Title: Secure token storage · Issue #715 · python-gitlab/python-gitlab · GitHub
Open Graph Title: Secure token storage · Issue #715 · python-gitlab/python-gitlab
X Title: Secure token storage · Issue #715 · python-gitlab/python-gitlab
Description: Description of the problem, including code/CLI snippet I haven't read the code, but from reading the documentation, it sounds like python-gitlab only has support for soliciting a private-token from a plain-text config file in the user's ...
Open Graph Description: Description of the problem, including code/CLI snippet I haven't read the code, but from reading the documentation, it sounds like python-gitlab only has support for soliciting a private-token from...
X Description: Description of the problem, including code/CLI snippet I haven't read the code, but from reading the documentation, it sounds like python-gitlab only has support for soliciting a private-token ...
Opengraph URL: https://github.com/python-gitlab/python-gitlab/issues/715
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Secure token storage","articleBody":"## Description of the problem, including code/CLI snippet\r\n\r\nI haven't read the code, but from reading the documentation, it sounds like python-gitlab only has support for soliciting a private-token from a plain-text config file in the user's home directory. Better techniques exist for storing secrets more securely, including the [keyring library](https://pypi.org/project/keyring), which stores passwords in system-managed secure stores. It would be nice if the library would allow and even recommend that tokens be stored/queried there.\r\n\r\n## Expected Behavior\r\n\r\nUsers would be incentivized not to store any secrets on the file system in plain text.\r\n\r\n## Actual Behavior\r\n\r\nUsers are required to store secrets in the file system in plain text.\r\n\r\n## Specifications\r\n\r\n - python-gitlab version: 1.8.0\r\n - API version you are using (v3/v4): n/a\r\n - Gitlab server version (or gitlab.com): n/a\r\n","author":{"url":"https://github.com/jaraco","@type":"Person","name":"jaraco"},"datePublished":"2019-02-26T18:30:25.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":3},"url":"https://github.com/715/python-gitlab/issues/715"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:4444043b-6f31-ef91-5a88-a1473ff7c5b8 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | C9A8:22CCE7:5A011C:788078:6973F2E6 |
| html-safe-nonce | 57d398c5c0d9fa094965caf75a0f8fd006041db9a1ed3154798029f34f6378c7 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDOUE4OjIyQ0NFNzo1QTAxMUM6Nzg4MDc4OjY5NzNGMkU2IiwidmlzaXRvcl9pZCI6Ijg0OTEyNjAyMTU1MTk2MDU0NzgiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 256703131d668079268c9f45d3168664b2340cb8c522c0d10ea9231e7749dc32 |
| hovercard-subject-tag | issue:414755158 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python-gitlab/python-gitlab/715/issue_layout |
| twitter:image | https://opengraph.githubassets.com/f19022761b4ba2776ca611ee73e7faaef88b94ec528d7693d6c961ae9c80383c/python-gitlab/python-gitlab/issues/715 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/f19022761b4ba2776ca611ee73e7faaef88b94ec528d7693d6c961ae9c80383c/python-gitlab/python-gitlab/issues/715 |
| og:image:alt | Description of the problem, including code/CLI snippet I haven't read the code, but from reading the documentation, it sounds like python-gitlab only has support for soliciting a private-token from... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | jaraco |
| hostname | github.com |
| expected-hostname | github.com |
| None | 99794f659b61e238a7ec37595eeb36b54a0ba1f2ae246f51ccb8ac5e4f08812e |
| turbo-cache-control | no-preview |
| go-import | github.com/python-gitlab/python-gitlab git https://github.com/python-gitlab/python-gitlab.git |
| octolytics-dimension-user_id | 28886265 |
| octolytics-dimension-user_login | python-gitlab |
| octolytics-dimension-repository_id | 8077625 |
| octolytics-dimension-repository_nwo | python-gitlab/python-gitlab |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 8077625 |
| octolytics-dimension-repository_network_root_nwo | python-gitlab/python-gitlab |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 8b15a65f03216f079a4ae509ff400d3e2ce03b58 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width