Add support for --env-mysql-* flags for secure credential passing#284
Open
TheVaibhaw wants to merge 1 commit into
Open
Add support for --env-mysql-* flags for secure credential passing#284TheVaibhaw wants to merge 1 commit into
TheVaibhaw wants to merge 1 commit into
Conversation
Implements feature requested in issue WordPress#24: - Add --env-mysql-password=VAR_NAME support - Add --env-mysql-user=VAR_NAME support - Add --env-mysql-host=VAR_NAME support - Add --env-mysql-database=VAR_NAME support These flags allow credentials to be sourced from environment variables specified by the user, avoiding password visibility in 'ps aux' output. Maintains backward compatibility with existing --mysql-* flags. Falls back to hardcoded MYSQL_PASSWORD env var if no flag specified. Changes: - Add CLI option definitions for all 4 new flags - Update credential parsing logic to check env flags first - Only persist non-password credentials in state Fixes WordPress#24
adamziel
reviewed
Jul 7, 2026
| if (isset($options["env_mysql_host"])) { | ||
| $env_var_name = $options["env_mysql_host"]; | ||
| $this->mysql_host = getenv($env_var_name) ?: ''; | ||
| if (!empty($this->mysql_host)) { |
Collaborator
There was a problem hiding this comment.
I'd remove this check. If we're telling the tool to use a specific ENV, let it use specific ENV. We're not checking for non-empty values in other branches. Other than that, this PR looks good!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements feature requested in issue #24:
These flags allow credentials to be sourced from environment variables specified by the user, avoiding password visibility in 'ps aux' output.
Maintains backward compatibility with existing --mysql-* flags. Falls back to hardcoded MYSQL_PASSWORD env var if no flag specified.
Changes:
Fixes #24