import NIOSSL /// The TLS posture used when connecting to the database. /// /// The executable derives a posture from its `database.tls` configuration and passes it along as /// part of ``Configuration``; the MySQL driver receives the resulting `TLSConfiguration` through /// ``tlsConfiguration``. public enum TLS: Sendable { /// Connect without TLS, in plaintext. case off /// Connect over TLS when the server offers it, falling back to plaintext otherwise. case prefer /// Connect only over TLS, refusing the connection when the server offers none. case require } // MARK: - Properties extension TLS { /// The NIO TLS configuration passed to the MySQL driver for this posture. /// /// Returns `nil` for ``off`` (connect in plaintext) and the default client configuration for /// ``prefer`` and ``require``. /// /// - Note: `prefer` and `require` currently map to the same client configuration — both enable TLS. /// The distinction (fall back to plaintext vs. fail when the server offers no TLS) is not yet /// enforced here; tighten this mapping if that guarantee becomes required. var tlsConfiguration: TLSConfiguration? { switch self { case .off: return nil case .prefer, .require: return .makeClientConfiguration() } } }