Important
The SingleStore 9.1 release candidate (RC) is available now. It will be promoted to general availability (GA) soon and at that time it will be renamed to SingleStore 10.
In the interim, SingleStore 9.1 RC can be used to preview, evaluate, and provide feedback on the new and upcoming features in SingleStore 10, while SingleStore 9.0 is recommended for production workloads.
SECRET
On this page
The SECRET() function provides the ability to hide credentials from queries.
Passing credentials in queries can leave them exposed in plain text during parameterization which means they can be seen in logs and the process list.SECRET() function.SECRET() takes a string (such as a password or other sensitive information) and replaces it with the literal string "<password>" during parameterization.
Syntax
SECRET(str)
Arguments
-
str: any string
Return Type
String
Remarks
-
There are two cases where the string passed in the
SECRET()function could still be exposed:-
When
SECRET()is used as a column without an alias:SELECT SECRET(argument);Instead, use something like:
SELECT SECRET(argument) AS column_name; -
When the
NOPARAM()function is combined withSECRET():SECRET(NOPARAM(argument));
-
Example
CALL db.log_in_now('root', SECRET('super-secret-password'));
Related Topics
Last modified: