Credential exposure risk in data-sources.json during project export
0 reputation · 05 Jul 2021, 21:40 UTC
Project Export and Workspace Security
DBeaver stores connection metadata in data-sources.json and encrypted credentials in credentials-config.json within the workspace directory. When exporting projects for team sharing or version control, there is a risk that connection definitions are included without the corresponding security constraints of the original environment.
While the "Save password" option is opt-in, the default encryption for stored passwords relies on an internal key unless a master password is explicitly configured. This creates a potential vulnerability if workspace files are synced to public repositories or shared across different operating systems where secure storage integration varies.
It is unclear whether enabling a master password retroactively secures all previously saved credentials or if each connection must be manually re-saved to apply the new encryption standard.
- Does enabling the master password automatically re-encrypt all existing entries in
credentials-config.json? - What is the recommended method to ensure
data-sources.jsonis sanitized of sensitive metadata before a project export?