dash-b · Features · Connect

One way in, whatever it is you are connecting.

A database you run, a file you drop, a small script on your own server. They are all entries in the same table, they are all registered the same way, and adding a new kind is an entry rather than a new screen.

What you can connect today

Two shapes, and a file

A database, directly

PostgreSQL, MySQL or MongoDB. Host, port, database, user, password, TLS on by default. Read-only — nothing dash-b does can write to your production data.

A connector on your own server

One PHP file you upload beside the database. dash-b gets an address and a signing secret, and nothing else: no host, no username, no password. It is the only source that can write, and that is exactly why.

A file

Drop a spreadsheet or a CSV on the board and it becomes a real table, with its columns read from the file rather than guessed at by you. No registration, no credentials, nothing to set up.

What happens to a password

A secret is never shown back to you

Once a credential is stored, the form that stores it cannot render it again. That is not a setting — it is a separate piece of code from the one that fills forms with saved values, kept separate on purpose, so that "show the stored value" is not one flag away from writing a database password into a page that can be screenshotted, screen-shared or read out of the DOM.

The connector exists so that the strongest secret you have never leaves your own server.

Your database credentials stay in a config file on the machine that already had them. dash-b holds an address and a signature, and neither one opens your database to anybody else.

Signing in to something else

Why there is no sign-in box here

Connecting an account — as opposed to a database — means a provider's own sign-in page, in a window of its own, and a broker that holds the application secret so that dash-b never does and never sees your password.

It is not done inside the page, and that is not a preference. Google and Facebook both refuse to be framed, deliberately: a sign-in form displayed inside somebody else's document is indistinguishable from a phishing page, and building one would ship a blank rectangle.

The catalogue is built for these and the mechanism is in place; the connections themselves are not open yet, so the designer will not offer you a button that fails after you have chosen it. When they open, they arrive as entries in the same table as everything above.

Two things pinned by test

The checks that are not allowed to regress

  • No secret is rendered back. A test puts a marker into every field of every provider and then searches the rendered page for it.
  • A sign-in answer is believed only when everything about it checks — where it came from, its shape, the one-time value it must carry, and its age — and all of that is verified before a single field of it is read. Exactly one sign-in is in flight at a time, so an old one cannot be answered by a later message.

Both exist because the failure they prevent is silent: the first would leak a password into a screenshot, and the second would let a link connect somebody else's account to yours.

Connected is only half of it.

A tile can read what you connect. With a connector, a tile can also write to it — a button on the board that adds a row to your own database.