fix: disable PostgreSQL TLS for refusing RDS endpoint

This commit is contained in:
brother7 committed 2026-08-16 23:26:03 +08:00
1 parent acf368b6fe
commit ed978142eb
17 files changed
+340 -180

No files matched your search

+28 -1
View File
@@ -1,5 +1,9 @@
import { readFile } from "node:fs/promises";
import { describe, expect, it } from "vitest";
import { describe, expect, it, vi } from "vitest";
vi.mock("server-only", () => ({}));
import { buildPlaintextPoolConfig } from "../lib/server/database";
describe("PostgreSQL readiness contract", () => {
it("checks every runtime table and both atomic functions", async () => {
@@ -22,4 +26,27 @@ describe("PostgreSQL readiness contract", () => {
expect(source).toContain("claim_generation_jobs(text,integer,integer)");
expect(source).toContain("billing_post_wallet_entry(text,text,text,text,text,bigint,text,text,text,jsonb)");
});
it("forces the legacy server adapter to use plaintext without reading a CA", async () => {
const source = await readFile(new URL("../lib/server/database.ts", import.meta.url), "utf8");
expect(source).not.toContain("readFileSync");
expect(source).not.toContain("rejectUnauthorized");
expect(source).not.toContain('|| "verify-full"');
expect(source).toContain('["sslmode", "sslrootcert"].includes(key.toLowerCase())');
expect(source).toContain('parsed.searchParams.set("sslmode", "disable")');
expect(source).toContain("ssl: false");
});
it("normalizes a legacy TLS URL into an executable plaintext pool config", () => {
const config = buildPlaintextPoolConfig(
"postgresql://app:secret@rds.example:5432/app?connect_timeout=5&sslmode=verify-full&sslrootcert=/missing/ca.pem"
);
expect(config.ssl).toBe(false);
expect(config.connectionString).toContain("sslmode=disable");
expect(config.connectionString).not.toContain("verify-full");
expect(config.connectionString).not.toContain("sslrootcert");
expect(config.connectionString).toContain("connect_timeout=5");
});
});
+7 -2
View File
@@ -12,14 +12,19 @@ describe("PostgreSQL script configuration", () => {
expect(getScriptDataBackend({ NODE_ENV: "test", ZHINIAN_DATA_BACKEND: "postgres" })).toBe("postgres");
});
it("accepts SSL settings in the single DATABASE_URL value", async () => {
it("forces plaintext even when DATABASE_URL requests verified TLS", async () => {
const pool = createPostgresPool({
env: {
NODE_ENV: "test",
ZHINIAN_DATA_BACKEND: "postgres",
DATABASE_URL: "postgresql://app:secret@rds.example:5432/app?sslmode=verify-full"
DATABASE_URL: "postgresql://app:secret@rds.example:5432/app?connect_timeout=5&sslmode=verify-full&sslrootcert=/missing/ca.pem"
}
});
expect(pool.options.ssl).toBe(false);
expect(pool.options.connectionString).toContain("sslmode=disable");
expect(pool.options.connectionString).not.toContain("sslrootcert");
expect(pool.options.connectionString).toContain("connect_timeout=5");
await pool.end();
});