fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify - #910

Merged
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899
Sep 2, 2026
Merged

fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify#910
joryirving merged 1 commit into
mainfrom
foreman/wl-misospace-dispatch-899/issue-899

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Fixes issue #899 by correctly handling sslmode=no-verify in the connection URL to enable TLS without certificate verification.

Fixes#899

Opened by foreman on review GO (workload wl-misospace-dispatch-899).

`@prisma/adapter-pg` parses the connection URL via `pg-connection-string`,
which only knows libpq's standard `sslmode` values: `disable`, `allow`,
`prefer`, `require`, `verify-ca`, `verify-full`. The README documents
`sslmode=no-verify` (TLS on, certificate not verified) but `no-verify` is
not one of those, so the parser falls through and `pg.Pool` is built with
no `ssl` config. Servers that require encryption then reject the
connection with `no pg_hba.conf entry ... no encryption`, even though the
operator followed the documented setting.
Detect `sslmode=no-verify` in `DATABASE_URL`, strip it from the URL, and
hand PrismaPg `{ connectionString, ssl: { rejectUnauthorized: false } }`
so node-postgres requires TLS without validating the certificate —
matching what the README already promises. Standard `sslmode` values and
URLs without `sslmode` are passed through unchanged.
Fixes#899
Signed-off-by: Saffron <263493777+itsmiso-ai@users.noreply.github.com>

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

PR Review: fix(prisma): turn TLS on when DATABASE_URL uses sslmode=no-verify

Summary

This PR fixes issue PR 899 where sslmode=no-verify in DATABASE_URL fails to enable TLS, resulting in the error no pg_hba.conf entry ... no encryption. The root cause is that pg-connection-string (used by @prisma/adapter-pg) doesn't recognize no-verify as a valid sslmode, causing it to fall through to the default prefer behavior which attempts plaintext.

Changes

src/lib/prisma.ts (+32/-1 lines):

  • Added buildAdapter(url) function that:
    • Detects sslmode=no-verify in the connection URL
    • Strips the unrecognized sslmode param to prevent pg-connection-string from falling through to prefer
    • Passes explicit ssl: { rejectUnauthorized: false } to node-postgres to enable TLS without certificate validation
    • Falls back to direct new PrismaPg(url) for standard sslmode values or unparseable URLs
  • Updated initClient() to use buildAdapter(url) instead of new PrismaPg(url)

src/lib/prisma.test.ts (+76 lines):

  • Added 4 test cases covering:
    • sslmode=no-verify → passes ssl: { rejectUnauthorized: false } and strips the param from connection string
    • Standard sslmode values (require) → URL left untouched
    • No sslmode → no explicit ssl config added
    • Unparseable URL → raw URL passed through

Standards Compliance

The implementation follows repository conventions:

  • Uses error instanceof Error pattern principles (proper error handling via try/catch for URL parsing)
  • Validates input before database operations (URL parsing before adapter creation)
  • Appropriate test coverage for a bug fix
  • Clear inline documentation explaining the root cause and fix rationale

Linked Issue Fit

Issue PR 899 clearly states:

  • sslmode=no-verify should enable TLS without certificate verification (documented in README)
  • Currently results in no pg_hba.conf entry ... no encryption error
  • sslmode=require works but rejects self-signed certificates

This PR directly addresses the issue by ensuring no-verify triggers the same TLS behavior as require but with rejectUnauthorized: false. The fix aligns with the documented semantics in README.md lines 147-148.

Tool Harness Findings

Not applicable — no tool harness output in corpus.

CI Check Results

All CI checks passed:

  • Build, Typecheck, Lint: success
  • Tests, Coverage: success
  • Database migrations, Database integration: success
  • Docker Build (MCP), Docker Build, npm audit, smoke: success

Unknowns / Needs Verification

None — the fix is well-documented, has comprehensive test coverage, and all CI checks pass.

@joryirving
joryirving merged commit 204f200 into mainSep 2, 2026
12 checks passed
@joryirving
joryirving deleted the foreman/wl-misospace-dispatch-899/issue-899 branch September 2, 2026 02:41
@its-misoits-misoBot mentioned this pull request Sep 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DATABASE_URL with sslmode=no-verify does not turn TLS on

2 participants

@itsmiso-ai@joryirving