Repository navigation
Credential fall back #168
Description
Activity
@ingox , this kind of sounds like a bash scripting issue and not a cmk issue. Can you explain your setup a bit more?
It sounds like you should have two profiles in .cmk/config and call cmk with -p to execute the different commands.
@ingox I think this can be prevented if you can use different profiles with
set profile, ie, before setting apikey/secrekey, set a new profileLeave that bash thing out for now. Here are the steps:
- I have a single profile in my config file with username (admin) and password.
- Once I login to cmk (command: "cmk") I do a "list users" to check who I am. It is admin now.
- I logout again.
- Now I login again by using the APIkey and Secret of a specific user "cmk -s -k
- List users will show that I'm ACSUser now (example).
- Now I logout again and remove just one character from the key or secret (potential mistake).
- I would expect an error now. But there is no error. I'm logged in into cmk again.
- List users shows me that I'm admin.
That is quite risky from my point of view.
Thanks @ingox for the clarification. I understand your issue now. I'll check and update
Reacted by ingox- added a commit that references this issue
on Aug 7, 2025 @ingox @shwstppr @weizhouapache , if we start wit (just) -s and -k we cannot ignore the profile as we do not have the url (and maybe domain)?
So if we log in like this and the keys are wrong, we are still going to the url from a profile. Actually to the currently configured as default. A retry with name/password would make sense. In the PR @weizhouapache suggests to forget about the default profile if -s/-k are used. That would make sense, but the url is still needed so not entirely possible. What we could do is set a flag internally when -s/-k is used on the cli to not retry, or to not try anything but the keys.
thoughts?
@DaanHoogland I like the approach you're suggesting. Same behavior happen if you logged in to the console with right keys once but stored the wrong information into the config file. Means anytime the key and secret are used either from command line or config file it will happen in the same way.
Based on the discussion with @DaanHoogland and @ingox the behaviour can be tweaked to the following:
- When credentials are passed as command-line parameters, then only those credentials will be used for the API call, and there won't be any fallback.
- When credentials are set in the cmk shell or with
cmk setcommand and the API call with cmk is done without any credentials, then the current behaviour of falling back will remain as it is.
- added a commit that references this issue
on Aug 13, 2025 - added a commit that references this issue
on Aug 25, 2025 - moved this from Discuss to Done in Apache CloudStack BugFest - Issues
on Aug 25, 2025
I have the following use case:
Now I see a behavior which will cause issues: