[Fix] Snowflake connection fails when users configure encrypted private keys - #1664
Draft
roomote-roomote[bot] wants to merge 1 commit into
Draft
[Fix] Snowflake connection fails when users configure encrypted private keys#1664roomote-roomote[bot] wants to merge 1 commit into
roomote-roomote[bot] wants to merge 1 commit into
Conversation
Contributor
Comment on lines
+451
to
+455
| const { privateKey: shortPrivateKey } = generateKeyPairSync('rsa', { | ||
| modulusLength: 1024, | ||
| privateKeyEncoding: { type: 'pkcs8', format: 'pem' }, | ||
| publicKeyEncoding: { type: 'spki', format: 'pem' }, | ||
| }); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Why this change was made
Snowflake SDK does not apply
privateKeyPassto inline private keys, so encrypted PKCS8 credentials could be saved but failed when a task connected. Roomote must decrypt and validate the key before invoking the SDK without persisting or exposing the normalized key.Impact
Encrypted and unencrypted PKCS8 RSA keys now reach Snowflake SDK in its supported inline form. Password-only stored connections continue to work when no private key exists.
Security-sensitive behavior is covered with generated encrypted RSA and EC keys, wrong-passphrase rejection, minimum key-size enforcement, SDK option assertions, and error-redaction assertions. The focused API suite passes 13 tests; the broader API MCP suite passes 256 tests; web integration settings pass 69 tests; SDK and worker proxy suites pass 36 and 40 tests. API/web typechecks,
lint:fast,check-types:fast,knip, and docs validation also pass.A live external Snowflake login was not run because this environment has no Snowflake credentials. Production acceptance still requires a controlled JWT smoke test against the target Snowflake account.
Security considerations
Cutover instructions
RSA_PUBLIC_KEY_2rotation slot.list_databases,list_schemas, andexecute_sqlwithSELECT CURRENT_USER(), CURRENT_ROLE(), CURRENT_WAREHOUSE(); confirm one authorized read and the intended role restrictions.