Skip to content

Conversation

@sethmlarson
Copy link
Contributor

@sethmlarson sethmlarson commented Jan 16, 2026

@sethmlarson sethmlarson requested a review from a team as a code owner January 16, 2026 17:48
@sethmlarson sethmlarson added type-security A security issue needs backport to 3.10 only security fixes needs backport to 3.11 only security fixes needs backport to 3.12 only security fixes needs backport to 3.13 bugs and security fixes needs backport to 3.14 bugs and security fixes labels Jan 16, 2026
@sethmlarson sethmlarson requested a review from gpshead January 16, 2026 17:48
@bitdancer
Copy link
Member

Here I have a backward compatibility concern. While the RFC makes it clear that non-printables other than space are not acceptable in commands, I can imagine people using passwords with things like tab and backspace in them, and while that would violate the RFC, it would currently work, and this would break that.

What do you think?

Note that since this is the client side, this is not, IMO, a security issue, it's more of an RFC conformance issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting review needs backport to 3.10 only security fixes needs backport to 3.11 only security fixes needs backport to 3.12 only security fixes needs backport to 3.13 bugs and security fixes needs backport to 3.14 bugs and security fixes type-security A security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants