Skip to content

security: PostGIS connections hardcoded to SSL mode 'disable' — credentials transmitted in cleartext #379

Description

@evan-zhang11

Description

The validate_connection_config function in backend/src/postgis.rs explicitly rejects any SSL mode other than "disable":

if ssl_mode != "disable" {
    return Err("Only sslMode=disable is supported in current MVP".to_string());
}

This means all PostGIS database connections — including username/password authentication — occur over unencrypted TCP connections using tokio_postgres::NoTls.

Risk

For production deployments connecting to remote PostGIS servers:

  • Database credentials (username + password) are transmitted in cleartext
  • Vulnerable to network sniffing, MITM attacks, and credential theft
  • Any attacker on the network path between MapFlow and PostGIS can capture credentials

Affected Code

  • backend/src/postgis.rs line ~715: validate_connection_config rejects non-disable SSL modes
  • backend/src/postgis.rs connect_postgis_client_from_connection: uses NoTls hardcoded

Recommendation

  1. Add support for ssl_mode = "require" and ssl_mode = "verify-full" using tokio_postgres::rustls or tokio_postgres::native-tls
  2. Update connect_postgis_client_from_connection to use TLS when ssl_mode is not "disable"
  3. For MVP: at minimum, document that PostGIS connections should only be used with localhost or trusted networks
  4. Long-term: deprecate ssl_mode = "disable" for remote connections

Severity

Medium-High — Credential exposure over network

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions