Repository navigation
MotherDuck plugin for DuckDB - #511
Conversation
|
Hi folks! If there's any more information you need from me, please let me know. Thanks! |
|
Hi! Just checking in on this again. Thanks! |
|
Is it fair to assume that the shell extensions project is dead? |
edif2008
left a comment
There was a problem hiding this comment.
Thank you for your contribution! 😄
I've left a couple of improvements that I've seen by trying out MotherDuck myself.
|
@edif2008 Thanks for the review, and sorry for the delayed response! I'll address your comments soon. |
|
If you're new to commit signing, there are different ways to set it up: Sign commits with
|
- length is not fixed so remove - token can include . and _
…duck. Defer to environment variable or provided token value if either is set.
4620375 to
14818e7
Compare
|
@edif2008 This should be ready for another look. Thanks! |
|
@edif2008 One design choice I'm not sure how to address that I'd love advice on. As it is now, if the user has set Ideally this would be something you could configure when you initialize the plugin, but I'm not sure if there's a good way to do that, but I'm not sure if that's supported. Other than that I think this is ready to go. Let me know if there's anything else I should address. Thanks! |
|
I've been using this locally now and it's been pretty convenient. I'd love to get it officially supported so I could promote it to people. Thanks! |
|
Hi! Just checking in again to see if we can get this merged. 😄 |
|
Checking in again, thanks! |
|
@edif2008 Let me know if there's anything I can do that would make it easy to get this merged. Thanks! |
SimonBarendse
left a comment
There was a problem hiding this comment.
Thank you for your contribution! 🙌
|
Thanks @SimonBarendse! I'm really excited to see movement on this! |
Replace space indentation with tabs in ForMotherDuckButTokenNotSet so golangci-lint's gofmt check passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The provisioner and importer use the lowercase motherduck_token env var, which the MotherDuck extension gives precedence over MOTHERDUCK_TOKEN. Align the test expectations with that and drop leftover TODO comments.
Add NeedsAuth cases for local databases, MotherDuck connection strings, ATTACH from a command, and a token supplied via the connection string or the motherduck_token env var. Token env vars are cleared so a developer's own shell doesn't affect the results. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The MotherDuck extension reads its token from either motherduck_token or MOTHERDUCK_TOKEN. The plugin only deferred to motherduck_token, so with just MOTHERDUCK_TOKEN set it still prompted and injected motherduck_token, which takes precedence and silently replaced the user's token. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ixes
DuckDB connects to MotherDuck for 'motherduck:' as well as 'md:', and
matches the prefix case-insensitively ('MD:' works too). Those connections
previously skipped the plugin and fell back to MotherDuck's browser login.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A plain substring match on "md:" also fired on text like 'cmd:' inside a query passed with -c, prompting for a token DuckDB wouldn't use. Require the prefix to not follow a word character. Also drop the empty-args check, which the loop already covers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ken= DuckDB accepts 'token=' as an alias for 'motherduck_token=' in a MotherDuck connection string, and that token wins over any env var. Skip the plugin for either parameter so users aren't prompted for a token that won't be used. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The importer only looked at motherduck_token, so a token exported as MOTHERDUCK_TOKEN, which the MotherDuck extension also reads, wasn't offered during op plugin init. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks so much for the contribution, @sterlinm, and for sticking with this PR for so long! 🦆 I merged in the latest main and pushed some fixes so CI passes:
I'm merging this now, and the plugin will be available in the next 1Password CLI release. Thanks again! |
Overview
Creating a plugin for the DuckDB CLI to allow you to securely store your MotherDuck token using 1password.
Type of change
Related Issue(s)
How To Test
The plugin is used when the
duckdbCLI is called and the user attempts to connect to MotherDuck without providing a token via environment variable or as part of the connection string.This would require authentication with 1password:
duckdb 'md:'.From the DuckDB CLI interface, if you run
PRAGMA PRINT_MD_TOKEN;it should print out the token that you have stored in 1password.These would not require authentication with 1password:
duckdbduckdb localdb.ddbduckdb 'md:my_db?motherduck_token=<motherduck_token>motherduck_token=<motherduck_token> duckdb 'md:'You can test that it uses the token from the connection string or environment variable (rather than 1password) by running the following commands:
duckdb 'md:my_db?motherduck_token=<motherduck_token> -c 'PRAGMA print_md_token'motherduck_token=<motherduck_token> duckdb 'md:' -c 'PRAGMA print_md_token'The token that is printed out should match the provided token rather than the one saved in 1password.
Changelog