fix(workspaces): align postgres connection diagnostics
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { readFile } from "node:fs/promises";
|
||||
import { Client } from "pg";
|
||||
import { Client, type ClientConfig } from "pg";
|
||||
import { MAX_WORKSPACE_DIAGNOSTIC_TIMEOUT_MS } from "../config.js";
|
||||
import { buildInstallationContract } from "./contracts.js";
|
||||
import type { RuntimeBindings } from "./runtime-renderer.js";
|
||||
@@ -111,9 +111,16 @@ export interface DatabaseDiagnosticClientFactory {
|
||||
}): Promise<DatabaseDiagnosticClient>;
|
||||
}
|
||||
|
||||
export interface PostgreSqlDiagnosticWireClient {
|
||||
connect(): Promise<void>;
|
||||
query(sql: string, values: readonly unknown[]): Promise<{ rows: Array<Record<string, unknown>> }>;
|
||||
end(): Promise<void>;
|
||||
}
|
||||
|
||||
export interface ConcreteDiagnosticAdapterDependencies {
|
||||
directProtocol?: DirectProtocolFactory;
|
||||
databaseClient?: DatabaseDiagnosticClientFactory;
|
||||
createPostgresClient?: (config: ClientConfig) => PostgreSqlDiagnosticWireClient;
|
||||
}
|
||||
|
||||
/** Adapters retain only diagnostic metadata and never return credential contents or bodies. */
|
||||
@@ -146,6 +153,15 @@ async function restHeaders(
|
||||
export function createConcreteDiagnosticAdapters(
|
||||
dependencies: ConcreteDiagnosticAdapterDependencies = {},
|
||||
): DiagnosticAdapters {
|
||||
const createPostgresClient = dependencies.createPostgresClient
|
||||
?? ((config: ClientConfig): PostgreSqlDiagnosticWireClient => {
|
||||
const client = new Client(config);
|
||||
return {
|
||||
connect: async () => { await client.connect(); },
|
||||
query: async (sql, values) => await client.query(sql, [...values]),
|
||||
end: async () => await client.end(),
|
||||
};
|
||||
});
|
||||
const databaseClient = dependencies.databaseClient ?? {
|
||||
async connect(request: {
|
||||
host: string;
|
||||
@@ -157,17 +173,21 @@ export function createConcreteDiagnosticAdapters(
|
||||
tlsServername?: string;
|
||||
signal: AbortSignal;
|
||||
}) {
|
||||
const client = new Client({
|
||||
const tlsConfigured = request.tlsCaFile !== undefined || request.tlsServername !== undefined;
|
||||
const ssl: ClientConfig["ssl"] = tlsConfigured
|
||||
? {
|
||||
...(request.tlsCaFile ? { ca: await readFile(request.tlsCaFile, "utf8") } : {}),
|
||||
...(request.tlsServername ? { servername: request.tlsServername } : {}),
|
||||
rejectUnauthorized: true,
|
||||
}
|
||||
: false;
|
||||
const client = createPostgresClient({
|
||||
host: request.host,
|
||||
port: request.port,
|
||||
database: request.database,
|
||||
user: request.user,
|
||||
password: (await readFile(request.credentialFile, "utf8")).trim(),
|
||||
ssl: {
|
||||
...(request.tlsCaFile ? { ca: await readFile(request.tlsCaFile, "utf8") } : {}),
|
||||
...(request.tlsServername ? { servername: request.tlsServername } : {}),
|
||||
rejectUnauthorized: true,
|
||||
},
|
||||
ssl,
|
||||
connectionTimeoutMillis: 5_000,
|
||||
});
|
||||
const abort = () => { void client.end(); };
|
||||
@@ -209,8 +229,18 @@ export function createConcreteDiagnosticAdapters(
|
||||
});
|
||||
try {
|
||||
const result = await client.query(
|
||||
"SELECT current_database() AS database, current_schema() AS schema",
|
||||
[],
|
||||
`SELECT
|
||||
current_database() AS database,
|
||||
CASE
|
||||
WHEN pg_catalog.has_schema_privilege(
|
||||
current_user,
|
||||
(SELECT oid FROM pg_catalog.pg_namespace WHERE nspname = $1),
|
||||
'USAGE'
|
||||
)
|
||||
THEN $1
|
||||
ELSE NULL
|
||||
END AS schema`,
|
||||
[schema],
|
||||
);
|
||||
const row = result.rows[0];
|
||||
if (row?.database !== database || row.schema !== schema) throw new Error("direct probe failed");
|
||||
|
||||
Reference in New Issue
Block a user