Namespace(use_random_password=True, password=None)
password = user_command._create_password(args)
assert mock_choice.call_count == 16
assert len(password) == 16
assert not any(char in string.whitespace for char in password)


def _does_user_belong_to_role(appbuilder, email, rolename):
user = appbuilder.sm.find_user(email=email)
role = appbuilder.sm.find_role(rolename)
Expand Down
Loading