redact-secret · Report
Connection-string password
Password embedded in a URI's userinfo component per RFC 3986.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-20Documentation for the one property varied in legacy twin fixtures (RFC 3986 userinfo): userinfo is delimited from the host by "@" and the deprecated user:password form places the password after the first ":". The password value has no grammar, so twins mutate the context, not the value
- www.rfc-editor.org/rfc/rfc3986provider-documentation · last read 2026-10-03 · latest outcome read · supports userinfo is delimited from the host by "@" and the deprecated user:password form places the password after the first ":". The password value has no grammar, so twins mutate the context, not the value · #section-3.2.1
Unresolved ·
listed-references· current · observed 2026-09-20The legacy contract lists 1 reference without stating which property each supports.
- www.rfc-editor.org/rfc/rfc3986provider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract · #section-3.2.1
Project policy ·
legacy-contract-tier· current · observed 2026-09-20The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.
Source not recorded.
Project policy ·
dossier-research· current · observed 2026-09-26Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/651/README.mdproject-research-note · last read 2026-09-26 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- www.rfc-editor.org/rfc/rfc3986provider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- RFC 3986 §3.2.1 userinfo: the password sits after the first
:and before@. No RFC or vendor states a length or identifying element; §7.5 deprecates passwords in URIs. Vendors disagree on which characters need percent-encoding (MongoDB requires$encoded, MySQL Connector/J requires( ) & =, RabbitMQ forbids a raw:). - Basis
- RFC 3986, RFC 1738, RabbitMQ URI spec, MongoDB and PostgreSQL docs: delimiter and alphabet only. The #651 hunt found no provider or RFC identifying element (2026-09-23); the boundary is project policy (T3, decision
2026-09-26-qualify-bounded-t3-credential-policy, benchmarks#365, core #857), so the verdict isreadyat T3, consistent with bearer and OTP seed. - Issuance
- not applicable.
- Contract in core
- detector-families.md; #651 record. Password surfaces outside userinfo (
password=parameters, Azure StorageAccountKey=) fall outside the family definition.
In this benchmark
- Fixtures
- 104
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
104 fixtures: 4 expect a redaction, 59 must stay quiet, 41 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 26 | 0 | 0 | 0 |
| T3Project policy | 78 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 104 | 6 | 9 | 18 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 104 | 43 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 104 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled4 rules target it | 104 | 23 | 6 | 12 |
Looks like it, but isn't
- Collisions
- providers that issue passwords with a fixed prefix (PlanetScale
pscale_pw_, Neonnpg_, Aiven and DigitalOceanAVNS_) are separate families.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | url_credentials | scheme:// user:password@ URL |
| openredaction · rules 1.1.5 | DATABASE_CONNECTION | postgres, mysql, mongodb, redis or sqlite URI with a password |
| openredaction · rules 1.1.5 | URL_WITH_AUTH | http(s) or ftp URL with user:password@ |
| trufflehog · rules 3.97.4 | mongodb | mongodb:// or mongodb+srv:// URI with a password |
| trufflehog · rules 3.97.4 | postgres | postgres:// or postgresql:// URI with a password |
| trufflehog · rules 3.97.4 | redis | redis:// URI with a password |
| trufflehog · rules 3.97.4 | uri | http(s) URL with a userinfo password |
No rule maps to this family in gitleaks.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
go-sum-excerpt-with-goproxy-passworddeveloper-artifact-lookalikes-authored · package-integrity-hashes-beside-a-literal-registry-password | Must redactT1 · Provider-documented | Redacted |
pip-requirements-hashes-with-index-url-passworddeveloper-artifact-lookalikes-authored · package-integrity-hashes-beside-a-literal-registry-password | Must redactT1 · Provider-documented | Redacted |
connection-string-celery-amqpsgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-database-url-querygeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-docs-uppercase-placeholdergeneric · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
connection-string-interpolated-password-referencegeneric · templated-reference | Must not flagT3 · Project policy | Quiet |
connection-string-jdbc-user-param-public-idgeneric · public-identifier | Must not flagT1 · Provider-documented | Quiet |
connection-string-mariadb-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mariadb-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mariadb-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mongodb-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mongodb-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mongodb-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mysql-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mysql-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-mysql-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-orm-connection-errorgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-percent-template-encoded-valuegeneric · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
connection-string-postgres-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-postgres-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-postgres-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-postgres-userinfogeneric · password-inside-connection-strings | Project policyT3 · Project policy | Redacted |
connection-string-psql-historygeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-rails-database-ymlgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-redis-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-redis-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-redis-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
connection-string-rediss-password-onlygeneric · password-inside-connection-strings | Project policyT3 · Project policy | Redacted |
connection-string-referencegeneric · variable-reference-in-credential-position | Must not flagT3 · Project policy | Quiet |
connection-string-sqlalchemy-ipv6generic · documented-format-literal | Project policyT3 · Project policy | Redacted |
embedded-wordgeneric · connection-uri-placeholder-lookalike-passwords | Project policyT3 · Project policy | Redacted |
filler-near-missgeneric · connection-uri-placeholder-lookalike-passwords | Project policyT3 · Project policy | Redacted |
mariadb-defaultgeneric · tutorial-default-url-passwords | Must not flagT3 · Project policy | Quiet |
mariadb-literalgeneric · literal-url-passwords | Project policyT3 · Project policy | Redacted |
mongodb-defaultgeneric · tutorial-default-url-passwords | Must not flagT3 · Project policy | Quiet |
mongodb-literalgeneric · literal-url-passwords | Project policyT3 · Project policy | Redacted |
mysql-defaultgeneric · tutorial-default-url-passwords | Must not flagT3 · Project policy | Quiet |
mysql-literalgeneric · literal-url-passwords | Project policyT3 · Project policy | Redacted |
placeholder-1generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-2generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-3generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-4generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-5generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-6generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
placeholder-7generic · connection-uri-placeholder-passwords | Must not flagT3 · Project policy | Quiet |
postgres-defaultgeneric · tutorial-default-url-passwords | Must not flagT3 · Project policy | Quiet |
postgres-literalgeneric · literal-url-passwords | Project policyT3 · Project policy | Redacted |
redis-defaultgeneric · tutorial-default-url-passwords | Must not flagT3 · Project policy | Quiet |
redis-literalgeneric · literal-url-passwords | Project policyT3 · Project policy | Redacted |
unrelated-suffixgeneric · connection-uri-placeholder-lookalike-passwords | Project policyT3 · Project policy | Redacted |
Sources
Documentation and code
- www.rfc-editor.org/rfc/rfc3986
Research log
- redact-secret/redact-secret#651Research issue
- redact-secret/redact-secret#857Research issue
- redact-secret/redact-secret-benchmarks#365Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/651/README.md