MarketSquare / MarketSquare/Robotframework-Database-Library

Support Robot Framework Secret values for database passwords

Aperta
#259 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@amochin ci sta già lavorando.

Dal 18/9/2026.

Lingua principale
Python
Stelle
179
Fork
178
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Description

Robot Framework 7.4 introduced the Secret type. It allows sensitive values such as passwords to be passed to keywords without exposing them in Robot Framework logs.

I would like to use a secret variable as the db_password argument of Connect To Database:

*** Variables ***
${DB_PASSWORD: Secret}    %{DB_PASSWORD}

*** Test Cases ***
Connect using a secret password
    Connect To Database
    ...    db_module=psycopg
    ...    db_name=example
    ...    db_user=robot
    ...    db_password=${DB_PASSWORD}
    ...    db_host=localhost

The current db_password argument accepts an optional string. Robot Framework deliberately rejects automatic conversion of a Secret object to a string, so the value needs to be accepted and accessed inside DatabaseLibrary before it is passed to the database driver. The error message currently:

ValueError: Argument 'db_password' got value '<secret>' (Secret) that cannot be converted to string or None.
Expected behaviour

Connect To Database should accept both regular strings and Robot Framework Secret objects as db_password.

When a Secret is provided, DatabaseLibrary should:

  • keep it protected while processing and logging connection parameters;
  • access its encapsulated value internally when required by the database driver;
  • avoid including the unwrapped value in log messages or library-generated diagnostics.

Existing string passwords and configuration-file passwords should continue to work unchanged.

It may also be worth checking whether password values passed through custom connection parameters need the same handling.

Compatibility consideration

DatabaseLibrary currently supports Python 3.8.1 and Robot Framework 5.0.1 or newer, while Secret was introduced in Robot Framework 7.4. The implementation therefore needs to preserve compatibility with supported versions or document any resulting change to the minimum Robot Framework version.

Acceptance criteria
  • Connect To Database accepts a Secret object as db_password.
  • The encapsulated value is passed to the database driver.
  • Existing string and None values continue to work.
  • Neither DatabaseLibrary logs nor library-generated diagnostics expose the unwrapped value.
  • Automated tests cover string and Secret password values.
  • The keyword documentation includes a short secret-variable example.
References

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.