From 2af3ee0742e41614a9d0d0b779ed90604fbee135 Mon Sep 17 00:00:00 2001 From: Robin Appelman Date: Mon, 14 Sep 2026 23:11:19 +0200 Subject: [PATCH] add support for pgsql_ssl fixes #2 --- src/nc.rs | 18 ++++++++++++- tests/configs.rs | 46 ++++++++++++++++++++++++++++++++-- tests/configs/postgres_ssl.php | 21 ++++++++++++++++ 3 files changed, 82 insertions(+), 3 deletions(-) create mode 100644 tests/configs/postgres_ssl.php diff --git a/src/nc.rs b/src/nc.rs index e2a88e3..7249179 100644 --- a/src/nc.rs +++ b/src/nc.rs @@ -266,7 +266,23 @@ fn parse_db_options(parsed: &Value) -> Result { *connect_port = port; } } - if disable_ssl { + if let Some(ssl_options) = parsed["pgsql_ssl"].clone().into_map() { + if let Some(mode) = ssl_options["mode"].as_str() { + options.insert("sslmode".into(), mode.into()); + } + if let Some(mode) = ssl_options["cert"].as_str() { + options.insert("sslcert".into(), mode.into()); + } + if let Some(mode) = ssl_options["rootcert"].as_str() { + options.insert("sslrootcert".into(), mode.into()); + } + if let Some(mode) = ssl_options["key"].as_str() { + options.insert("sslkey".into(), mode.into()); + } + if let Some(mode) = ssl_options["crl"].as_str() { + options.insert("sslcrl".into(), mode.into()); + } + } else if disable_ssl { options.insert("sslmode".into(), "disable".into()); } diff --git a/tests/configs.rs b/tests/configs.rs index 04ea2c8..062b81b 100644 --- a/tests/configs.rs +++ b/tests/configs.rs @@ -2,6 +2,7 @@ use nextcloud_config_parser::{ parse, parse_glob, Config, Database, DbConnect, RedisClusterConnectionInfo, RedisConfig, RedisConnectionAddr, RedisConnectionInfo, RedisTlsParams, SslOptions, }; +use sqlx::postgres::PgSslMode; use std::fmt::Debug; use indexmap::{indexmap, IndexMap}; @@ -394,6 +395,47 @@ fn test_parse_postgres_socket_folder() { ); } +#[test] +fn test_parse_postgres_ssl() { + let config = config_from_file("tests/configs/postgres_ssl.php"); + assert_debug_equal( + &Database::Postgres { + database: "nextcloud".to_string(), + username: "redacted".to_string(), + password: "".to_string(), + connect: DbConnect::Tcp { + host: "1.2.3.4".into(), + port: 5432, + }, + options: indexmap! { + "sslmode".into() => "require".into(), + "sslcert".into() => "/cert.crt".into(), + "sslrootcert".into() => "/root.crt".into(), + "sslkey".into() => "/key.pem".into(), + "sslcrl".into() => "/root.crl".into(), + }, + }, + &config.database, + ); + + assert_eq!( + config.database.url(), + "postgresql://redacted:@1.2.3.4/nextcloud?sslmode=require&sslcert=/cert.crt&sslrootcert=/root.crt&sslkey=/key.pem&sslcrl=/root.crl" + ); + assert_debug_equal( + PgConnectOptions::new() + .host("1.2.3.4") + .port(5432) + .username("redacted") + .database("nextcloud") + .ssl_mode(PgSslMode::Require) + .ssl_client_cert("/cert.crt") + .ssl_root_cert("/root.crt") + .ssl_client_key("/key.pem"), + PgConnectOptions::from_str(&config.database.url()).unwrap(), + ); +} + #[test] fn test_parse_redis_cluster() { let config = config_from_file("tests/configs/redis.cluster.php"); @@ -644,7 +686,7 @@ fn test_parse_postgres_ip() { .password("redacted") .database("nextcloud") .port(5432) - .ssl_mode(sqlx::postgres::PgSslMode::Disable), + .ssl_mode(PgSslMode::Disable), PgConnectOptions::from_str(&config.database.url()).unwrap(), ); } @@ -747,7 +789,7 @@ fn test_parse_postgres_escaped_credentials() { .password("reda@cted") .port(5432) .database("nextcloud") - .ssl_mode(sqlx::postgres::PgSslMode::Disable), + .ssl_mode(PgSslMode::Disable), PgConnectOptions::from_str(&config.database.url()).unwrap(), ); } diff --git a/tests/configs/postgres_ssl.php b/tests/configs/postgres_ssl.php new file mode 100644 index 0000000..ba05c01 --- /dev/null +++ b/tests/configs/postgres_ssl.php @@ -0,0 +1,21 @@ + 'https://cloud.example.com', + 'dbtype' => 'pgsql', + 'dbname' => 'nextcloud', + 'dbhost' => '1.2.3.4', + 'dbport' => '', + 'dbtableprefix' => 'oc_', + 'dbuser' => 'redacted', + 'pgsql_ssl' => [ + 'mode' => 'require', + 'cert' => '/cert.crt', + 'rootcert' => '/root.crt', + 'key' => '/key.pem', + 'crl' => '/root.crl', + ], + 'redis' => [ + 'host' => 'localhost' + ] +];