Skip to content

feat(postgres): make password authentication optional - #4417

Open
leseb wants to merge 1 commit into
transact-rs:mainfrom
leseb:feat/postgres-password-auth
Open

leseb wants to merge 1 commit into
transact-rs:mainfrom
leseb:feat/postgres-password-auth

Conversation

@leseb

@leseb leseb commented Sep 23, 2026

Copy link
Copy Markdown

Does your PR solve an issue?

Fixes #4416.

Is this a breaking change?

Potentially. Public APIs remain unchanged, and default-feature users retain password authentication.

Users with default-features = false who rely on PostgreSQL cleartext, MD5, or SCRAM authentication must enable postgres-password-auth. Certificate-only connections can omit it.

Summary

  • Gate PostgreSQL password authentication behind a default-enabled feature.
  • Propagate it through SQLx, macros, and the CLI.
  • Return a clear configuration error when password authentication is requested without support.
  • Update documentation, examples, tooling, and CI.
  • Keep certificate-only CI running without password authentication.

Testing

  • PostgreSQL unit tests pass without default features: 148 passed.
  • PostgreSQL unit tests pass with default features: 150 passed.
  • CI explicitly tests password-authenticated and certificate-only configurations.

Add a default-enabled password-auth feature to sqlx-postgres and expose it as
postgres-password-auth through the SQLx facade, macros, and CLI. This preserves
existing behavior while allowing certificate-only users to omit the cleartext,
MD5, and SCRAM authentication code and dependencies.

Return a configuration error when a password authentication method is requested
without the feature. Update CI, examples, tooling, and documentation so
password-backed configurations enable it explicitly and certificate-only
coverage exercises the reduced build.

Closes transact-rs#4416.

Signed-off-by: S茅bastien Han <seb@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature-gate PostgreSQL password authentication crypto

1 participant