Skip to content

security: PostgreSQL TLS 인증서 검증 활성화 #7

Description

@co2plant

우선순위: P2

현재 문제

src/lib/prisma.ts는 DB URL의 sslmode=require에 uselibpqcompat=true를 자동 추가함. 현재 pg에서는 이 조합이 rejectUnauthorized: false로 해석되어 TLS 암호화는 사용하지만 서버 인증서와 호스트를 검증하지 않음. .env.example도 검증 모드를 명시하지 않음.

관련 문서: https://supabase.com/docs/guides/platform/ssl-enforcement

영향

네트워크 중간자 공격이 가능한 환경에서는 DB 자격증명과 쿼리 데이터가 가짜 서버로 전달될 수 있음.

기대 동작

  • compatibility 변환 제거
  • 운영 DB에서 verify-full과 신뢰 CA 사용
  • Prisma와 import 스크립트에 동일한 TLS 정책 적용
  • 인증서 검증을 끄는 운영 URL 거부

검증 방법

  • 운영 URL 파싱 결과가 인증서 검증을 활성화하는지 확인
  • 신뢰하지 않는 인증서 연결 실패
  • 정상 Supabase 연결과 import 스크립트 통과

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions