Skip to content

fix(server): avoid plaintext fallback for Postgres SQL errors - #332

Open
tahodev wants to merge 2 commits into
wordbricks:mainfrom
tahodev:fix/postgres-no-plaintext-retry-on-sql-errors
Open

tahodev wants to merge 2 commits into
wordbricks:mainfrom
tahodev:fix/postgres-no-plaintext-retry-on-sql-errors

Conversation

@tahodev

@tahodev tahodev commented Sep 25, 2026

Copy link
Copy Markdown

What

Stop sslmode=prefer from retrying over plaintext when PostgreSQL has already returned a five-character SQLSTATE error. Add a regression test that verifies only the TLS attempt runs for a syntax error.

Why

A PostgreSQL SQLSTATE means the server received the connection and rejected the query. Changing transport cannot fix that failure. The old fallback sent the credentials and query again over plaintext, and could turn an error into a success if circumstances changed between attempts. TLS handshake and transport failures retain their existing fallback behavior.

Validation

  • bunx vitest run packages/server/src/services/data-source-query/execute-query.test.ts (17 passed)
  • bunx turbo typecheck --filter=@onequery/server --json (passed)
  • bunx oxfmt on changed files and git diff --check (passed)

Local oxlint panicked in its Rust allocator; CI should verify lint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant