Skip to content

fix(auth): materialize trust superuser identity - #198

Merged
farhan-syah merged 1 commit into
mainfrom
fix/trust-superuser-identity
Jul 21, 2026
Merged

farhan-syah merged 1 commit into
mainfrom
fix/trust-superuser-identity

Conversation

@farhan-syah

Copy link
Copy Markdown
Member

Summary

  • materialize the configured trust-mode superuser as a durable catalog identity before listeners start
  • remove empty-store and fabricated user_id = 0 trust authority across pgwire, native, HTTP/WS, and sync
  • make trust/password superuser bootstrap failure-atomic by committing the user and next-user-ID counter together
  • preserve existing regular-user credentials and stable identity while rejecting service-account conflicts
  • add cross-protocol, restart, ownership-integrity, transition, and rollback regression coverage

Validation

  • cargo nextest run -p nodedb --lib -E 'test(credential::store) | test(backward_compat_stored_user_defaults) | test(control::server::sync::session::handshake)'
  • cargo nextest run -p nodedb --test pgwire_auth_wire --test native_handshake_e2e --test http_route_authentication --no-fail-fast
  • HTTP/WS focused suite: 69 passed
  • pgwire/tenant/startup focused suite: 75 passed
  • cargo clippy -p nodedb --all-targets -- -D warnings
  • cargo fmt --all --check

Closes #195

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0.4.0: CREATE TENANT permanently locks out trust-mode auth and leaves the data directory unbootable

1 participant