microsoft / microsoft/vscode-pgsql

Dev container connections lose SecretStore entry on rebuild

Open
#246 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
No language data
Stars
395
Forks
33
Avg merge
1h 46m
Merged PRs (30d)
3

Description

Summary

When a workspace connection profile is stored in .vscode/settings.json with a
password field, the extension automatically strips the plaintext password from
the file (expected — plaintext passwords shouldn't be committed). However, when a
Dev Container is rebuilt or VS Code re-establishes the remote connection, the
corresponding SecretStore entry is not present, leaving the connection in a broken
state until the user manually opens the connection editor and re-saves.

Steps to reproduce

  1. Add a connection profile to .vscode/settings.json (or check one in) with a
    password field populated.
  2. Open the workspace in a Dev Container.
  3. Observe the password field is immediately stripped from settings.json by the
    extension (expected behavior).
  4. The connection is shown as errored in the extension — it has no password to use.
  5. Open the connection editor in the extension UI, make no changes, and click Save.
  6. The connection now works (SecretStore entry is created).
  7. Rebuild the Dev Container (e.g., to update a dependency or add an extension).
  8. After rebuild, the connection is broken again — back to step 4.

Expected behavior

On first activation of a connection profile from workspace settings, the extension
should prompt for the password and store it in SecretStore — or otherwise surface
a clear recovery path — rather than silently leaving the connection in an errored
state. Subsequent cold starts (e.g., container rebuild) should also trigger this
flow if no SecretStore entry exists for the profile.

Actual behavior

The connection is left silently broken. The only workaround is to open the
connection editor and re-save, which is not obvious and must be repeated on every
container rebuild.

Workaround

Open the connection via the extension UI → Edit → Save (no changes needed). This
creates the SecretStore entry and the connection begins working. Must be repeated
after each container rebuild.

Environment

  • Extension version: v1.19.0 (pre-release)
  • VS Code: remote / Dev Container
  • Connection storage: .vscode/settings.json (workspace scope)

Related

  • Closes #191 (the connection-storage-in-workspace-settings feature request, now
    shipped — this is a follow-on friction point in the devcontainer flow)
  • Related: #143 (password retrieval via custom mechanism)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the workspace-scoped .vscode/settings.json connection flow and the first activation after a Dev Container rebuild. Trace how the connection editor creates the SecretStore entry and how the extension handles a missing entry. Done means a rebuilt container either prompts for the password or shows a clear recovery path, and the connection no longer fails silently.

Written by the indexing model from the issue text.

Assessment

Tech stack
postgresql, vscode
Domain
authentication, devtools
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.