Skip to content

Add verified PostgreSQL TLS mode - #94

Merged
BenCodez merged 1 commit into
mainfrom
codex/simpleapi-postgres-tls-mode-20260926
Sep 26, 2026
Merged

BenCodez merged 1 commit into
mainfrom
codex/simpleapi-postgres-tls-mode-20260926

Conversation

@BenCodez

Copy link
Copy Markdown
Owner

Summary

  • add explicit PostgreSQL TLS modes: LEGACY, DISABLE, REQUIRE, and VERIFY_FULL
  • keep existing UseSSL behavior as the default for upgrade compatibility
  • make VERIFY_FULL request CA and hostname verification, while documenting that REQUIRE provides encryption without server identity verification
  • reject conflicting raw JDBC TLS parameters when an explicit mode is selected
  • apply the setting through Bukkit, Bungee, Velocity, and Sponge configuration adapters and the shared classifier

Security model and compatibility

LEGACY is the default and preserves existing installations, including private or self-signed deployments. Operators can migrate explicitly to VERIFY_FULL after installing a trusted CA and using a hostname that matches the server certificate. Explicit PostgreSQL modes also disable GSS encryption negotiation so the chosen SSL mode remains authoritative. MySQL and MariaDB behavior is unchanged, and PostgreSQL-only modes are rejected for those drivers.

Validation

  • focused TLS/configuration tests passed
  • mvn -B -f SimpleAPI/pom.xml clean package passed: 413 tests, no failures/errors
  • full and shared JARs inspected; shared linkage test passed
  • git diff --check passed
  • fresh independent read-only review: No findings

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 27 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 880a3767-63fc-40a0-af36-244ea8871af8

📥 Commits

Reviewing files that changed from the base of the PR and between 2a899b8 and 8158465.

📒 Files selected for processing (12)
  • SimpleAPI/pom.xml
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/core/sql/MysqlConfigView.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/ConnectionManager.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/MySQL.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/PostgreSqlTlsMode.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/config/MysqlConfig.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/config/MysqlConfigBungee.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/config/MysqlConfigSpigot.java
  • SimpleAPI/src/main/java/com/bencodez/simpleapi/sql/mysql/config/MysqlConfigVelocity.java
  • SimpleAPI/src/test/java/com/bencodez/simpleapi/sql/mysql/PostgreSqlTlsConfigTest.java
  • SimpleAPI/src/test/java/com/bencodez/simpleapi/sql/mysql/PostgreSqlTlsModeTest.java
  • docs/postgresql-tls.md

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T22:51:21.829524Z 8158465 PR opened
🔒 Security Review ✅ Completed 2026-09-26T22:53:29.834833Z 8158465 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@BenCodez
BenCodez merged commit 0ccd2ce into main Sep 26, 2026
5 checks passed
@BenCodez
BenCodez deleted the codex/simpleapi-postgres-tls-mode-20260926 branch September 26, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant