Connections

Named profiles, connection strings, TLS modes, and what Test Connection does not do.

Connections are saved as named profiles. A profile records how to reach the database (host, port, database, user, TLS posture) and pointedly does not record the password. Sticky notes are not a backend, and neither is JSON.

Saving a profile

  • Give the connection a name you’ll recognize later. “prod” is a name. Barely.
  • Test Connection verifies reachability without writing anything to the keyring. Only saving the profile stores the password.
  • On save, the password goes to the platform credential store (Keychain on macOS, Credential Manager on Windows) when one is available.
  • Each connection remembers the last schema you used. The default database and default schema are a Settings choice (“Default query location”), not a flag on the profile itself.

Connection strings

Paste a URL or ADO-style string into Connection string and Apply. Host, port, database, and user fill in from:

  • PostgreSQL: jdbc:postgresql://, postgres://, postgresql://
  • MySQL: jdbc:mysql://, mysql://
  • SQL Server: jdbc:sqlserver://, or Server= / Data Source=
  • Oracle: jdbc:oracle:thin:, @tcps:, @tcp:, @//

Oracle TNS DESCRIPTION blocks are rejected. A password in a pasted URL fills the password field and is scrubbed from the string; on save it goes to the credential store, never the profile.

Supported engines

PostgreSQL (5432), MySQL (3306), SQL Server (1433), and Oracle (1521). Those are the default ports; yours can differ. Engine-specific trust behavior is covered in Credential storage; the short version is that verified connections use each ecosystem’s normal trust machinery rather than reinventing it.

Transport security

The form’s TLS dropdown, not a JDBC property, is how you pick the posture. Labels in the app:

  • SSL with hostname verification (recommended off localhost)
  • SSL certificate verification only (no hostname check)
  • SSL encrypt only (no cert check)
  • SSL disabled (unencrypted)

localhost, 127.0.0.1, and ::1 default to disabled; everything else defaults to hostname verification. SQL Server does not offer certificate-only verification. Oracle uses TCPS wording, omits encrypt-only, and for verified TCPS requires an Oracle wallet location; a generic PKCS12 file is not a substitute.

Driver parameters

Each profile can carry custom JDBC driver parameters for the occasional server that needs them. Reserved and credential-shaped names are rejected outright; a driver parameter is not a second place to keep a password.

safe-db is proudly opensource. Apache License 2.0.

GitHub