microsoft / microsoft/pg_durable

Move HTTP security to GUCs instead of Cargo features.

Open
#374 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
2.8k
Forks
80
Avg merge
1d 22h
Merged PRs (30d)
32

Description

Currently, the HTTP security level is controlled by three cargo features (https://github.com/microsoft/pg_durable/blob/69eefdc251dbf81bf25fb9929cebec91968abf87/Cargo.toml#L18-L20), which must be enabled or disabled at the time when the extension is built. Ideally, this would be done via one or more Postmaster GUCs (probably SUPERUSER_ONLY), so that it can be changed more flexibly.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the three HTTP security features in Cargo.toml at the linked lines, then trace where they control the PostgreSQL extension's HTTP behavior. Define the Postmaster GUC configuration, including SUPERUSER_ONLY access, so security levels can be changed after the extension is built and verify the cargo-feature controls are no longer required.

Written by the indexing model from the issue text.

Assessment

Tech stack
postgresql, rust
Domain
backend, database, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.