⚠️ This issue respects the following points: ⚠️
Bug description
occ files_external:scan does not ask for password on stdin, and there is no option to make it do so, as far as I can tell.
This is a potential security risk, because on systems without hardened /proc, a simple ps -au will tell any unprivileged user the password that was passed on the command line.
Steps to reproduce
- install nextcloud with external storage and session credentials
- try to use the background scan with externally provided passwords
- realize that anybody with a user account on the machine can read the passwords from /proc
Expected behavior
The scan command should ask for the password on stdin instead.
Nextcloud Server version
32
Operating system
None
PHP engine version
None
Web server
None
Database engine version
None
Is this bug present after an update or on a fresh install?
None
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
Configuration report
List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
While this is a security concern in some sense, I think it is fine to open a regular issue here, since admins should know that passing a secret on the command line has security implications.
Bug description
occ files_external:scan does not ask for password on stdin, and there is no option to make it do so, as far as I can tell.
This is a potential security risk, because on systems without hardened
/proc, a simpleps -auwill tell any unprivileged user the password that was passed on the command line.Steps to reproduce
Expected behavior
The scan command should ask for the password on stdin instead.
Nextcloud Server version
32
Operating system
None
PHP engine version
None
Web server
None
Database engine version
None
Is this bug present after an update or on a fresh install?
None
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
Configuration report
List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
While this is a security concern in some sense, I think it is fine to open a regular issue here, since admins should know that passing a secret on the command line has security implications.