Skip to content

Commit

Permalink
disable keyring per default
Browse files Browse the repository at this point in the history
  • Loading branch information
radoering committed Nov 22, 2024
1 parent c70cbf4 commit a09fed1
Show file tree
Hide file tree
Showing 8 changed files with 45 additions and 20 deletions.
14 changes: 8 additions & 6 deletions docs/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -249,7 +249,7 @@ across all your projects if incorrectly set.

**Environment Variable**: `POETRY_INSTALLER_ONLY_BINARY`

*Introduced in 1.9.0*
*Introduced in 2.0.0*

When set, this configuration allows users to enforce the use of binary distribution format for all, none or
specific packages.
Expand Down Expand Up @@ -495,7 +495,7 @@ Set repository credentials (`username` and `password`) for `<name>`.
See [Repositories - Configuring credentials]({{< relref "repositories#configuring-credentials" >}})
for more information.

### `pypi-token.<name>`:
### `pypi-token.<name>`

**Type**: `string`

Expand All @@ -505,7 +505,7 @@ Set repository credentials (using an API token) for `<name>`.
See [Repositories - Configuring credentials]({{< relref "repositories#configuring-credentials" >}})
for more information.

### `certificates.<name>.cert`:
### `certificates.<name>.cert`

**Type**: `string | boolean`

Expand All @@ -518,7 +518,7 @@ for more information.
This configuration can be set to `false`, if TLS certificate verification should be skipped for this
repository.

### `certificates.<name>.client-cert`:
### `certificates.<name>.client-cert`

**Type**: `string`

Expand All @@ -528,14 +528,16 @@ Set client certificate for repository `<name>`.
See [Repositories - Configuring credentials - Custom certificate authority]({{< relref "repositories#custom-certificate-authority-and-mutual-tls-authentication" >}})
for more information.

### `keyring.enabled`:
### `keyring.enabled`

**Type**: `boolean`

**Default**: `true`
**Default**: `false`

**Environment Variable**: `POETRY_KEYRING_ENABLED`

*Changed default to `false` in 2.0.0*

Enable the system keyring for storing credentials.
See [Repositories - Configuring credentials]({{< relref "repositories#configuring-credentials" >}})
for more information.
15 changes: 9 additions & 6 deletions docs/repositories.md
Original file line number Diff line number Diff line change
Expand Up @@ -472,16 +472,19 @@ poetry config http-basic.pypi <username> <password>
You can also specify the username and password when using the `publish` command
with the `--username` and `--password` options.

If a system keyring is available and supported, the password is stored to and retrieved from the keyring. In the above example, the credential will be stored using the name `poetry-repository-pypi`. If access to keyring fails or is unsupported, this will fall back to writing the password to the `auth.toml` file along with the username.

Keyring support is enabled using the [keyring library](https://pypi.org/project/keyring/). For more information on supported backends refer to the [library documentation](https://keyring.readthedocs.io/en/latest/?badge=latest).

If you do not want to use the keyring, you can tell Poetry to disable it and store the credentials in plaintext config files:
If a system keyring is available and supported, the password is stored to and retrieved from the keyring.
Otherwise, credentials are stored in plaintext config files.
In order to use keyring, you have to enable keyring support:

```bash
poetry config keyring.enabled false
poetry config keyring.enabled true
```

In the above example, the credential will be stored using the name `poetry-repository-pypi`.
If access to keyring is disabled, fails or is unsupported, this will fall back to writing the password to the `auth.toml` file along with the username.

Keyring support is enabled using the [keyring library](https://pypi.org/project/keyring/). For more information on supported backends refer to the [library documentation](https://keyring.readthedocs.io/en/latest/?badge=latest).

{{% note %}}

Poetry will fall back to Pip style use of keyring so that backends like
Expand Down
2 changes: 1 addition & 1 deletion src/poetry/config/config.py
Original file line number Diff line number Diff line change
Expand Up @@ -134,7 +134,7 @@ class Config:
},
"system-git-client": False,
"keyring": {
"enabled": True,
"enabled": False,
},
}

Expand Down
6 changes: 5 additions & 1 deletion src/poetry/utils/password_manager.py
Original file line number Diff line number Diff line change
Expand Up @@ -154,7 +154,11 @@ def keyring(self) -> PoetryKeyring:

@staticmethod
def warn_plaintext_credentials_stored() -> None:
logger.warning("Using a plaintext file to store credentials")
logger.warning(
"Using a plaintext file to store credentials.\n"
"Enable keyring support (`poetry config keyring.enabled true`)"
" to store credentials securely."
)

def set_pypi_token(self, repo_name: str, token: str) -> None:
if not self.use_keyring:
Expand Down
4 changes: 4 additions & 0 deletions tests/config/test_config.py
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,10 @@ def test_config_expands_tilde_for_virtualenvs_path(
def test_disabled_keyring_is_unavailable(
config: Config, with_simple_keyring: None, dummy_keyring: DummyBackend
) -> None:
manager = PasswordManager(config)
assert not manager.use_keyring

config.config["keyring"]["enabled"] = True
manager = PasswordManager(config)
assert manager.use_keyring

Expand Down
12 changes: 6 additions & 6 deletions tests/console/commands/test_config.py
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ def test_list_displays_default_value_if_not_set(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
requests.max-retries = 0
solver.lazy-wheel = true
system-git-client = false
Expand Down Expand Up @@ -92,7 +92,7 @@ def test_list_displays_set_get_setting(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
requests.max-retries = 0
solver.lazy-wheel = true
system-git-client = false
Expand Down Expand Up @@ -145,7 +145,7 @@ def test_unset_setting(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
requests.max-retries = 0
solver.lazy-wheel = true
system-git-client = false
Expand Down Expand Up @@ -176,7 +176,7 @@ def test_unset_repo_setting(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
requests.max-retries = 0
solver.lazy-wheel = true
system-git-client = false
Expand Down Expand Up @@ -305,7 +305,7 @@ def test_list_displays_set_get_local_setting(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
requests.max-retries = 0
solver.lazy-wheel = true
system-git-client = false
Expand Down Expand Up @@ -344,7 +344,7 @@ def test_list_must_not_display_sources_from_pyproject_toml(
installer.only-binary = null
installer.parallel = true
installer.re-resolve = true
keyring.enabled = true
keyring.enabled = false
repositories.foo.url = "https://foo.bar/simple/"
requests.max-retries = 0
solver.lazy-wheel = true
Expand Down
6 changes: 6 additions & 0 deletions tests/utils/test_authenticator.py
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,12 @@ def repo() -> dict[str, dict[str, str]]:
return {"foo": {"url": "https://foo.bar/simple/"}}


@pytest.fixture
def config(config: Config) -> Config:
config.config["keyring"]["enabled"] = True
return config


@pytest.fixture
def mock_config(config: Config, repo: dict[str, dict[str, str]]) -> Config:
config.merge(
Expand Down
6 changes: 6 additions & 0 deletions tests/utils/test_password_manager.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,12 @@
from tests.conftest import DummyBackend


@pytest.fixture
def config(config: Config) -> Config:
config.config["keyring"]["enabled"] = True
return config


def test_set_http_password(
config: Config, with_simple_keyring: None, dummy_keyring: DummyBackend
) -> None:
Expand Down

0 comments on commit a09fed1

Please sign in to comment.