Code quality plan, MR D: security defaults
Phase D of the code quality action plan (https://gitlab.com/postgres-ai/database-lab/-/blob/docs/code-quality-action-plan/docs/plans/20260913-code-quality-assessment-action-plan.md). One MR.
Security defaults confirmed on origin/master 8a42a6ef.
Findings
upgradeImageAllowListempty means any image (internal/srv/upgrade.go:206, all example configs)--dbnameunquoted in thesh -cdump-and-restore path (logical/dump.go:821); name comes frompg_databasePhysicalEnvsnotsensitive; not in the YAML mask list, so WAL-G / pgBackRest credentials show up in config viewshttp.Serverwithout timeouts (srv/server.go:331,runci/server.go:66); noMaxBytesReader;ReadJSONechoes the request body into the errordblabapiand webhookhttp.ClientwithoutTimeout(#720)
Tasks
- 13. Empty allow-list resolves to the repository of the clone image (
containerOptions.DockerImageplusclone.DockerImageoverride), not the pg_upgrade image;["*"]keeps the old behavior; changelog entry, five example configs updated. Intentional breaking default. - 14.
shellQuoteevery value joined into the dump-and-restore string; narrow fix, #728 owns the argv-exec migration - 15.
groups:"sensitive"onPhysicalEnvs; maskretrieval.spec.physicalRestore.options.envsvalues in the YAML view - 16.
ReadHeaderTimeout/ReadTimeout/IdleTimeouton both servers (noWriteTimeout, streaming endpoints);MaxBytesReaderat 1 MiB with a 413 mapping at the 17ReadJSONcall sites; clientTimeoutfrom--request-timeout, withDownloadArtifacton a separate client so streamed bodies are not truncated
Related