Skip to content

fix(security): preserve credential integrity across auth lifecycle - #178

Merged
farhan-syah merged 1 commit into
mainfrom
fix-trust-bootstrap-credential-persistence
Jul 14, 2026
Merged

farhan-syah merged 1 commit into
mainfrom
fix-trust-bootstrap-credential-persistence

Conversation

@farhan-syah

@farhan-syah farhan-syah commented Jul 14, 2026 •

Copy link
Copy Markdown
Member

Summary

  • keep Trust-mode pgwire identities connection-local instead of creating durable credentials
  • reject empty passwords and password assignment to service accounts across local and replicated credential APIs
  • reject persisted regular-user credentials derived from an empty password while preserving intentional passwordless service accounts
  • preserve and revalidate Trust identity across prepared queries and session resets
  • split the pgwire factory into focused modules while preserving its public API

Validation

  • focused credential-store security coverage passes
  • focused pgwire authentication, tenant-scoping, user, and grant coverage passes
  • workspace Clippy passes with all targets, all features, and warnings denied
  • formatting and diff hygiene checks pass

@farhan-syah
farhan-syah merged commit 2cda2b9 into main Jul 14, 2026
@farhan-syah
farhan-syah deleted the fix-trust-bootstrap-credential-persistence branch July 14, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant