authenticator: do not send credentials configured for https with http - #11073
Merged
Merged
Conversation
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="src/poetry/utils/authenticator.py" line_range="447-449" />
<code_context>
candidates = []
for repository in self.configured_repositories.values():
+ if repository.scheme == "https" and parsed_url.scheme != "https":
+ # never send credentials configured for https in the clear
+ continue
+
if exact_match:
</code_context>
<issue_to_address>
**🚨 issue (security):** When an HTTPS repository has credentials stored in the keyring under its URL or netloc, an HTTP request skips that repository and then falls through to the generic keyring lookup in `_get_credentials_for_url`, which retrieves and sends the same credentials over HTTP.
**Triggers:** When keyring credentials are stored under the repository URL or host rather than only under the repository name.
**Suggested fix:** If a non-HTTPS request shares a netloc with a configured HTTPS repository and no eligible HTTP repository matches, return empty credentials instead of performing the generic URL/netloc keyring fallback.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and this changes the credential transport trust boundary: HTTPS-configured credentials are withheld whenever the request uses HTTP. If that policy is wrong, the behavior applies immediately to all matching repositories and can cause authentication failures until reverted, while any credentials exposed before a correction cannot be recovered by the revert.
Blocking findings: src/poetry/utils/authenticator.py:449
mwalbeck
pushed a commit
to mwalbeck/docker-python-poetry
that referenced
this pull request
Sep 26, 2026
This PR contains the following updates: | Package | Update | Change | Pending | |---|---|---|---| | [poetry](https://github.com/python-poetry/poetry) ([changelog](https://python-poetry.org/history/)) | minor | `2.4.3` → `2.5.0` | `2.5.1` | --- ### Release Notes <details> <summary>python-poetry/poetry (poetry)</summary> ### [`v2.5.0`](https://github.com/python-poetry/poetry/blob/HEAD/CHANGELOG.md#250---2026-09-19) [Compare Source](python-poetry/poetry@2.4.3...2.5.0) ##### Added - Add an `installer.builtin-uninstall` setting to uninstall packages with a built-in uninstaller instead of invoking `pip uninstall` ([#​10931](python-poetry/poetry#10931)). - Add official support for Python 3.15 ([#​11046](python-poetry/poetry#11046)). ##### Changed - Do not send credentials configured for an `https` repository via `http` ([#​11073](python-poetry/poetry#11073)). - Fail with an error when the current Python version is not compatible with the project and `virtualenvs.create` is `false` ([#​10941](python-poetry/poetry#10941)). - Validate version constraints that are entered interactively in `poetry init` ([#​10909](python-poetry/poetry#10909)). - Include the path of the `pyproject.toml` file in the message about already present packages in `poetry add` ([#​10908](python-poetry/poetry#10908)). - Improve performance of processing package links and repository pages ([#​10895](python-poetry/poetry#10895), [#​10896](python-poetry/poetry#10896), [#​10903](python-poetry/poetry#10903), [#​10949](python-poetry/poetry#10949), [#​10951](python-poetry/poetry#10951), [#​10953](python-poetry/poetry#10953)). - Improve performance of dependency resolution ([#​10907](python-poetry/poetry#10907), [#​10954](python-poetry/poetry#10954)). - Improve performance of choosing and installing wheels ([#​10905](python-poetry/poetry#10905), [#​10958](python-poetry/poetry#10958)). - Improve performance by avoiding redundant keyring lookups for repositories without credentials ([#​10959](python-poetry/poetry#10959)). - Improve performance by reducing the number of subprocesses to discover virtual environment data ([#​11042](python-poetry/poetry#11042)). - Improve performance of `poetry search` for single-token queries ([#​10906](python-poetry/poetry#10906)). - Improve startup time by deferring the import of `requests` ([#​11004](python-poetry/poetry#11004)). - Improve performance of schema validation by caching compiled JSON schema validators ([#​11033](python-poetry/poetry#11033)). ##### Fixed - Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host ([#​11072](python-poetry/poetry#11072)). - Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same ([#​11074](python-poetry/poetry#11074)). - Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers ([#​10944](python-poetry/poetry#10944)). - Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups ([#​10943](python-poetry/poetry#10943)). - Fix an issue where dependency resolution failed with a `KeyError` ([#​11008](python-poetry/poetry#11008)). - Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the `pyproject.toml` file ([#​10987](python-poetry/poetry#10987)). - Fix an issue where a path or git dependency was not reinstalled when its `develop` setting changed ([#​11022](python-poetry/poetry#11022)). - Fix an issue where scripts of type `file` were not installed when installing the project ([#​10736](python-poetry/poetry#10736)). - Fix an issue where GUI scripts were not installed when installing the project ([#​10973](python-poetry/poetry#10973)). - Fix an issue where a relative path was written to `direct_url.json` for path dependencies ([#​10917](python-poetry/poetry#10917)). - Fix an issue where `poetry show <package>` showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file ([#​11003](python-poetry/poetry#11003)). - Fix an issue where `poetry show --outdated` did not find newer versions of packages from sources with `explicit` priority ([#​10982](python-poetry/poetry#10982)). - Fix an issue where `poetry env activate` ignored the environment that was determined by the application, e.g. when using `--directory` ([#​10916](python-poetry/poetry#10916)). - Fix an issue where `poetry init` proposed an invalid package name if the directory name was not a valid package name ([#​10975](python-poetry/poetry#10975)). ##### Docs - Document the `--license` option of `poetry init` and `poetry new` ([#​11064](python-poetry/poetry#11064)). - Clarify which dependencies are locked when running `poetry update` with dependency groups ([#​11024](python-poetry/poetry#11024)). - Clarify the portability of path dependencies ([#​11020](python-poetry/poetry#11020)). - Clarify the usage of `poetry run` with console scripts ([#​10984](python-poetry/poetry#10984)). - Clarify what `--no-cache` disables ([#​10915](python-poetry/poetry#10915)). - Document how to use package sources for `poetry self update` ([#​10923](python-poetry/poetry#10923)). - Fix the stale minimum Python version ([#​11050](python-poetry/poetry#11050)). - Update outdated links ([#​10913](python-poetry/poetry#10913), [#​10938](python-poetry/poetry#10938), [#​11000](python-poetry/poetry#11000), [#​11043](python-poetry/poetry#11043)). ##### poetry-core ([`2.5.0`](https://github.com/python-poetry/poetry-core/releases/tag/2.5.0)) - Add Python 3.15 to the automatically generated classifiers ([#​961](python-poetry/poetry-core#961)). - Fix an issue where a `<V` version constraint wrongly allowed pre-releases of `V` in some cases ([#​939](python-poetry/poetry-core#939)). - Fix an issue where version ranges with coincident bounds were not recognized as empty ([#​939](python-poetry/poetry-core#939)). - Fix an issue where the string representation of a version union did not describe the same constraint after being parsed again ([#​939](python-poetry/poetry-core#939)). - Fix an issue where the intersection of a version range with a local version resulted in a wrong constraint ([#​949](python-poetry/poetry-core#949)). - Fix an issue where the union of a version range and a public version did not include all local versions of the public version ([#​950](python-poetry/poetry-core#950)). - Fix an issue where the union of a public version and one of its local versions did not result in the public version ([#​966](python-poetry/poetry-core#966)). - Fix an issue where the difference between a public version and one of its local versions still allowed the local version, which could result in an infinite loop during dependency resolution ([#​953](python-poetry/poetry-core#953)). - Fix an issue where a version range that excluded some local versions of a public version was wrongly considered to allow all versions of the public version ([#​959](python-poetry/poetry-core#959)). - Fix an issue where a `!= <value>` constraint was wrongly considered to allow all values of a `<value> not in` constraint ([#​955](python-poetry/poetry-core#955)). - Fix an issue where merging `platform_release` markers with incompatible constraint types failed ([#​956](python-poetry/poetry-core#956)). - Fix an issue where the string representation of a version range whose upper bound only consists of zeros raised an `IndexError` ([#​964](python-poetry/poetry-core#964)). - Fix an issue where formatting a Python constraint that only allows unknown Python versions raised an `IndexError` ([#​971](python-poetry/poetry-core#971)). - Fix an issue where marker values containing spaces could not be parsed ([#​972](python-poetry/poetry-core#972)). - Fix an issue where the upper bound of a `~=` constraint was wrong for versions with more than three release segments ([#​973](python-poetry/poetry-core#973)). - Fix an issue where the filename of a link created from a Windows path was wrong and reject filenames containing path separators ([#​974](python-poetry/poetry-core#974)). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI2MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Reviewed-on: https://git.walbeck.it/mwalbeck/docker-python-poetry/pulls/1762
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Check List