microsoft / microsoft/vscode-pgsql
Dev container connections lose SecretStore entry on rebuild
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 395
- Forks
- 33
- Avg merge
- 1h 46m
- Merged PRs (30d)
- 3
Description
Summary
When a workspace connection profile is stored in .vscode/settings.json with a
password field, the extension automatically strips the plaintext password from
the file (expected — plaintext passwords shouldn't be committed). However, when a
Dev Container is rebuilt or VS Code re-establishes the remote connection, the
corresponding SecretStore entry is not present, leaving the connection in a broken
state until the user manually opens the connection editor and re-saves.
Steps to reproduce
- Add a connection profile to
.vscode/settings.json(or check one in) with a
passwordfield populated. - Open the workspace in a Dev Container.
- Observe the
passwordfield is immediately stripped fromsettings.jsonby the
extension (expected behavior). - The connection is shown as errored in the extension — it has no password to use.
- Open the connection editor in the extension UI, make no changes, and click Save.
- The connection now works (SecretStore entry is created).
- Rebuild the Dev Container (e.g., to update a dependency or add an extension).
- After rebuild, the connection is broken again — back to step 4.
Expected behavior
On first activation of a connection profile from workspace settings, the extension
should prompt for the password and store it in SecretStore — or otherwise surface
a clear recovery path — rather than silently leaving the connection in an errored
state. Subsequent cold starts (e.g., container rebuild) should also trigger this
flow if no SecretStore entry exists for the profile.
Actual behavior
The connection is left silently broken. The only workaround is to open the
connection editor and re-save, which is not obvious and must be repeated on every
container rebuild.
Workaround
Open the connection via the extension UI → Edit → Save (no changes needed). This
creates the SecretStore entry and the connection begins working. Must be repeated
after each container rebuild.
Environment
- Extension version: v1.19.0 (pre-release)
- VS Code: remote / Dev Container
- Connection storage:
.vscode/settings.json(workspace scope)
Related
- Closes #191 (the connection-storage-in-workspace-settings feature request, now
shipped — this is a follow-on friction point in the devcontainer flow) - Related: #143 (password retrieval via custom mechanism)
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the workspace-scoped .vscode/settings.json connection flow and the first activation after a Dev Container rebuild. Trace how the connection editor creates the SecretStore entry and how the extension handles a missing entry. Done means a rebuilt container either prompts for the password or shows a clear recovery path, and the connection no longer fails silently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- postgresql, vscode
- Domain
- authentication, devtools
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100