fix: disable PostgreSQL TLS for refusing RDS endpoint

This commit is contained in:
2026-08-16 23:26:03 +08:00
parent acf368b6fe
commit ed978142eb
17 changed files with 340 additions and 180 deletions

View File

@@ -12,14 +12,19 @@ describe("PostgreSQL script configuration", () => {
expect(getScriptDataBackend({ NODE_ENV: "test", ZHINIAN_DATA_BACKEND: "postgres" })).toBe("postgres");
});
it("accepts SSL settings in the single DATABASE_URL value", async () => {
it("forces plaintext even when DATABASE_URL requests verified TLS", async () => {
const pool = createPostgresPool({
env: {
NODE_ENV: "test",
ZHINIAN_DATA_BACKEND: "postgres",
DATABASE_URL: "postgresql://app:secret@rds.example:5432/app?sslmode=verify-full"
DATABASE_URL: "postgresql://app:secret@rds.example:5432/app?connect_timeout=5&sslmode=verify-full&sslrootcert=/missing/ca.pem"
}
});
expect(pool.options.ssl).toBe(false);
expect(pool.options.connectionString).toContain("sslmode=disable");
expect(pool.options.connectionString).not.toContain("sslrootcert");
expect(pool.options.connectionString).toContain("connect_timeout=5");
await pool.end();
});