Skip to content

sec(postgres): bound DedicatedProvider Neon HTTP client with neonHTTPTimeout - #32

Merged
mastermanas805 merged 1 commit into
masterfrom
sec/prov-dedicated-http-timeout
May 29, 2026
Merged

sec(postgres): bound DedicatedProvider Neon HTTP client with neonHTTPTimeout#32
mastermanas805 merged 1 commit into
masterfrom
sec/prov-dedicated-http-timeout

Conversation

@mastermanas805

Copy link
Copy Markdown
Member

Closes SEC-PROV finding from audit wave 2026-05-29.

Why

NewDedicatedProvider (provisioner/internal/backend/postgres/dedicated.go:40-47) used &http.Client{} with NO timeout for the Neon Management API path. A hung Neon connection would wedge the provisioning gRPC handler (and any caller — worker storage tick, regrader) indefinitely, piling up goroutines until pod OOM.

NeonBackend already bounds its client at neonHTTPTimeout (30s); the DedicatedProvider path was an oversight in the same family.

What

1-line fix on the &http.Client literal: reuse the existing neonHTTPTimeout constant. Any future tuning lands in one place.

Verification

  • make gate green (build + vet + go test ./... -short -count=1).
  • go test ./internal/backend/postgres/ -short -count=1 → ok.

LOC delta: 1 functional + 5 comment lines.

🤖 Generated with Claude Code

…Timeout

Closes SEC-PROV finding (audit wave 2026-05-29): NewDedicatedProvider used
`&http.Client{}` with NO timeout for the Neon Management API path. A hung
Neon connection would wedge the provisioning gRPC handler (and any caller
— worker storage tick, regrader) indefinitely, piling up goroutines until
OOM.

NeonBackend already bounds its client at neonHTTPTimeout (30s); the
DedicatedProvider path was an oversight in the same family.

Fix: 1-line — set Timeout on the &http.Client literal. Reuses the existing
constant so any future tuning lands in one place.

Production LOC delta: 1 functional + 5 comment lines.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@mastermanas805
mastermanas805 merged commit 3f12859 into master May 29, 2026
12 checks passed
@mastermanas805
mastermanas805 deleted the sec/prov-dedicated-http-timeout branch May 29, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant