Skip to content

S3 credentials are logged in plaintext again: redactRcloneCredentials stopped matching after the shell-quote change #5519

Description

@johnmaguire

To Reproduce

  1. Create an S3 destination whose access key and secret contain only letters, digits and /. Most real keys look like this (Backblaze B2, AWS).
  2. Create a scheduled backup for a database that uses that destination.
  3. Let the backup run, or run it manually.
  4. Run docker service logs dokploy on the Dokploy host. The Executing backup command entry shows both credentials in plaintext:
INFO (7): Executing backup command: postgres database
    rcloneCommand: "rclone rcat --s3-provider=Other --s3-access-key-id=001aaaabbbbccccdd0000000001 --s3-secret-access-key=K001FAKEfakeFAKEfake/FAKEfakeFAKE --s3-region=us-west-001 --s3-endpoint=https\://s3.us-west-001.backblazeb2.com ..."

Current vs. Expected behavior

Expected: the access key and secret are redacted, as #4648 intended when it fixed #4621.

Current: both are logged in plaintext on every backup run. Anyone who can read the Dokploy service logs, or wherever they are shipped, gets full access to the backup bucket. That is read and delete access to every database backup stored there.

Cause: redactRcloneCredentials() (packages/server/src/utils/backups/redact.ts) only matches double-quoted values:

.replace(/(--s3-access-key-id=)"[^"]*"/g, '$1"[REDACTED]"')
.replace(/(--s3-secret-access-key=)"[^"]*"/g, '$1"[REDACTED]"');

eeb6e7b ("fix(security): escape S3/rclone args and restore paths to prevent command injection") switched getS3Credentials() to shell-quote:

`--s3-access-key-id=${quote([accessKey])}`,
`--s3-secret-access-key=${quote([secretAccessKey])}`,

quote() leaves a value bare when it has no special characters, so the flags come out unquoted, as --s3-secret-access-key=K001..., and the redaction regex never matches.

The tests in apps/dokploy/__test__/backups/redact-credentials.test.ts build hand-written double-quoted command strings instead of calling getS3Credentials(), so they kept passing after the format changed.

Provide environment information

Operating System:
  OS: Ubuntu 24.04.4 LTS
  Arch: x86_64
Dokploy version: v0.30.7 (still present on canary as of a0e0574bc)
Docker: 29.6.2
VPS Provider: self-hosted (Incus instance on a dedicated server)
What applications/services are you trying to deploy?
  Postgres database with a scheduled S3 backup (Backblaze B2)

Which area(s) are affected? (Select all that apply)

Databases

Are you deploying the applications where Dokploy is installed or on a remote server?

Same server where Dokploy is installed

Additional context

#4951 fixed this: it redacts unquoted, single-quoted and space-separated forms, and tests against output from getS3Credentials(), so the next change to quoting breaks the test instead of silently leaking. Its description says the same credentials also reach notifications, API error responses and the restore stream in the UI. It was a draft and was closed on Sep 11 without review.

Will you send a PR to fix it?

No

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions