better handling of postgres options

This commit is contained in:
Robin Appelman 2026-03-02 22:14:44 +01:00
commit a8f4622c1a
5 changed files with 86 additions and 37 deletions

View file

@ -1,6 +1,7 @@
mod nc;
use form_urlencoded::Serializer;
use indexmap::IndexMap;
use itertools::Either;
use miette::Diagnostic;
use std::iter::once;
@ -192,7 +193,7 @@ pub enum NotAConfigError {
NotAnArray(PathBuf),
}
#[derive(Debug, Clone)]
#[derive(Debug, Clone, PartialEq)]
pub enum SslOptions {
Enabled {
key: String,
@ -204,7 +205,7 @@ pub enum SslOptions {
Default,
}
#[derive(Debug, Clone)]
#[derive(Debug, Clone, PartialEq)]
pub enum Database {
Sqlite {
database: PathBuf,
@ -221,11 +222,11 @@ pub enum Database {
username: String,
password: String,
connect: DbConnect,
ssl_options: SslOptions,
options: IndexMap<String, String>,
},
}
#[derive(Debug, Clone)]
#[derive(Debug, Clone, PartialEq)]
pub enum DbConnect {
Tcp { host: String, port: u16 },
Socket(PathBuf),
@ -300,21 +301,11 @@ impl Database {
username,
password,
connect,
ssl_options,
options,
} => {
let mut params = Serializer::new(String::new());
match ssl_options {
SslOptions::Default => {}
SslOptions::Disabled => {
params.append_pair("sslmode", "disable");
}
SslOptions::Enabled { ca, verify, .. } => {
params.append_pair(
"ssl-mode",
if *verify { "verify-full" } else { "verify-ca" },
);
params.append_pair("sslrootcert", ca.as_str());
}
for (key, value) in options {
params.append_pair(key.as_str(), value.as_str());
}
let (host, port) = match connect {
DbConnect::Socket(socket) => {

View file

@ -3,6 +3,7 @@ use crate::{
RedisClusterConnectionInfo, RedisConnectionInfo, RedisTlsParams, Result, SslOptions,
};
use crate::{RedisConfig, RedisConnectionAddr};
use indexmap::IndexMap;
use php_literal_parser::Value;
use std::collections::HashMap;
use std::fs::DirEntry;
@ -215,8 +216,10 @@ fn parse_db_options(parsed: &Value) -> Result<Database> {
Some("pgsql") => {
let username = parsed["dbuser"].as_str().ok_or(DbError::NoUsername)?;
let password = parsed["dbpassword"].as_str().unwrap_or_default();
let db_host = parsed["dbhost"].as_str().unwrap_or_default();
let mut host_parts = db_host.split(';');
let (mut connect, disable_ssl) =
match split_host(parsed["dbhost"].as_str().unwrap_or_default()) {
match split_host(host_parts.next().expect("empty split")) {
(addr, None, None) => (
DbConnect::Tcp {
host: addr.into(),
@ -248,6 +251,14 @@ fn parse_db_options(parsed: &Value) -> Result<Database> {
unreachable!()
}
};
let mut options = IndexMap::new();
for part in host_parts {
if let Some((key, value)) = part.split_once('=') {
options.insert(key.into(), value.into());
}
}
if let Some(port) = parsed["dbport"].clone().into_int() {
if let DbConnect::Tcp {
port: connect_port, ..
@ -256,20 +267,21 @@ fn parse_db_options(parsed: &Value) -> Result<Database> {
*connect_port = port as u16;
}
}
let database = parsed["dbname"].as_str().unwrap_or("owncloud");
if disable_ssl {
options.insert("sslmode".into(), "disable".into());
}
let ssl_options = if disable_ssl {
SslOptions::Disabled
} else {
SslOptions::Default
};
let database = parsed["dbname"]
.as_str()
.or_else(|| options.get("dbname").map(String::as_str))
.unwrap_or("owncloud");
Ok(Database::Postgres {
database: database.into(),
username: username.into(),
password: password.into(),
connect,
ssl_options,
options,
})
}
Some("sqlite3") | Some("sqlite") | None => {
@ -377,3 +389,36 @@ fn test_redis_empty_password_none() {
let redis = parse_redis_options(&config, "redis");
assert_eq!(redis.passwd(), None);
}
#[test]
fn test_postgres_options() {
use indexmap::indexmap;
let config =
php_literal_parser::from_str(r#"[
'dbtype' => 'pgsql',
'dbhost' => 'db.example.org;sslmode=verify-ca;sslrootcert=/etc/ssl/certs/ca-certificates.crt;dbname=nextcloud',
'dbuser' => 'nextcloud',
'dbpassword' => 'nextcloud',
]"#)
.unwrap();
let db = parse_db_options(&config).unwrap();
assert_eq!(
db,
Database::Postgres {
database: "nextcloud".to_string(),
username: "nextcloud".to_string(),
password: "nextcloud".to_string(),
connect: DbConnect::Tcp {
host: "db.example.org".into(),
port: 5432,
},
options: indexmap! {
"sslmode".into() => "verify-ca".into(),
"sslrootcert".into() => "/etc/ssl/certs/ca-certificates.crt".into(),
"dbname".into() => "nextcloud".into(),
},
}
);
assert_eq!(db.url(), "postgresql://nextcloud:nextcloud@db.example.org/nextcloud?sslmode=verify-ca&sslrootcert=/etc/ssl/certs/ca-certificates.crt&dbname=nextcloud");
}