To Reproduce
- Create an S3 destination whose access key and secret contain only letters, digits and
/. Most real keys look like this (Backblaze B2, AWS).
- Create a scheduled backup for a database that uses that destination.
- Let the backup run, or run it manually.
- Run
docker service logs dokploy on the Dokploy host. The Executing backup command entry shows both credentials in plaintext:
INFO (7): Executing backup command: postgres database
rcloneCommand: "rclone rcat --s3-provider=Other --s3-access-key-id=001aaaabbbbccccdd0000000001 --s3-secret-access-key=K001FAKEfakeFAKEfake/FAKEfakeFAKE --s3-region=us-west-001 --s3-endpoint=https\://s3.us-west-001.backblazeb2.com ..."
Current vs. Expected behavior
Expected: the access key and secret are redacted, as #4648 intended when it fixed #4621.
Current: both are logged in plaintext on every backup run. Anyone who can read the Dokploy service logs, or wherever they are shipped, gets full access to the backup bucket. That is read and delete access to every database backup stored there.
Cause: redactRcloneCredentials() (packages/server/src/utils/backups/redact.ts) only matches double-quoted values:
.replace(/(--s3-access-key-id=)"[^"]*"/g, '$1"[REDACTED]"')
.replace(/(--s3-secret-access-key=)"[^"]*"/g, '$1"[REDACTED]"');
eeb6e7b ("fix(security): escape S3/rclone args and restore paths to prevent command injection") switched getS3Credentials() to shell-quote:
`--s3-access-key-id=${quote([accessKey])}`,
`--s3-secret-access-key=${quote([secretAccessKey])}`,
quote() leaves a value bare when it has no special characters, so the flags come out unquoted, as --s3-secret-access-key=K001..., and the redaction regex never matches.
The tests in apps/dokploy/__test__/backups/redact-credentials.test.ts build hand-written double-quoted command strings instead of calling getS3Credentials(), so they kept passing after the format changed.
Provide environment information
Operating System:
OS: Ubuntu 24.04.4 LTS
Arch: x86_64
Dokploy version: v0.30.7 (still present on canary as of a0e0574bc)
Docker: 29.6.2
VPS Provider: self-hosted (Incus instance on a dedicated server)
What applications/services are you trying to deploy?
Postgres database with a scheduled S3 backup (Backblaze B2)
Which area(s) are affected? (Select all that apply)
Databases
Are you deploying the applications where Dokploy is installed or on a remote server?
Same server where Dokploy is installed
Additional context
#4951 fixed this: it redacts unquoted, single-quoted and space-separated forms, and tests against output from getS3Credentials(), so the next change to quoting breaks the test instead of silently leaking. Its description says the same credentials also reach notifications, API error responses and the restore stream in the UI. It was a draft and was closed on Sep 11 without review.
Will you send a PR to fix it?
No
To Reproduce
/. Most real keys look like this (Backblaze B2, AWS).docker service logs dokployon the Dokploy host. TheExecuting backup commandentry shows both credentials in plaintext:Current vs. Expected behavior
Expected: the access key and secret are redacted, as #4648 intended when it fixed #4621.
Current: both are logged in plaintext on every backup run. Anyone who can read the Dokploy service logs, or wherever they are shipped, gets full access to the backup bucket. That is read and delete access to every database backup stored there.
Cause:
redactRcloneCredentials()(packages/server/src/utils/backups/redact.ts) only matches double-quoted values:eeb6e7b ("fix(security): escape S3/rclone args and restore paths to prevent command injection") switched
getS3Credentials()toshell-quote:quote()leaves a value bare when it has no special characters, so the flags come out unquoted, as--s3-secret-access-key=K001..., and the redaction regex never matches.The tests in
apps/dokploy/__test__/backups/redact-credentials.test.tsbuild hand-written double-quoted command strings instead of callinggetS3Credentials(), so they kept passing after the format changed.Provide environment information
Operating System: OS: Ubuntu 24.04.4 LTS Arch: x86_64 Dokploy version: v0.30.7 (still present on canary as of a0e0574bc) Docker: 29.6.2 VPS Provider: self-hosted (Incus instance on a dedicated server) What applications/services are you trying to deploy? Postgres database with a scheduled S3 backup (Backblaze B2)Which area(s) are affected? (Select all that apply)
Databases
Are you deploying the applications where Dokploy is installed or on a remote server?
Same server where Dokploy is installed
Additional context
#4951 fixed this: it redacts unquoted, single-quoted and space-separated forms, and tests against output from
getS3Credentials(), so the next change to quoting breaks the test instead of silently leaking. Its description says the same credentials also reach notifications, API error responses and the restore stream in the UI. It was a draft and was closed on Sep 11 without review.Will you send a PR to fix it?
No