Description
The validate_connection_config function in backend/src/postgis.rs explicitly rejects any SSL mode other than "disable":
if ssl_mode != "disable" {
return Err("Only sslMode=disable is supported in current MVP".to_string());
}
This means all PostGIS database connections — including username/password authentication — occur over unencrypted TCP connections using tokio_postgres::NoTls.
Risk
For production deployments connecting to remote PostGIS servers:
- Database credentials (username + password) are transmitted in cleartext
- Vulnerable to network sniffing, MITM attacks, and credential theft
- Any attacker on the network path between MapFlow and PostGIS can capture credentials
Affected Code
backend/src/postgis.rs line ~715: validate_connection_config rejects non-disable SSL modes
backend/src/postgis.rs connect_postgis_client_from_connection: uses NoTls hardcoded
Recommendation
- Add support for
ssl_mode = "require" and ssl_mode = "verify-full" using tokio_postgres::rustls or tokio_postgres::native-tls
- Update
connect_postgis_client_from_connection to use TLS when ssl_mode is not "disable"
- For MVP: at minimum, document that PostGIS connections should only be used with localhost or trusted networks
- Long-term: deprecate
ssl_mode = "disable" for remote connections
Severity
Medium-High — Credential exposure over network
Description
The
validate_connection_configfunction inbackend/src/postgis.rsexplicitly rejects any SSL mode other than"disable":This means all PostGIS database connections — including username/password authentication — occur over unencrypted TCP connections using
tokio_postgres::NoTls.Risk
For production deployments connecting to remote PostGIS servers:
Affected Code
backend/src/postgis.rsline ~715:validate_connection_configrejects non-disable SSL modesbackend/src/postgis.rsconnect_postgis_client_from_connection: usesNoTlshardcodedRecommendation
ssl_mode = "require"andssl_mode = "verify-full"usingtokio_postgres::rustlsortokio_postgres::native-tlsconnect_postgis_client_from_connectionto use TLS when ssl_mode is not "disable"ssl_mode = "disable"for remote connectionsSeverity
Medium-High — Credential exposure over network