Skip to content

fix(security): prevent persistent private key leakage in /tmp and restrict file permissions in resolveMongoTlsCertificateKeyFile #915

Description

@ZhuchkaTriplesix

Summary

In resolveMongoTlsCertificateKeyFile (lib/core/security/ssl_certificate_support.dart, lines 135–150):

final certBytes = await File(certPath).readAsString();
final keyBytes = await File(keyPath).readAsString();
final dir = await Directory.systemTemp.createTemp('querya_mongo_tls_');
final merged = File('${dir.path}/client.pem');
await merged.writeAsString('$certBytes\n$keyBytes\n');
return merged.path;

When connecting to MongoDB with separate client certificate and private key files:

  1. No Permission Restrictions: The temporary PEM file containing the plaintext private key is written to the system temp directory (/tmp) without restrictive POSIX permissions (e.g. 0600). On multi-user systems, it is created with default umask (often world-readable).
  2. No Cleanup: Neither MongoConnection.disconnect() nor error handlers delete the created temporary directory or client.pem. Every connection attempt leaves an unencrypted private key file permanently stored in /tmp.

Repro

  1. Configure a MongoDB connection with TLS client certificate and client private key.
  2. Connect to the database.
  3. Inspect /tmp/querya_mongo_tls_*: observe client.pem exists, contains the private key, has standard permissions, and remains on disk even after disconnecting or terminating Querya.

Scope

  • Set restrictive file permissions (0600 on POSIX / owner-only ACLs) when writing temporary TLS key material.
  • Track temporary certificate files in MongoConnection and reliably delete them upon disconnect, connection error, or process exit.
  • Provide a clean-up hook for stale temp files on app startup.

Out of scope

  • In-memory TLS socket bridging for drivers that require file paths.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't workingconnectionsDatabase connections, URI parsing, poolscoreCore library logic and services

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions