'az sql server create' mishandling password string #10370
Description
Activity
- changed the title
[-]'az sql server create' mishandling password[/-][+]'az sql server create' mishandling password string[/+]on Aug 29, 2019 - addedService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.SQLaz sqlaz sql
on Aug 30, 2019 Thank you for reporting this issue. It looks like this issue affects more than just SQL commands.
> az group create -n "a<b" -g "westus" The system cannot find the file specified.I'll include the CLI core team to help investigate deeper.
Jared Moore (@jaredmoo) are you want to run
az group create -n "a<b" -l "westus"not-g "westus"? If yes,az group createwill tell youParameter 'resource_group_name' must conform to the following pattern: '^[-\\w\\._\\(\\)]+$'.az grouphave validation for parameters. So I think this may be just related to SQL not core.In that case it might just be PowerShell interpreting as I/O redirection. Either way, if I can repro it with another arbitrary command then the issue is not isolated to SQL commands.
Jan Kašpar (@hKaspy) When I want to reproduce your issue, it looks "<" works but ")" cannot be parsed correctly in PS. Can you verify it?
I really agree with what Jared Moore (@jaredmoo) said, it is more related to PS and there is a little we can do. But I will add these specific letters scenario in CLI document here to make users know these cases and use cli more effectively.Zunli Hu (@Juliehzl) Tested again after update to azure-cli 2.0.73, issue still valid with
a)b, buta<bresolved.Windows-10-10.0.17134-SP0 Python 3.6.6 Shell: powershell.exe azure-cli 2.0.73 *I disagree with you and Jared Moore (@jaredmoo), as this hints at bad string handling inside the script, since this happens no mather what string quotation technique I use. Per powershell documentation (5.1 in my case):
When you enclose a string in single-quotation marks (a single-quoted string), the string is passed to the command exactly as you type it. No substitution is performed.
Moreover,
mkdir "a)b"is completely valid and creates a folder nameda)bandmkdir "a>b"fails withmkdir : Illegal characters in path..This wouldn't be such a problem for me if it was not a password argument failing. It should accept any printable character. Invalidating
<,)and possibly other characters weakens password security.The issue is also in that Web GUI version accepts those characters, so (as happened to me) someone could create the DB password in GUI and then I am unable to replicate this in automated CI/CD script.
Tested now with Azure Key Vault, so we can rule out the SQL:
az keyvault secret set --vault-name test-kv --name "test" --value "a)b" b was unexpected at this time. C:\> "C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\wbin\\..\python.exe" -IBm azure.cli keyvault secret set --vault-name ice-sam-test-kv --name test --value a)bFrom this debug line i would guess that the problem is with azure.cli script invocation as the argument gets passed (or at least is printed that way in debug) as
--value a)b, stripped of quotation marks.4 remaining items
- addedService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.SQLaz sqlaz sql
on Oct 25, 2019 Zunli Hu (@Juliehzl) please create a PS ticket and put it here, then we can close this issue.
Same issue for
az postgres server create<and)in pasword arg crashed prosess
powershell 5, az cli 2.0.76Same issue for
az postgres server create<and)in pasword arg crashed prosess
powershell 5, az cli 2.0.76Hi ArgTang, it is a powershell issue. Could you use cmd to unblock yourself? Out of curiosity,
)doesn't work for you, right? Could you share more info about)scenario with me? It works for me as follows again.

As Zunli Hu (@Juliehzl) stated, this is a Windows PowerShell issue. We have updated CLI doc for explanation and workaround: https://github.com/Azure/azure-cli/blob/dev/doc/use_cli_effectively.md#argument-parsing-issue-in-powershell
jeroenterheerdt commented
on Dec 6, 2019 More actionsArgTang please let us know if you need more help - otherwise we will proceed to close this issue.
Jeroen ter Heerdt (@jeroenterheerdt) no, i think we have a workaround. thanks
Reacted by Jeroen ter Heerdtjeroenterheerdt commented
on Dec 6, 2019 More actionsJiashuo Li (@jiasli) please go ahead and close this.
Describe the bug
az sql server create --admin-passwordargument tries to interpret the password and fails on less-than sign.I've tried single quotes, double quotes, putting in equal sign, variable... No Luck so far.
Errors:
To Reproduce:
az sql server create --admin-user "admin" --admin-password "a<b"Expected Behavior
Fails with
az sql server create: error: the following arguments are required: --resource-group/-g, --name/-nEnvironment Summary
Additional Context
Right-sided parenthesis also breaks this in different way: