Repository navigation
sql(postgres): honour PGSSLMODE=verify-ca/verify-full next to a TLS_* connection URL #44498
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1861,10 +1861,14 @@ function parseOptions( | |
| // The rest of this function is logic specific to postgres/mysql/mariadb (they have the same options object) | ||
|
|
||
| let sslMode: SSLMode = sslModeFromConnectionDetails || SSLMode.disable; | ||
| if (sslMode === SSLMode.disable) { | ||
| if (adapter === "postgres") { | ||
| // libpq honours PGSSLMODE as the default; a URL ?sslmode= below overrides it. | ||
| const envSslMode = adapter === "postgres" ? env.PG_SSLMODE || env.PGSSLMODE : undefined; | ||
| if (envSslMode) sslMode = normalizeSSLMode(envSslMode); | ||
| const envSslMode = env.PG_SSLMODE || env.PGSSLMODE; | ||
| if (envSslMode) { | ||
| // A TLS_* URL variable is a floor of `require`: PGSSLMODE raises the mode, it does not lower it. | ||
| const envMode = normalizeSSLMode(envSslMode); | ||
| if (envMode > sslMode) sslMode = envMode; | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 Apps passing Why this was flaggedEnvironment has TLS_DATABASE_URL (or TLS_POSTGRES_DATABASE_URL) set to a postgres URL and PGSSLMODE=verify-ca, and the program calls new SQL({ tls: { ca: bundle } }) or new SQL({ tls: { rejectUnauthorized: true } }). On the base branch shared.ts:1864 skipped the env read because sslMode was already require (2); then shared.ts:2158-2161 saw Verification: After the change shared.ts:1864-1870 reads the env and sets sslMode=3; the promotion at shared.ts:2158-2161 is now skipped by the
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The facts are right. In this one shape the resolved mode goes from 4 to 3 next to a
The suggested fix does not hold as written. A Two changes keep 4 in this shape. Each one is a decision for a maintainer:
I left this thread open for that decision. |
||
| } | ||
|
robobun marked this conversation as resolved.
|
||
| } | ||
|
|
||
| let url = _url; | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.