Deployment-readiness gap (#244), BLOCKER — flagged by 2 of 3 reviewers.
Problem
No production connection string enforces TLS to Postgres. The provider passes the
string straight to UseNpgsql without checking its SSL posture
(PostgresDbContextConfigurator.cs);
deploy/docker-compose.yml builds a bare
Host=db;Port=5432;Database=…;Username=…;Password=… with no SSL params. A
repo/deploy/docs grep finds zero sslmode/SSL Mode.
Npgsql defaults to SSL Mode=Prefer, which silently falls back to plaintext
if the server allows it and never validates the server certificate. For any managed
Postgres reached over a non-loopback network, the DB password and all farm/customer
PII can travel unencrypted or be MITM'd.
Fix (app-side, portable)
Require at least SSL Mode=Require, preferably VerifyFull with a trusted root
cert + hostname verification, in Production; fail the boot when the effective
connection permits plaintext or an unverified certificate. The trusted-root / CA
bundle and the exact per-host suffix are deploy-repo config.
Verify
Log the effective (redacted) connection string at boot; confirm it still connects
with Require/VerifyFull; confirm an invalid server certificate is rejected.
Part of the #244 deployment-readiness audit; tracked in epic #15.
Deployment-readiness gap (#244), BLOCKER — flagged by 2 of 3 reviewers.
Problem
No production connection string enforces TLS to Postgres. The provider passes the
string straight to
UseNpgsqlwithout checking its SSL posture(PostgresDbContextConfigurator.cs);
deploy/docker-compose.ymlbuilds a bareHost=db;Port=5432;Database=…;Username=…;Password=…with no SSL params. Arepo/deploy/docs grep finds zero
sslmode/SSL Mode.Npgsql defaults to
SSL Mode=Prefer, which silently falls back to plaintextif the server allows it and never validates the server certificate. For any managed
Postgres reached over a non-loopback network, the DB password and all farm/customer
PII can travel unencrypted or be MITM'd.
Fix (app-side, portable)
Require at least
SSL Mode=Require, preferablyVerifyFullwith a trusted rootcert + hostname verification, in Production; fail the boot when the effective
connection permits plaintext or an unverified certificate. The trusted-root / CA
bundle and the exact per-host suffix are deploy-repo config.
Verify
Log the effective (redacted) connection string at boot; confirm it still connects
with
Require/VerifyFull; confirm an invalid server certificate is rejected.Part of the #244 deployment-readiness audit; tracked in epic #15.