Conversation
Author
|
I realise this will probably need some extra work for Cloudflare on the hash/digest method. |
4fd011e to
a92f470
Compare
4a0fe34 to
3a43815
Compare
Author
|
@porsager Any thoughts on adding support for channel binding (SCRAM-SHA-256-PLUS) — based on this PR or otherwise? node-postgres merged this a while back: It's currently behind a custom config flag there, but it would be nicer to support |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hello. I hope you'll consider this patch, which adds support for SCRAM-SHA-256-PLUS authentication.
SCRAM-SHA-256-PLUS in Postgres enables
tls-server-end-pointchannel binding, where the client sends the server a hash of the certificate it received as part of the TLS handshake. This prevents some kinds of MITM attacks where the attacker obtains a certificate that appears valid for the server, but is not actually the server's.So far I've tested it working against Neon (who support SCRAM-SHA-256-PLUS) and Supabase (who don't).
Feel free to make any changes you think appropriate.